Skip to main content

3-D Secure 2.x Test Cases


Use the card number specified in the test with the card expiration date set to the month of January and the current year plus three. For example, for 2026, use 2029. You also need the minimum required fields for an order.

Be sure to remove spaces in card numbers when testing.

The test card numbers provided are formatted with Xs for zeroes in the card number. When testing with the card numbers, replace the Xs with a 0 (zero).

While the usage of transaction ID (XID) values have declined in importance, they are still included in 3-D Secure 2.x test cases. Only Mastercard transactions do not return XIDs.

While the 3-D Secure version and directory server transaction ID fields are returned for the Check Enrollment and Validate Authentication services, this data is not included in the 3-D Secure 2.x test cases. Mastercard requires that the 3-D Secure version and directory server transaction ID be included along with all pertinent data in your authorization request.

Card-Specific Setup

The cards in this section require a specific merchant attribute or configuration during testing.

  • eftpos: The merchant should request that customer support enable the preferred secondary brand attribute to enable the preferred routing for eftpos.
  • mada: The merchant descriptor country should be set as SA and the card type should be set as mada.
  • Meeza: The merchant descriptor country should be set as EG and the card type should be set as Meeza.

2.1: Frictionless Authentication Is Successful

This test verifies that successful frictionless authentication of the cardholder by the card issuer works correctly.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 27X8
Cartes Bancaires Mastercard (Card Type = 036)52XX XXXX XXXX 3XX152XX XXXX XXXX 48X1
Cartes Bancaires Visa (Card Type = 036)4XXX XXXX XXXX 3XX64XXX XXXX XXXX 497X
China UnionPay (Card Type = 062)62XX X1XX XX2X XXXX81XXX1 XX XXXX X142 / 621XX3 82 3532 713X
Diners Club (Card Type = 005)—6X11 XXXX XXXX 2117
Discover (Card Type = 004)—6X11 XXXX XXXX 2117
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 517X—
eftpos Mastercard (Card Type = 070)516366 XX 1XXX XXX1—
eftpos Visa (Card Type = 001)4XXXXX XX XXXX 5126—
eftpos Visa (Card Type = 070)47X565 XX 1XXX XXXX—
Elo (Card Type = 054)—65X529 XX XXXX 2XXX

2.2: Frictionless Authentication Is Unsuccessful

This test verifies that cardholder authentication without a challenge by the card issuer will fail.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2X96
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X1952XXXX XX XXXX 4538
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X144XXXXX XX XXXX 4574
China UnionPay (Card Type = 062)62XXX1 XX XX1X XX1X81XXX1 XX XXXX X647 / 621XX3 77 X3X8 1377
Diners Club (Card Type = 005)—6X11XX XX XXXX 2364
Discover (Card Type = 004)—6X11XX XX XXXX 2364
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 522X—
eftpos Mastercard (Card Type = 070)516366 XX 1XXX XX19—
eftpos Visa (Card Type = 001)4XXXXX XX XXXX 5X19—
eftpos Visa (Card Type = 070)47X565 XX 1XXX XX18—
Elo (Card Type = 054)—65X529 XX XXXX 2X18

2.3: Stand-In Frictionless Authentication Is Attempted

This test verifies how your system reacts when the cardholder is enrolled in 3-D Secure but the card issuer does not support 3-D Secure, requiring a stand-in authentication experience.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2872
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X2752XXXX XX XXXX 4587
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X224XXXXX XX XXXX 4111
China UnionPay (Card Type = 062)62XXX1 XX XXXX XX2X62XXX1 XX XXXX XX2X / 621XX3 35 3371 144X
Diners Club (Card Type = 005)—6X11XX XX XXXX 2646
Discover (Card Type = 004)—6X11XX XX XXXX 2646
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 5360—
eftpos Mastercard (Card Type = 070)516366 XX 1XXX XX27—
eftpos Visa (Card Type = 001)4XXXXX XX XXXX 5X27—
eftpos Visa (Card Type = 070)47X565 XX 1XXX XX26—
Elo (Card Type = 054)—65X529 XX XXXX 2026

2.4: Frictionless Authentication Is Unavailable

This test verifies how your system behaves when authentication is unavailable at the time of the transaction.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXXX XX XXXX 2922
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 303552XXXX XX XXXX 4306
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X3X4XXXXX XX XXXX 4160
China UnionPay (Card Type = 062)62XXX1 XX XX40 XX3X81XXX1 XX XXXX X894 / 621XX3 17 X75X 3X15
Diners Club (Card Type = 005)—6X11XX XX XXXX 2612
Discover (Card Type = 004)—6X11XX XX XXXX 2612
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 541X—
eftpos Mastercard (Card Type = 070)516366 XX 1XXX XX35—
eftpos Visa (Card Type = 001)4XXXXX XX XXXX 5X35—
eftpos Visa (Card Type = 070)47X56 5X X1XX XXX34—
Elo (Card Type = 054)—65X529 XX XXXX 2X34

2.5: Frictionless Authentication Is Rejected

This test verifies how your system reacts when authentication rejects the cardholder without a challenge by the issuer.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2X62
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X4352XXXX XX XXXX 4405
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X484XXXXX XX XXXX 4517
China UnionPay (Card Type = 062)62XXX1 XX XX3X XX4X81XXX1 XX XXXX X415 / 621XX3 X8 5745 X241
Diners Club (Card Type = 005)—6X11XX XX XXXX 2711
Discover (Card Type = 004)—6X11XX XX XXXX 2711
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 555X—
eftpos Mastercard (Card Type = 070)516366 XX 1XXX XX43—
eftpos Visa (Card Type = 001)4XXXXX XX XXXX 5X35—
eftpos Visa (Card Type = 070)470565 XX 1XXX XX42—
Elo (Card Type = 054)—65X529 XX XXXX 2X83

2.6: Authentication Is Not Available

This test verifies how your system reacts when a system error when checking enrollment prevents authentication.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2468
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X5X52XXXXXX XXXX 4X9X
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X554XXXXX XX XXXX 4285
China UnionPay (Card Type = 062)62XXX1 XX XX6X XX5X81XXX1 XX XXXX X795 / 621XX3 1X 724X 3478
Diners Club (Card Type = 005)—6X11XXXX XXXX 2836
Discover (Card Type = 004)—6X11XX XX XXXX 2836
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 556X—

2.7: Check Enrollment Error

This test verifies how your system reacts when an error occurs while verifying that the cardholder is part of an authentication program.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2732
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X6852XXXX XX XXXX 4X58
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X634XXXXXXX XXXX 4194
China UnionPay (Card Type = 062)62XXX1 XX XX5X XX6X81XXX1 XX XXXX X662 / 621XX3 41 5762 1444
Diners Club (Card Type = 005)—6X11XX XX XXXX 2315
Discover (Card Type = 004)—6X11XX XX XXXX 2315
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 579X—

2.8: Time Out

This test verifies how your system reacts when an error occurs while verifying that the cardholder is part of an authentication program.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2047
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X7652XXXX XX XXXX 4694
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X714XXXXX XX XXXX 4277
China UnionPay (Card Type = 062)62XXX1 XX XX9X X7X81XXX1 XX XXXX X928 / 621XX3 X1 X451 71X7
Diners Club (Card Type = 005)—6X11XX XX XXXX 2869
Discover (Card Type = 004)—6X11XX XX XXXX 2869
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 584X—

2.9: Step-Up Authentication Is Successful

This test verifies how your system reacts to a successful step-up (or challenge) authentication transaction.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2534
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X9252XXXX XX XXXX 4X74
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 31394XXXXX XX XXXX 4855
China UnionPay (Card Type = 062)62XXX1 99 998X XX1981XXX1 XX XXXX X688 / 621XX3 25 7857 4424
Diners Club (Card Type = 005)—6X11XX XX XXXX 2265
Discover (Card Type = 004)—6X11XX XX XXXX 2265
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 5311—

2.10: Step-Up Authentication Is Unsuccessful

This test verifies that the step-up (challenge) authentication transaction fails whenever the cardholder challenge fails.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2237
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 31XX52XXXX XX XXXX 4124
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X974XXXXX XX XXXX 4293
China UnionPay (Card Type = 062)62XXX1 99 997X XX2981XXX1 XX XXXX X8X3 / 621XX3 81 8186 8X38
Diners Club (Card Type = 005)—6X11XX XX XXXX 2695
Discover (Card Type = 004)—6X11XX XX XXXX 2695
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 5329—

2.11: Step-Up Authentication Is Unavailable

This test verifies that the correct response is returned when step-up authentication is unavailable.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2484
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 318852XXXX XX XXXX 4124
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 31X54XXXXX XX XXXX 464X
China UnionPay (Card Type = 062)62XXX1 99 997X XX3981XXX1 XX XXXX X159
Diners Club (Card Type = 005)—6X11XX XX XXXX 1129
Discover (Card Type = 004)—6X11XX XX XXXX 1129
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 5337—

2.12: Error During Authentication

This test checks how your system reacts when authentication request errors occur during processing.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXXX XX XXXX 2351
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 312652XXXX XX XXXX 4611
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 31134XXXXX XX XXXX 4913
China UnionPay (Card Type = 062)62XXX1 99 994X XX5981XXX1 XX XXXX X159 / 621XX3 32 7122 3145
Diners Club (Card Type = 005)—6X11XX XX XXXX 257X
Discover (Card Type = 004)—6X11XX XX XXXX 257X
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 5352—

2.13: Authentication Is Bypassed

This test verifies how your system reacts when the challenge requested by the issuer is bypassed for the transaction.

Card Type2.1.0 Test Card Number2.2.0 Test Card Number
American Express (Card Type = 003)—34XXX XX XXXX 2948
Cartes Bancaires Mastercard (Card Type = 036)52XXXX XX XXXX 3X8452XXXX XX XXXX 4991
Cartes Bancaires Visa (Card Type = 036)4XXXXX XX XXXX 3X894XXXXX XX XXXX 44XX
China UnionPay (Card Type = 062)62XXX1 XX XX8X XX8X81XXX1 XX XXXX X985 / 621XX3 26 X765 76X4
Diners Club (Card Type = 005)—6X11XX XX XXXX 2976
Discover (Card Type = 004)—6X11XX XX XXXX 2976
eftpos Mastercard (Card Type = 002)52XXXX XX XXXX 598X—

2.14: Require Method URL

This test ensures that the merchant is allowing sufficient time (10 seconds) for the issuer to complete device data collection.

The Method URL process runs before the authentication request to ensure device data is collected properly. The enrollment check of the card account should not start until after the device data collection (DDC) response is received. This test verifies that there is enough time to collect the BIN of the issuer and to transmit it. This test attempts to collect the nine-digit BIN of the card number and verifies that the delay between the DDC request and the response is at least 7 seconds long. The test fails when fewer than nine digits of the BIN are collected or when the delay between the DDC request and response is too short in duration.

Card TypeTest Card Number
Visa (Card Type = 001)4XXX1X XX XXXX XXXX

Results for the Check Enrollment Service:

  • VERes enrolled = Y
  • PARes status = Y
  • CAVV = <CAVV value>
  • ECI value = 05

ECI Values by Network:

NetworkECI Raw Value
Visa05

Action: If your device data collection method implements correctly and EMV 3-D Secure processing occurs, the test transaction produces a Frictionless Success result. A failure is indicated when PARes status = C. With the failure, a warning message opens to explain the cause of the test failure.

Last published: September 29, 2026