Skip to main content
Mastercard

Mastercard

Mastercard ECI Code 02: Authentication Successful

technical decline

Last updated: September 25, 2026

About 02 - "Authentication successful (liability shift applies)"

Key details

Brand
Mastercard
Code
02
Category
ECI Codes
Response
02
Detailed Response
Authentication successful (liability shift applies)
technical decline

What it means

Mastercard ECI 02 is not a payment decline or an issuer authorization response; it is a 3D Secure Electronic Commerce Indicator. It signifies that the cardholder was fully and successfully authenticated, either through a frictionless flow or a completed challenge. Receiving ECI 02 acts as a strong signal for liability shift from the merchant to the issuer for eligible fraud-related disputes.

Classification & retryability

technicalRetryable: no

Why does code 02 occur?

  • The cardholder successfully completed a 3D Secure authentication challenge, such as entering a one-time password or using biometrics.
  • The transaction qualified for a frictionless authentication flow, allowing the issuer to verify the user passively.
  • The 3D Secure authentication resulted in a successful authentication status (ThreeDResult Y) and returned a valid CAVV.

How to solve 02?

Because ECI 02 indicates a successful 3D Secure authentication rather than an error or decline, no corrective resolution is needed. The standard procedure is to take the authentication data and proceed directly to card authorization. Do not attempt to retry or recover ECI 02 as a decline. If the subsequent authorization request is declined by the issuer, you must troubleshoot that specific issuer response code independently.

Solving as a merchant

Proceed to the authorization phase by passing the ECI 02 value and the generated CAVV to the issuer. Ensure your system captures and stores the final ECI returned in the authorization response, as payment networks can sometimes downgrade the status. Finally, retain all authentication evidence to leverage the liability shift in the event of an eligible fraud dispute.

Solving as a customer

No action is required from the customer regarding this code, as their identity has been successfully authenticated.

Tip from SmartRetry Configure your payment pipeline to pass the accompanying cryptographic proof directly into the downstream authorization payload rather than routing this status into an exception or retry queue. Treating ECI 02 as a failure mistakenly halts valid checkouts and risks forfeiting your fraud liability shift.

Frequently asked questions about this topic

Share this article

Share on XShare on FacebookShare on LinkedIn
Kyle Regacho

Author

Kyle Regacho
LinkedInFind me on Linkedin

Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue

Read all articles >
View all