Electronic Commerce Indicator
An Electronic Commerce Indicator (ECI) is a short code attached to an online card transaction that signals how, or whether, the payment was authenticated during the checkout process. It helps the merchant and the card issuer understand the security context of the transaction and decide what to do next, such as proceeding with or declining a payment. The code is also used to communicate who may carry responsibility if the transaction turns out to be fraudulent.
The Electronic Commerce Indicator (ECI) is a two-digit response value used in 3-D Secure processing, including EMV 3-D Secure, that conveys the level of payer authentication achieved for a card-not-present transaction. It is returned during the authentication flow and passed into authorization to indicate to the issuer how the transaction was authenticated and to inform fraud-liability handling; merchants use the ECI value to determine subsequent processing decisions. The specific ECI values, their meanings, and any associated liability shift are defined by individual card brand and network rules, which vary by region and change over time, so exact mappings should be confirmed against the current rules of the applicable network. ECI is a signal about authentication context only and does not by itself authenticate a cardholder or eliminate fraud.
Why it matters
The Electronic Commerce Indicator sits at the intersection of authentication and fraud liability for card-not-present transactions, which makes it a practical decision input rather than just a technical artifact. When a 3-D Secure authentication flow completes, the ECI value communicates to the issuer how the transaction was authenticated and, under the applicable card brand and network rules, can inform who carries responsibility if the transaction is later disputed as fraudulent. Merchants and processors rely on this signal to decide whether to proceed with authorization, apply additional scrutiny, or decline.
Because the meanings of specific ECI values and any associated liability shift are defined by individual card brands and networks, and because those rules vary by region and change over time, misreading or hard-coding ECI mappings can lead to incorrect processing decisions and unexpected chargeback outcomes. A merchant that assumes a given ECI value always transfers fraud liability may find that assumption does not hold across all networks or regions. Confirming values against the current published rules of the applicable network is important for accurate handling.
It is equally important to understand what the ECI does not do. The ECI is a signal about authentication context only; it does not itself authenticate a cardholder and does not eliminate fraud. Treating a favorable ECI value as a guarantee of a legitimate transaction can create a false sense of security, since fraud such as account takeover or first-party disputes can still occur within transactions that carry any given authentication outcome. The ECI should be used as one input alongside broader fraud-detection and risk controls, not as a standalone control.
Who it's relevant to
Inside ECI
Common questions
Answers to the questions practitioners most commonly ask about ECI.