Skip to content

Response codes reference

Action and response codes across ISO 8583 DE 39, Visa, Mastercard, American Express, Discover and UPI. Filter by scheme, search by code or meaning, and read the provenance badge — because not every code in circulation is officially published.

Provenance ISO standard Scheme-published Community

114 codes

Code Scheme Meaning Notes Provenance
00 ISO 8583 (DE 39) Approved or completed successfully ISO standard
01 ISO 8583 (DE 39) Refer to card issuer ISO standard
02 ISO 8583 (DE 39) Refer to card issuer, special condition ISO standard
03 ISO 8583 (DE 39) Invalid merchant ISO standard
04 ISO 8583 (DE 39) Pick up card No fraud suspected; capture the card if able. ISO standard
05 ISO 8583 (DE 39) Do not honour The generic issuer decline; no reason given. ISO standard
06 ISO 8583 (DE 39) Error ISO standard
07 ISO 8583 (DE 39) Pick up card, special condition Fraud suspected. ISO standard
08 ISO 8583 (DE 39) Honour with identification ISO standard
09 ISO 8583 (DE 39) Request in progress ISO standard
10 ISO 8583 (DE 39) Approved for partial amount ISO standard
11 ISO 8583 (DE 39) Approved (VIP) ISO standard
12 ISO 8583 (DE 39) Invalid transaction ISO standard
13 ISO 8583 (DE 39) Invalid amount ISO standard
14 ISO 8583 (DE 39) Invalid card number (no such number) ISO standard
15 ISO 8583 (DE 39) No such issuer ISO standard
16 ISO 8583 (DE 39) Approved, update track 3 ISO standard
17 ISO 8583 (DE 39) Customer cancellation ISO standard
18 ISO 8583 (DE 39) Customer dispute ISO standard
19 ISO 8583 (DE 39) Re-enter transaction ISO standard
20 ISO 8583 (DE 39) Invalid response ISO standard
21 ISO 8583 (DE 39) No action taken ISO standard
22 ISO 8583 (DE 39) Suspected malfunction ISO standard
23 ISO 8583 (DE 39) Unacceptable transaction fee ISO standard
24 ISO 8583 (DE 39) File update not supported by receiver ISO standard
25 ISO 8583 (DE 39) Unable to locate record on file ISO standard
26 ISO 8583 (DE 39) Duplicate file update record ISO standard
27 ISO 8583 (DE 39) File update field edit error ISO standard
28 ISO 8583 (DE 39) File update record locked out ISO standard
29 ISO 8583 (DE 39) File update not successful, contact acquirer ISO standard
30 ISO 8583 (DE 39) Format error A field is malformed or a required field is missing. ISO standard
31 ISO 8583 (DE 39) Bank not supported by switch ISO standard
32 ISO 8583 (DE 39) Completed partially ISO standard
33 ISO 8583 (DE 39) Expired card, pick up ISO standard
34 ISO 8583 (DE 39) Suspected fraud, pick up ISO standard
35 ISO 8583 (DE 39) Card acceptor contact acquirer, pick up ISO standard
36 ISO 8583 (DE 39) Restricted card, pick up ISO standard
37 ISO 8583 (DE 39) Card acceptor call acquirer security, pick up ISO standard
38 ISO 8583 (DE 39) Allowable PIN tries exceeded, pick up ISO standard
39 ISO 8583 (DE 39) No credit account ISO standard
40 ISO 8583 (DE 39) Requested function not supported ISO standard
41 ISO 8583 (DE 39) Lost card, pick up ISO standard
42 ISO 8583 (DE 39) No universal account ISO standard
43 ISO 8583 (DE 39) Stolen card, pick up ISO standard
44 ISO 8583 (DE 39) No investment account ISO standard
51 ISO 8583 (DE 39) Not sufficient funds ISO standard
52 ISO 8583 (DE 39) No cheque account ISO standard
53 ISO 8583 (DE 39) No savings account ISO standard
54 ISO 8583 (DE 39) Expired card ISO standard
55 ISO 8583 (DE 39) Incorrect PIN ISO standard
56 ISO 8583 (DE 39) No card record ISO standard
57 ISO 8583 (DE 39) Transaction not permitted to cardholder ISO standard
58 ISO 8583 (DE 39) Transaction not permitted to terminal ISO standard
59 ISO 8583 (DE 39) Suspected fraud ISO standard
60 ISO 8583 (DE 39) Card acceptor contact acquirer ISO standard
61 ISO 8583 (DE 39) Exceeds withdrawal amount limit ISO standard
62 ISO 8583 (DE 39) Restricted card e.g. a country or region restriction on the card. ISO standard
63 ISO 8583 (DE 39) Security violation ISO standard
64 ISO 8583 (DE 39) Original amount incorrect ISO standard
65 ISO 8583 (DE 39) Exceeds withdrawal frequency limit ISO standard
66 ISO 8583 (DE 39) Card acceptor call acquirer's security department ISO standard
67 ISO 8583 (DE 39) Hard capture, pick up card at ATM ISO standard
68 ISO 8583 (DE 39) Response received too late The issuer replied after the switch timed out. ISO standard
75 ISO 8583 (DE 39) Allowable number of PIN tries exceeded ISO standard
90 ISO 8583 (DE 39) Cutoff is in progress ISO standard
91 ISO 8583 (DE 39) Issuer or switch is inoperative The issuer could not be reached; often retryable. ISO standard
92 ISO 8583 (DE 39) Financial institution or intermediate network facility cannot be found for routing ISO standard
93 ISO 8583 (DE 39) Transaction cannot be completed, violation of law ISO standard
94 ISO 8583 (DE 39) Duplicate transmission ISO standard
95 ISO 8583 (DE 39) Reconcile error ISO standard
96 ISO 8583 (DE 39) System malfunction ISO standard
98 ISO 8583 (DE 39) Duplicate transaction ISO standard
1A Visa Additional customer authentication required Strong customer authentication (SCA) step-up needed; re-attempt with 3-D Secure. Scheme-published
N7 Visa Decline for CVV2 failure The CVV2 supplied did not match. Scheme-published
R0 Visa Stop payment order Cardholder has requested a stop on this specific recurring payment. Scheme-published
R1 Visa Revocation of authorization order Cardholder has revoked authorization for this merchant. Scheme-published
R3 Visa Revocation of all authorizations order Cardholder has revoked all recurring authorizations. Scheme-published
N0 Visa Force STIP Issuer directs the transaction to stand-in processing. Community
N3 Visa Cash service not available Community
N4 Visa Cashback request exceeds issuer limit Community
P5 Visa PIN change / unblock request declined Community
Q1 Visa Card authentication failed Community
Z3 Visa Unable to go online, offline-declined Community
1A Mastercard Additional customer authentication required SCA step-up needed; re-attempt with 3-D Secure. Scheme-published
70 Mastercard Contact card issuer / PIN data required Community
71 Mastercard Decline, PIN not changed Community
79 Mastercard Life-cycle decline, invalid or expired product One of Mastercard's decline categories; a soft decline for recurring. Community
82 Mastercard Policy decline, count exceeded / security Community
83 Mastercard Fraud/security decline Community
000 American Express Approved Amex Global Credit Auth Guide numbering; equivalent to ISO 00. Community
100 American Express Deny Community
101 American Express Expired card Community
106 American Express Exceeded PIN attempts Community
107 American Express Please call issuer Community
109 American Express Invalid merchant Community
110 American Express Invalid amount Community
111 American Express Invalid card number Community
121 American Express Exceeds withdrawal limit Community
181 American Express Format error Community
200 American Express Deny, pick up card Community
1A Discover Additional customer authentication required SCA step-up; re-attempt with 3-D Secure. Otherwise Discover follows the ISO DE 39 numeric set. Community
5A Discover Additional authentication data required Community
U16 UPI (NPCI) Risk threshold exceeded Community
U17 UPI (NPCI) PSP not available Community
U28 UPI (NPCI) Beneficiary bank offline or unavailable Community
U30 UPI (NPCI) Debit has failed Community
U54 UPI (NPCI) Transaction / collect request expired Community
U67 UPI (NPCI) Debit timeout / deemed approved pending Community
U69 UPI (NPCI) Collect request expired Community
Z6 UPI (NPCI) Number of PIN tries exceeded Community
Z9 UPI (NPCI) Insufficient funds in payer account Community
ZA UPI (NPCI) Transaction declined by customer Community
ZH UPI (NPCI) Invalid virtual address (VPA) Community
ZM UPI (NPCI) Invalid MPIN Community

Notes

What is DE 39?
Data Element 39 is the action/response code in an ISO 8583 message — the two-character field the issuer or switch sets to say what happened. "00" is approved; everything else is a decline, referral or system condition. The numeric set here is the ISO 8583:1987 standard; the schemes layer their own codes on top.
What does the provenance badge mean?
It says how authoritative an entry is. "ISO standard" is the published ISO 8583 numeric set. "Scheme-published" is documented in the scheme's own public response-code material. "Community" is widely used and cross-referenced but has no authoritative public source — treat the wording as a guide and confirm it against your acquirer or scheme specification.
Why are Amex, Discover and UPI thinner than Visa and Mastercard?
Because their public documentation is thinner. Rather than present invented meanings as fact, only the codes that can be reasonably sourced are listed, most of them tagged "community". The dataset is structured so more can be added per scheme without changing anything else.
A code is missing or I think one is wrong.
This is a debugging aid, not a certified reference. Response-code meanings vary by acquirer, region and message version, and the same numeric code can carry a scheme-specific nuance. When this reference disagrees with your specification, trust the specification.

These are debugging aids, not certified reference implementations. If a tool disagrees with your specification, trust the specification.