Tip from SmartRetry If downstream authorizations linked to ECI 04 fail, avoid re-submitting the data-only check; instead, configure your 3DS logic to escalate high-risk transactions to a full challenge flow to secure an issuer liability shift.
Mastercard
Mastercard ECI Code 04: Data Share Only
Last updated: September 25, 2026
About 04 - "Data share only, not authenticated, improves approval rate (EMV 3DS only)"
Key details
- 04
- ECI Codes
- 04
- Data share only, not authenticated, improves approval rate (EMV 3DS only)
What it means
Mastercard ECI 04 is an authentication-result indicator for Mastercard Identity Check Data Only (IDCI) transactions within EMV 3DS. It indicates that the merchant submitted device and transaction data to Mastercard for risk scoring without challenging the cardholder to authenticate. This data is passed to the issuer to improve authorization approval rates, though it does not result in an authenticated transaction or provide a liability shift.
Classification & retryability
Why does code 04 occur?
- The merchant intentionally initiated a Mastercard Identity Check Data Only flow to reduce checkout friction while passing rich transaction data.
- The issuer successfully received the EMV 3DS device and transaction data without requiring a cardholder challenge.
How to solve 04?
ECI 04 is a successful data-share authentication response, not a payment decline. The returned authentication data—specifically the ECI 04 indicator, the CAVV, and the Directory Server transaction ID (and paresStatus U)—must be correctly carried into your subsequent authorization request. If the ensuing authorization is declined by the issuer, you must evaluate the separate authorization decline code to determine if a retry or different payment method is appropriate. Repeating the same ECI 04 authentication result is not a remedy for an authorization decline.
Solving as a merchant
Ensure your payment gateway captures the ECI 04, CAVV, and Directory Server transaction ID from the 3DS response and correctly passes them into the authorization message. Do not treat ECI 04 as fraud protection or a chargeback liability shift, and avoid using the Data Only flow in regions where Strong Customer Authentication (SCA) is legally mandated.
Solving as a customer
No action is required from the customer. The Data Only flow is entirely frictionless and happens in the background without prompting the cardholder to complete a challenge.
Frequently asked questions about this topic
Author
Kyle Regacho
Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue
Read all articles >Articles you may find interesting:
View all
Turning Payment Declines into Revenue with Context-Aware Retry Logic
Blind retries waste fees and damage issuer trust. By analyzing decline codes and timing reattempts around payroll cycles, payment teams can successfully salvage recurring revenue without customer disruption.

Why Payments Fail: Decoding Decline Codes and Modernizing Retry Logic
Surface-level decline messages conceal critical issuer signals. Discover how intelligent retries, network tokens, and behavioral timing protect MID health and systematically recover lost recurring revenue.

Decoding Payment Declines: Turning Authorization Failures into Recovered Revenue
Blindly retrying failed transactions hurts authorization rates and risks network fines. Discover how decoding issuer responses turns card declines into recovered revenue.

The Real Cost of Payment Declines and How to Recover Lost Revenue
Payment failures cost merchants billions in uncaptured revenue and customer churn. Discover how data-driven retries and response code intelligence help teams recover failed transactions and protect conversion.