Data-Only: Mastercard Use Cases
3-D Secure Data Only is a solution that shares data that merchants collect during transactions with the issuer, so that the issuers can make more informed authorization decisions for future transactions. Data Only uses the 3-D Secure infrastructure, but it is not a complete 3-D Secure authentication. 3-D Secure Data Only is a frictionless experience.
Mastercard has two options for Data Only:
- Mastercard Data Share Only: This option mirrors the Visa Data Only program by allowing the AReq message to reach the Issuer. The Issuer can then obtain all of the enhanced data and link that information on the authorization message.
- Mastercard Identity Check Insights: This option stops the AReq at the Mastercard Directory Server. Mastercard returns a Data Only response to the merchant and then passes a risk score outside of the transaction flow to the Issuer that the Issuer can append to the authorization to aid in their decision process.
Mastercard Data Only (Data Share Only)
Mastercard has a Data Only data flow so that merchants can share customer data with the issuers without going through authentication. Data Only data flows are frictionless and do not affect the customer experience.
When sending a Mastercard Data Only check enrollment request, be sure to include all of the required fields and set the consumerAuthenticationInformation.challengeCode to 06.
The response from the Data Only request includes this data:
- ECI =
06 - CAVV value
- Directory server transaction ID
- paresStatus =
I - Risk score
- Reason code
This data from the response must be included in the authorization request.
POST /pts/v2/payments
POST /pts/v2/payments
POST /pts/v2/payments
Example: Mastercard Data Only
{ "clientReferenceInformation": { "code": "test" }, "customerInformation": { "merchantCustomerId": "SW489TT19" }, "orderInformation": { "amountDetails": { "currency": "USD", "totalAmount": "10.99" }, "billTo": { "address1": "1 Market St", "address2": "Address 2", "administrativeArea": "CA", "country": "US", "locality": "san francisco", "firstName": "Test", "lastName": "Testlastname", "phoneNumber": "4158880000", "email": "[email protected]", "postalCode": "94105" } }, "paymentInformation": { "card": { "expirationMonth": "05", "expirationYear": "2029", "number": "52XXXXXXXXXX28X5" } }, "deviceInformation": { "httpAcceptBrowserValue": "data", "httpAcceptContent": "pa_http_user_accept_value", "httpBrowserLanguage": "en_us", "httpBrowserJavaEnabled": false, "httpBrowserJavaScriptEnabled": false, "httpBrowserColorDepth": "24", "httpBrowserScreenHeight": "864", "httpBrowserScreenWidth": "1536", "httpBrowserTimeDifference": "300", "userAgentBrowserValue": "123" }, "consumerAuthenticationInformation": { "deviceChannel": "Browser", "challengeCode": "06", "scoreRequest": "N" }}{ "clientReferenceInformation": { "code": "test" }, "consumerAuthenticationInformation": { "eciRaw": "06", "challengeRequired": "N", "authenticationTransactionId": "KjNeRerYgMLXJD8gzC51", "effectiveAuthenticationType": "FR", "eci": "06", "cavv": "AJkBBkhgQQAAAE4gSEJydQAAAAA=", "paresStatus": "I" }, "status": "AUTHENTICATION_SUCCESSFUL", "submitTimeUtc": "2025-04-25T10:58:45Z"}Example: Bundled Authentication and Authorization with Mastercard Data Only
{ "clientReferenceInformation": { "code": "test" }, "customerInformation": { "merchantCustomerId": "SW489TT19" }, "orderInformation": { "amountDetails": { "currency": "USD", "totalAmount": "10.99" }, "billTo": { "address1": "1 Market St", "address2": "Address 2", "administrativeArea": "CA", "country": "US", "locality": "san francisco", "firstName": "Test", "lastName": "Testlastname", "phoneNumber": "4158880000", "email": "[email protected]", "postalCode": "94105" } }, "processingInformation": { "actionList": [ "CONSUMER_AUTHENTICATION" ] }, "paymentInformation": { "card": { "expirationMonth": "05", "expirationYear": "2029", "number": "52XXXXXXXXXX28X5" } }, "deviceInformation": { "httpAcceptBrowserValue": "data", "httpAcceptContent": "pa_http_user_accept_value", "httpBrowserLanguage": "en_us", "httpBrowserJavaEnabled": false, "httpBrowserJavaScriptEnabled": false, "httpBrowserColorDepth": "24", "httpBrowserScreenHeight": "864", "httpBrowserScreenWidth": "1536", "httpBrowserTimeDifference": "300", "userAgentBrowserValue": "123" }, "consumerAuthenticationInformation": { "deviceChannel": "Browser", "challengeCode": "06", "scoreRequest": "N" }}{ "consumerAuthenticationInformation": { "eciRaw": "06", "effectiveAuthenticationType": "FR", "eci": "06", "cavv": "AJkBBkhgQQAAAE4gSEJydQAAAAA=", "paresStatus": "I" }, "status": "AUTHORIZED", "submitTimeUtc": "2025-04-25T10:58:45Z"}Required Fields for Mastercard Data Only
These fields are the minimum fields required when you request the Mastercard Data service.
| Field | Description |
|---|---|
buyerInformation.mobilePhone | This field is required (when available) if buyerInformation.workPhone is not used, unless market or regional mandate restricts sending this information. |
buyerInformation.workPhone | This field is required (when available) if buyerInformation.mobilePhone is not used, unless market or regional mandate restricts sending this information. |
clientReferenceInformation.code | |
consumerAuthenticationInformation.challengeCode | Set to 06 for data only. |
deviceInformation.httpAcceptBrowserValue | |
deviceInformation.httpAcceptContent | |
deviceInformation.httpBrowserColorDepth | |
deviceInformation.httpBrowserJavaEnabled | |
deviceInformation.httpBrowserJavaScriptEnabled | |
deviceInformation.httpBrowserLanguage | |
deviceInformation.httpBrowserScreenHeight | |
deviceInformation.httpBrowserScreenWidth | |
deviceInformation.httpBrowserTimeDifference | |
deviceInformation.ipAddress | |
deviceInformation.userAgentBrowserValue | |
orderInformation.amountDetails.currency | |
orderInformation.amountDetails.totalAmount | |
orderInformation.billTo.address1 | |
orderInformation.billTo.administrativeArea | This field is required for the US and Canada. |
orderInformation.billTo.country | |
orderInformation.billTo.email | |
orderInformation.billTo.firstName | |
orderInformation.billTo.lastName | |
orderInformation.billTo.locality | |
orderInformation.billTo.postalCode | |
paymentInformation.card.expirationMonth | |
paymentInformation.card.expirationYear | |
paymentInformation.card.number |
Mastercard Identity Check Insights (IDCI)
Mastercard has an IDCI data flow so that merchants can share customer data with the issuers without going through authentication. Unlike the Data Only flow, the AReq remains at the Mastercard Directory Server. Using the device information and additional data, Mastercard calculates a risk score for the transaction that is then shared with the issuer during authorization. Mastercard IDCI data flows are frictionless and do not affect the customer experience.
When sending a Mastercard IDCI check enrollment request, be sure to include all of the required fields and set the consumerAuthenticationInformation.messageCategory to 80.
The response from the IDCI request includes this data:
- ECI =
04 - CAVV value
- Directory server transaction ID
- paresStatus =
U - Risk score
- Reason code
This data from the response must be included in the authorization request.
POST /pts/v2/payments
POST /pts/v2/payments
POST /pts/v2/payments
Example: Mastercard IDCI
{ "clientReferenceInformation": { "code": "test" }, "customerInformation": { "merchantCustomerId": "SW489TT19" }, "orderInformation": { "amountDetails": { "currency": "USD", "totalAmount": "10.99" }, "billTo": { "address1": "1 Market St", "address2": "Address 2", "administrativeArea": "CA", "country": "US", "locality": "san francisco", "firstName": "Test", "lastName": "Testlastname", "phoneNumber": "4158880000", "email": "[email protected]", "postalCode": "94105" } }, "paymentInformation": { "card": { "expirationMonth": "05", "expirationYear": "2029", "number": "52XXXXXXXXXX28X5" } }, "deviceInformation": { "httpAcceptBrowserValue": "data", "httpAcceptContent": "pa_http_user_accept_value", "httpBrowserLanguage": "en_us", "httpBrowserJavaEnabled": false, "httpBrowserJavaScriptEnabled": false, "httpBrowserColorDepth": "24", "httpBrowserScreenHeight": "864", "httpBrowserScreenWidth": "1536", "httpBrowserTimeDifference": "300", "userAgentBrowserValue": "123" }, "consumerAuthenticationInformation": { "deviceChannel": "Browser", "messageCategory": "80", "scoreRequest": "N" }}{ "consumerAuthenticationInformation": { "eciRaw": "04", "challengeRequired": "N", "authenticationTransactionId": "abc123XYZ789", "effectiveAuthenticationType": "FR", "eci": "04", "cavv": "AJkBBkhgQQAAAE4gSEJydQAAAAA=", "paresStatus": "U" }, "status": "AUTHENTICATION_SUCCESSFUL", "submitTimeUtc": "2025-04-25T10:58:45Z"}Example: Bundled Authentication and Authorization with Mastercard IDCI
{ "clientReferenceInformation": { "code": "test" }, "orderInformation": { "amountDetails": { "currency": "USD", "totalAmount": "10.99" }, "billTo": { "address1": "1 Market St", "administrativeArea": "CA", "country": "US", "locality": "san francisco", "firstName": "Test", "lastName": "Testlastname", "phoneNumber": "4158880000", "email": "[email protected]", "postalCode": "94105" } }, "processingInformation": { "actionList": [ "CONSUMER_AUTHENTICATION" ] }, "paymentInformation": { "card": { "expirationMonth": "05", "expirationYear": "2029", "number": "52XXXXXXXXXX28X5" } }, "deviceInformation": { "httpAcceptBrowserValue": "data", "httpAcceptContent": "pa_http_user_accept_value", "httpBrowserLanguage": "en_us", "httpBrowserJavaEnabled": false, "httpBrowserJavaScriptEnabled": false, "httpBrowserColorDepth": "24", "httpBrowserScreenHeight": "864", "httpBrowserScreenWidth": "1536", "httpBrowserTimeDifference": "300", "userAgentBrowserValue": "123" }, "consumerAuthenticationInformation": { "deviceChannel": "Browser", "messageCategory": "80", "scoreRequest": "N" }}{ "consumerAuthenticationInformation": { "eciRaw": "04", "effectiveAuthenticationType": "FR", "eci": "04", "cavv": "AJkBBkhgQQAAAE4gSEJydQAAAAA=", "paresStatus": "U" }, "status": "AUTHORIZED", "submitTimeUtc": "2025-04-25T10:58:45Z"}Required Fields for Mastercard IDCI
| Field | Description |
|---|---|
buyerInformation.mobilePhone | This field is required (when available) if buyerInformation.workPhone is not used. |
buyerInformation.workPhone | This field is required (when available) if buyerInformation.mobilePhone is not used. |
clientReferenceInformation.code | |
consumerAuthenticationInformation.messageCategory | Set to 80 for IDCI. |
deviceInformation.httpAcceptBrowserValue | |
deviceInformation.httpAcceptContent | |
deviceInformation.httpBrowserColorDepth | |
deviceInformation.httpBrowserJavaEnabled | |
deviceInformation.httpBrowserJavaScriptEnabled | |
deviceInformation.httpBrowserLanguage | |
deviceInformation.httpBrowserScreenHeight | |
deviceInformation.httpBrowserScreenWidth | |
deviceInformation.httpBrowserTimeDifference | |
deviceInformation.ipAddress | |
deviceInformation.userAgentBrowserValue | |
orderInformation.amountDetails.currency | |
orderInformation.amountDetails.totalAmount | |
orderInformation.billTo.address1 | |
orderInformation.billTo.administrativeArea | |
orderInformation.billTo.country | |
orderInformation.billTo.email | |
orderInformation.billTo.firstName | |
orderInformation.billTo.lastName | |
orderInformation.billTo.locality | |
orderInformation.billTo.postalCode | |
paymentInformation.card.expirationMonth | |
paymentInformation.card.expirationYear | |
paymentInformation.card.number |
Thanks for your feedback!
Last published: September 29, 2026