Skip to main content
Visa

Visa

Visa ECI Code 05: Successful Authentication

technical decline

Last updated: September 25, 2026

About 05 - "Cardholder authentication is successful (step-up or frictionless)"

Key details

Brand
Visa
Code
05
Category
ECI Codes
Response
05
Detailed Response
Cardholder authentication is successful (step-up or frictionless)
technical decline

What it means

Visa ECI (Electronic Commerce Indicator) 05 is not a decline code; it is a positive status indicating that 3-D Secure cardholder authentication was successful. It signifies that the issuer's Access Control Server (ACS) authenticated the cardholder, either through a frictionless flow or a step-up challenge. While it indicates a highly secure transaction, it does not guarantee that the subsequent authorization request will be approved.

Classification & retryability

technicalRetryable: no

Because ECI 05 is a success indicator rather than a decline, you should not retry the authentication. If the subsequent authorization attempt fails, base your retry strategy on the specific authorization decline code provided by the issuer.

Why does code 05 occur?

  • The cardholder successfully completed a 3-D Secure authentication challenge (step-up authentication).
  • The issuer's Access Control Server (ACS) successfully authenticated the cardholder without a challenge via a frictionless flow.

How to solve 05?

Proceed to authorization. Pass the ECI 05 value alongside the required authentication values (such as the CAVV) in your e-commerce authorization message to VisaNet. Ensure no 3-D Secure fields are omitted or malformed, as this can result in the authorization being refused or downgraded.

Solving as a merchant

Submit the authorization request with all returned authentication data to secure potential fraud liability shifts. Retain the authentication records for dispute defense. Be prepared to handle separate authorization declines, as ECI 05 relates solely to identity authentication, not fund availability or account standing.

Solving as a customer

No action is required from the customer, as their identity has already been successfully authenticated by their issuing bank.

Tip from SmartRetry Because ECI 05 transfers fraud liability to the issuer, you can safely configure your internal risk engine to relax pre-auth fraud rules on these transactions to avoid false-positive declines. Ensure your gateway routes the authorization immediately, as cryptographic tokens like the CAVV expire quickly.

Frequently asked questions about this topic

Share this article

Share on XShare on FacebookShare on LinkedIn
Kyle Regacho

Author

Kyle Regacho
LinkedInFind me on Linkedin

Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue

Read all articles >
View all