Skip to main content
This page is the single reference for 3D Secure statuses, ECI values and error codes across 3DS with Elements, Challenge presentation and Your own 3DS provider. For the recovery-action version of the same errors, see Handle 3D Secure failures in Elements.

Status meanings

threeDS.authenticate() and threeDS.resume() resolve with { status, ref }. A decline resolves — it never throws. Use the status only to drive your UX; your server action is the same regardless (see Server policy). PENDING and DECOUPLED are intermediate states the SDK handles internally (polling on your behalf) and are never returned as a final result — see Decoupled authentication.
Whatever the status, your server must still independently verify the ref at charge time. Never skip that check because the client reported AUTHENTICATED — see Server policy.

ECI meanings

The electronic commerce indicator (ECI) records how strongly a card scheme backs an authentication, and whether liability shifts to the issuer. RadiumOne’s own 3DS flow doesn’t currently return the ECI to your server. If you use your own 3DS provider, you submit the ECI yourself; see the full ECI table there.

SDK errors

These are thrown by threeDS.authenticate()/resume() in the browser, before your server is ever involved:

Gateway errors

These come from the gateway, either while authenticating (authenticate()/ resume() calls) or at the purchase/authorize call itself:
Never use a secret key (r1sk_…) in browser code, mobile apps, or anywhere a shopper can inspect it. Secret keys belong on your server only.

Next steps

3DS with Elements

Where these statuses and errors come from in the authenticate/charge flow.

Use your own 3DS provider

ECI values you submit yourself on this path.
Last modified on September 15, 2026