Tip from SmartRetry Configure your payment pipeline to pass the accompanying cryptographic proof directly into the downstream authorization payload rather than routing this status into an exception or retry queue. Treating ECI 02 as a failure mistakenly halts valid checkouts and risks forfeiting your fraud liability shift.
Mastercard
Mastercard ECI Code 02: Authentication Successful
Last updated: September 25, 2026
About 02 - "Authentication successful (liability shift applies)"
Key details
- 02
- ECI Codes
- 02
- Authentication successful (liability shift applies)
What it means
Mastercard ECI 02 is not a payment decline or an issuer authorization response; it is a 3D Secure Electronic Commerce Indicator. It signifies that the cardholder was fully and successfully authenticated, either through a frictionless flow or a completed challenge. Receiving ECI 02 acts as a strong signal for liability shift from the merchant to the issuer for eligible fraud-related disputes.
Classification & retryability
Why does code 02 occur?
- The cardholder successfully completed a 3D Secure authentication challenge, such as entering a one-time password or using biometrics.
- The transaction qualified for a frictionless authentication flow, allowing the issuer to verify the user passively.
- The 3D Secure authentication resulted in a successful authentication status (ThreeDResult Y) and returned a valid CAVV.
How to solve 02?
Because ECI 02 indicates a successful 3D Secure authentication rather than an error or decline, no corrective resolution is needed. The standard procedure is to take the authentication data and proceed directly to card authorization. Do not attempt to retry or recover ECI 02 as a decline. If the subsequent authorization request is declined by the issuer, you must troubleshoot that specific issuer response code independently.
Solving as a merchant
Proceed to the authorization phase by passing the ECI 02 value and the generated CAVV to the issuer. Ensure your system captures and stores the final ECI returned in the authorization response, as payment networks can sometimes downgrade the status. Finally, retain all authentication evidence to leverage the liability shift in the event of an eligible fraud dispute.
Solving as a customer
No action is required from the customer regarding this code, as their identity has been successfully authenticated.
Frequently asked questions about this topic
Author
Kyle Regacho
Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue
Read all articles >Articles you may find interesting:
View all
Turning Payment Declines into Revenue with Context-Aware Retry Logic
Blind retries waste fees and damage issuer trust. By analyzing decline codes and timing reattempts around payroll cycles, payment teams can successfully salvage recurring revenue without customer disruption.

Why Payments Fail: Decoding Decline Codes and Modernizing Retry Logic
Surface-level decline messages conceal critical issuer signals. Discover how intelligent retries, network tokens, and behavioral timing protect MID health and systematically recover lost recurring revenue.

Decoding Payment Declines: Turning Authorization Failures into Recovered Revenue
Blindly retrying failed transactions hurts authorization rates and risks network fines. Discover how decoding issuer responses turns card declines into recovered revenue.

The Real Cost of Payment Declines and How to Recover Lost Revenue
Payment failures cost merchants billions in uncaptured revenue and customer churn. Discover how data-driven retries and response code intelligence help teams recover failed transactions and protect conversion.