3-D Secure 2.x Test Cases
Use the card number specified in the test with the card expiration date set to the month of January and the current year plus three. For example, for 2026, use 2029. You also need the minimum required fields for an order.
Be sure to remove spaces in card numbers when testing.
The test card numbers provided are formatted with Xs for zeroes in the card number. When testing with the card numbers, replace the Xs with a 0 (zero).
While the usage of transaction ID (XID) values have declined in importance, they are still included in 3-D Secure 2.x test cases. Only Mastercard transactions do not return XIDs.
While the 3-D Secure version and directory server transaction ID fields are returned for the Check Enrollment and Validate Authentication services, this data is not included in the 3-D Secure 2.x test cases. Mastercard requires that the 3-D Secure version and directory server transaction ID be included along with all pertinent data in your authorization request.
Card-Specific Setup
The cards in this section require a specific merchant attribute or configuration during testing.
- eftpos: The merchant should request that customer support enable the preferred secondary brand attribute to enable the preferred routing for eftpos.
- mada: The merchant descriptor country should be set as SA and the card type should be set as mada.
- Meeza: The merchant descriptor country should be set as
EGand the card type should be set as Meeza.
2.1: Frictionless Authentication Is Successful
This test verifies that successful frictionless authentication of the cardholder by the card issuer works correctly.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 27X8 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XX XXXX XXXX 3XX1 | 52XX XXXX XXXX 48X1 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXX XXXX XXXX 3XX6 | 4XXX XXXX XXXX 497X |
| China UnionPay (Card Type = 062) | 62XX X1XX XX2X XXXX | 81XXX1 XX XXXX X142 / 621XX3 82 3532 713X |
| Diners Club (Card Type = 005) | — | 6X11 XXXX XXXX 2117 |
| Discover (Card Type = 004) | — | 6X11 XXXX XXXX 2117 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 517X | — |
| eftpos Mastercard (Card Type = 070) | 516366 XX 1XXX XXX1 | — |
| eftpos Visa (Card Type = 001) | 4XXXXX XX XXXX 5126 | — |
| eftpos Visa (Card Type = 070) | 47X565 XX 1XXX XXXX | — |
| Elo (Card Type = 054) | — | 65X529 XX XXXX 2XXX |
2.2: Frictionless Authentication Is Unsuccessful
This test verifies that cardholder authentication without a challenge by the card issuer will fail.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2X96 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X19 | 52XXXX XX XXXX 4538 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X14 | 4XXXXX XX XXXX 4574 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX1X XX1X | 81XXX1 XX XXXX X647 / 621XX3 77 X3X8 1377 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2364 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2364 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 522X | — |
| eftpos Mastercard (Card Type = 070) | 516366 XX 1XXX XX19 | — |
| eftpos Visa (Card Type = 001) | 4XXXXX XX XXXX 5X19 | — |
| eftpos Visa (Card Type = 070) | 47X565 XX 1XXX XX18 | — |
| Elo (Card Type = 054) | — | 65X529 XX XXXX 2X18 |
2.3: Stand-In Frictionless Authentication Is Attempted
This test verifies how your system reacts when the cardholder is enrolled in 3-D Secure but the card issuer does not support 3-D Secure, requiring a stand-in authentication experience.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2872 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X27 | 52XXXX XX XXXX 4587 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X22 | 4XXXXX XX XXXX 4111 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XXXX XX2X | 62XXX1 XX XXXX XX2X / 621XX3 35 3371 144X |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2646 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2646 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 5360 | — |
| eftpos Mastercard (Card Type = 070) | 516366 XX 1XXX XX27 | — |
| eftpos Visa (Card Type = 001) | 4XXXXX XX XXXX 5X27 | — |
| eftpos Visa (Card Type = 070) | 47X565 XX 1XXX XX26 | — |
| Elo (Card Type = 054) | — | 65X529 XX XXXX 2026 |
2.4: Frictionless Authentication Is Unavailable
This test verifies how your system behaves when authentication is unavailable at the time of the transaction.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXXX XX XXXX 2922 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3035 | 52XXXX XX XXXX 4306 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X3X | 4XXXXX XX XXXX 4160 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX40 XX3X | 81XXX1 XX XXXX X894 / 621XX3 17 X75X 3X15 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2612 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2612 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 541X | — |
| eftpos Mastercard (Card Type = 070) | 516366 XX 1XXX XX35 | — |
| eftpos Visa (Card Type = 001) | 4XXXXX XX XXXX 5X35 | — |
| eftpos Visa (Card Type = 070) | 47X56 5X X1XX XXX34 | — |
| Elo (Card Type = 054) | — | 65X529 XX XXXX 2X34 |
2.5: Frictionless Authentication Is Rejected
This test verifies how your system reacts when authentication rejects the cardholder without a challenge by the issuer.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2X62 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X43 | 52XXXX XX XXXX 4405 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X48 | 4XXXXX XX XXXX 4517 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX3X XX4X | 81XXX1 XX XXXX X415 / 621XX3 X8 5745 X241 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2711 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2711 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 555X | — |
| eftpos Mastercard (Card Type = 070) | 516366 XX 1XXX XX43 | — |
| eftpos Visa (Card Type = 001) | 4XXXXX XX XXXX 5X35 | — |
| eftpos Visa (Card Type = 070) | 470565 XX 1XXX XX42 | — |
| Elo (Card Type = 054) | — | 65X529 XX XXXX 2X83 |
2.6: Authentication Is Not Available
This test verifies how your system reacts when a system error when checking enrollment prevents authentication.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2468 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X5X | 52XXXXXX XXXX 4X9X |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X55 | 4XXXXX XX XXXX 4285 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX6X XX5X | 81XXX1 XX XXXX X795 / 621XX3 1X 724X 3478 |
| Diners Club (Card Type = 005) | — | 6X11XXXX XXXX 2836 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2836 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 556X | — |
2.7: Check Enrollment Error
This test verifies how your system reacts when an error occurs while verifying that the cardholder is part of an authentication program.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2732 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X68 | 52XXXX XX XXXX 4X58 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X63 | 4XXXXXXX XXXX 4194 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX5X XX6X | 81XXX1 XX XXXX X662 / 621XX3 41 5762 1444 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2315 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2315 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 579X | — |
2.8: Time Out
This test verifies how your system reacts when an error occurs while verifying that the cardholder is part of an authentication program.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2047 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X76 | 52XXXX XX XXXX 4694 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X71 | 4XXXXX XX XXXX 4277 |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX9X X7X | 81XXX1 XX XXXX X928 / 621XX3 X1 X451 71X7 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2869 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2869 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 584X | — |
2.9: Step-Up Authentication Is Successful
This test verifies how your system reacts to a successful step-up (or challenge) authentication transaction.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2534 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X92 | 52XXXX XX XXXX 4X74 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3139 | 4XXXXX XX XXXX 4855 |
| China UnionPay (Card Type = 062) | 62XXX1 99 998X XX19 | 81XXX1 XX XXXX X688 / 621XX3 25 7857 4424 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2265 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2265 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 5311 | — |
2.10: Step-Up Authentication Is Unsuccessful
This test verifies that the step-up (challenge) authentication transaction fails whenever the cardholder challenge fails.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2237 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 31XX | 52XXXX XX XXXX 4124 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X97 | 4XXXXX XX XXXX 4293 |
| China UnionPay (Card Type = 062) | 62XXX1 99 997X XX29 | 81XXX1 XX XXXX X8X3 / 621XX3 81 8186 8X38 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2695 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2695 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 5329 | — |
2.11: Step-Up Authentication Is Unavailable
This test verifies that the correct response is returned when step-up authentication is unavailable.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2484 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3188 | 52XXXX XX XXXX 4124 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 31X5 | 4XXXXX XX XXXX 464X |
| China UnionPay (Card Type = 062) | 62XXX1 99 997X XX39 | 81XXX1 XX XXXX X159 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 1129 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 1129 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 5337 | — |
2.12: Error During Authentication
This test checks how your system reacts when authentication request errors occur during processing.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXXX XX XXXX 2351 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3126 | 52XXXX XX XXXX 4611 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3113 | 4XXXXX XX XXXX 4913 |
| China UnionPay (Card Type = 062) | 62XXX1 99 994X XX59 | 81XXX1 XX XXXX X159 / 621XX3 32 7122 3145 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 257X |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 257X |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 5352 | — |
2.13: Authentication Is Bypassed
This test verifies how your system reacts when the challenge requested by the issuer is bypassed for the transaction.
| Card Type | 2.1.0 Test Card Number | 2.2.0 Test Card Number |
|---|---|---|
| American Express (Card Type = 003) | — | 34XXX XX XXXX 2948 |
| Cartes Bancaires Mastercard (Card Type = 036) | 52XXXX XX XXXX 3X84 | 52XXXX XX XXXX 4991 |
| Cartes Bancaires Visa (Card Type = 036) | 4XXXXX XX XXXX 3X89 | 4XXXXX XX XXXX 44XX |
| China UnionPay (Card Type = 062) | 62XXX1 XX XX8X XX8X | 81XXX1 XX XXXX X985 / 621XX3 26 X765 76X4 |
| Diners Club (Card Type = 005) | — | 6X11XX XX XXXX 2976 |
| Discover (Card Type = 004) | — | 6X11XX XX XXXX 2976 |
| eftpos Mastercard (Card Type = 002) | 52XXXX XX XXXX 598X | — |
2.14: Require Method URL
This test ensures that the merchant is allowing sufficient time (10 seconds) for the issuer to complete device data collection.
The Method URL process runs before the authentication request to ensure device data is collected properly. The enrollment check of the card account should not start until after the device data collection (DDC) response is received. This test verifies that there is enough time to collect the BIN of the issuer and to transmit it. This test attempts to collect the nine-digit BIN of the card number and verifies that the delay between the DDC request and the response is at least 7 seconds long. The test fails when fewer than nine digits of the BIN are collected or when the delay between the DDC request and response is too short in duration.
| Card Type | Test Card Number |
|---|---|
| Visa (Card Type = 001) | 4XXX1X XX XXXX XXXX |
Results for the Check Enrollment Service:
- VERes enrolled = Y
- PARes status = Y
- CAVV = <CAVV value>
- ECI value = 05
ECI Values by Network:
| Network | ECI Raw Value |
|---|---|
| Visa | 05 |
Action: If your device data collection method implements correctly and EMV 3-D Secure processing occurs, the test transaction produces a Frictionless Success result. A failure is indicated when PARes status = C. With the failure, a warning message opens to explain the cause of the test failure.
Thanks for your feedback!
Last published: September 29, 2026