Tip from SmartRetry Avoid automated background retries for ECI 07 declines, as re-sending unauthenticated payloads will repeatedly fail with security-focused issuers. Instead, immediately route the user into an inline step-up 3DS challenge within the active session to capture valid authentication before resubmitting.
Visa
Visa ECI Codes: 07 (Non-Authenticated E-Commerce Transaction)
Last updated: September 25, 2026
About 07 - "Non-authenticated e-commerce transaction"
Key details
- 07
- ECI Codes
- 07
- Non-authenticated e-commerce transaction
What it means
Visa ECI 07 indicates that an e-commerce transaction was processed without being authenticated through 3-D Secure (Visa Secure). This value acts as an authentication and liability indicator, typically meaning that fraud liability remains with the merchant. It is used when authentication is not attempted, or when a properly authenticated transaction is technically downgraded due to missing data (such as the CAVV) in the authorization request.
Classification & retryability
ECI 07 itself is merely an indicator, not a decline. If the underlying authorization is declined with an SCA response code 1A (Soft Decline), perform EMV 3DS step-up authentication using challenge indicator 04, and retry the authorization containing the resulting CAVV and updated ECI. If authentication cannot be completed, treat it as a hard decline.
Why does code 07 occur?
- The merchant does not participate in Visa Secure or chose not to attempt 3-D Secure authentication.
- An authenticated transaction (ECI 05 or 06) was submitted without the required Cardholder Authentication Verification Value (CAVV), causing a downgrade to ECI 07.
- The transaction is legitimately utilizing an EEA/UK Strong Customer Authentication (SCA) exemption.
- The transaction is being processed via the Visa Delegated Authentication Framework.
How to solve 07?
Verify that your payment gateway properly maps and transmits all payer-authentication fields into the authorization message. Missing data, particularly the CAVV, will strip fraud-liability protection and downgrade the transaction to ECI 07. If an issuer rejects the transaction due to missing authentication (SCA code 1A), you must initiate a 3-D Secure challenge and resubmit with the new authentication data.
Solving as a merchant
Monitor your ECI 07 transaction volume to detect gateway configuration errors that might be dropping CAVV data. If you are intentionally bypassing authentication, utilize other fraud controls like CVV2 and AVS, as standard ECI 07 transactions do not carry chargeback protection.
Solving as a customer
If a transaction fails because the issuer requires authentication, the customer should be prepared to complete a 3-D Secure challenge (like an SMS OTP or app approval) presented by their bank upon retry.
Frequently asked questions about this topic
Author
Kyle Regacho
Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue
Read all articles >Articles you may find interesting:
View all
Turning Payment Declines into Revenue with Context-Aware Retry Logic
Blind retries waste fees and damage issuer trust. By analyzing decline codes and timing reattempts around payroll cycles, payment teams can successfully salvage recurring revenue without customer disruption.

Why Payments Fail: Decoding Decline Codes and Modernizing Retry Logic
Surface-level decline messages conceal critical issuer signals. Discover how intelligent retries, network tokens, and behavioral timing protect MID health and systematically recover lost recurring revenue.

Decoding Payment Declines: Turning Authorization Failures into Recovered Revenue
Blindly retrying failed transactions hurts authorization rates and risks network fines. Discover how decoding issuer responses turns card declines into recovered revenue.

The Real Cost of Payment Declines and How to Recover Lost Revenue
Payment failures cost merchants billions in uncaptured revenue and customer churn. Discover how data-driven retries and response code intelligence help teams recover failed transactions and protect conversion.