Skip to main content
Mastercard

Mastercard

Mastercard ECI Code 04: Data Share Only

technical decline

Last updated: September 25, 2026

About 04 - "Data share only, not authenticated, improves approval rate (EMV 3DS only)"

Key details

Brand
Mastercard
Code
04
Category
ECI Codes
Response
04
Detailed Response
Data share only, not authenticated, improves approval rate (EMV 3DS only)
technical decline

What it means

Mastercard ECI 04 is an authentication-result indicator for Mastercard Identity Check Data Only (IDCI) transactions within EMV 3DS. It indicates that the merchant submitted device and transaction data to Mastercard for risk scoring without challenging the cardholder to authenticate. This data is passed to the issuer to improve authorization approval rates, though it does not result in an authenticated transaction or provide a liability shift.

Classification & retryability

technicalRetryable: no

Why does code 04 occur?

  • The merchant intentionally initiated a Mastercard Identity Check Data Only flow to reduce checkout friction while passing rich transaction data.
  • The issuer successfully received the EMV 3DS device and transaction data without requiring a cardholder challenge.

How to solve 04?

ECI 04 is a successful data-share authentication response, not a payment decline. The returned authentication data—specifically the ECI 04 indicator, the CAVV, and the Directory Server transaction ID (and paresStatus U)—must be correctly carried into your subsequent authorization request. If the ensuing authorization is declined by the issuer, you must evaluate the separate authorization decline code to determine if a retry or different payment method is appropriate. Repeating the same ECI 04 authentication result is not a remedy for an authorization decline.

Solving as a merchant

Ensure your payment gateway captures the ECI 04, CAVV, and Directory Server transaction ID from the 3DS response and correctly passes them into the authorization message. Do not treat ECI 04 as fraud protection or a chargeback liability shift, and avoid using the Data Only flow in regions where Strong Customer Authentication (SCA) is legally mandated.

Solving as a customer

No action is required from the customer. The Data Only flow is entirely frictionless and happens in the background without prompting the cardholder to complete a challenge.

Tip from SmartRetry If downstream authorizations linked to ECI 04 fail, avoid re-submitting the data-only check; instead, configure your 3DS logic to escalate high-risk transactions to a full challenge flow to secure an issuer liability shift.

Frequently asked questions about this topic

Share this article

Share on XShare on FacebookShare on LinkedIn
Kyle Regacho

Author

Kyle Regacho
LinkedInFind me on Linkedin

Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue

Read all articles >
View all