Tip from SmartRetry Because ECI 05 transfers fraud liability to the issuer, you can safely configure your internal risk engine to relax pre-auth fraud rules on these transactions to avoid false-positive declines. Ensure your gateway routes the authorization immediately, as cryptographic tokens like the CAVV expire quickly.
Visa
Visa ECI Code 05: Successful Authentication
Last updated: September 25, 2026
About 05 - "Cardholder authentication is successful (step-up or frictionless)"
Key details
- 05
- ECI Codes
- 05
- Cardholder authentication is successful (step-up or frictionless)
What it means
Visa ECI (Electronic Commerce Indicator) 05 is not a decline code; it is a positive status indicating that 3-D Secure cardholder authentication was successful. It signifies that the issuer's Access Control Server (ACS) authenticated the cardholder, either through a frictionless flow or a step-up challenge. While it indicates a highly secure transaction, it does not guarantee that the subsequent authorization request will be approved.
Classification & retryability
Because ECI 05 is a success indicator rather than a decline, you should not retry the authentication. If the subsequent authorization attempt fails, base your retry strategy on the specific authorization decline code provided by the issuer.
Why does code 05 occur?
- The cardholder successfully completed a 3-D Secure authentication challenge (step-up authentication).
- The issuer's Access Control Server (ACS) successfully authenticated the cardholder without a challenge via a frictionless flow.
How to solve 05?
Proceed to authorization. Pass the ECI 05 value alongside the required authentication values (such as the CAVV) in your e-commerce authorization message to VisaNet. Ensure no 3-D Secure fields are omitted or malformed, as this can result in the authorization being refused or downgraded.
Solving as a merchant
Submit the authorization request with all returned authentication data to secure potential fraud liability shifts. Retain the authentication records for dispute defense. Be prepared to handle separate authorization declines, as ECI 05 relates solely to identity authentication, not fund availability or account standing.
Solving as a customer
No action is required from the customer, as their identity has already been successfully authenticated by their issuing bank.
Frequently asked questions about this topic
Author
Kyle Regacho
Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue
Read all articles >Articles you may find interesting:
View all
Turning Payment Declines into Revenue with Context-Aware Retry Logic
Blind retries waste fees and damage issuer trust. By analyzing decline codes and timing reattempts around payroll cycles, payment teams can successfully salvage recurring revenue without customer disruption.

Why Payments Fail: Decoding Decline Codes and Modernizing Retry Logic
Surface-level decline messages conceal critical issuer signals. Discover how intelligent retries, network tokens, and behavioral timing protect MID health and systematically recover lost recurring revenue.

Decoding Payment Declines: Turning Authorization Failures into Recovered Revenue
Blindly retrying failed transactions hurts authorization rates and risks network fines. Discover how decoding issuer responses turns card declines into recovered revenue.

The Real Cost of Payment Declines and How to Recover Lost Revenue
Payment failures cost merchants billions in uncaptured revenue and customer churn. Discover how data-driven retries and response code intelligence help teams recover failed transactions and protect conversion.