Skip to content
CardTools

ISO 8583 Data Element Reference

All 128 data elements with formats, lengths and the ones processors love to redefine.

Runs entirely in your browser. Nothing you paste is uploaded, logged or stored.

128 data elements

DENameFormat
1Secondary bitmapPresence is signalled by bit 1 of the primary bitmap, not by bit 1 itself being a data field.b 64
2Primary account number (PAN)sensitivevariablen ..19
3Processing codeThree 2-digit parts: transaction type, from-account, to-account. 00 = purchase, 01 = cash withdrawal, 09 = purchase with cashback, 20 = refund.n 6
4Amount, transactionMinor units of the DE 49 currency, no decimal point.n 12
5Amount, settlementn 12
6Amount, cardholder billingn 12
7Transmission date and timeMMDDhhmmss, UTC.n 10
8Amount, cardholder billing feen 8
9Conversion rate, settlementn 8
10Conversion rate, cardholder billingn 8
11System trace audit number (STAN)Set by the acquirer, echoed unchanged. Only unique within a day, per acquirer — not a global transaction id.n 6
12Time, local transactionhhmmss, terminal local time.n 6
13Date, local transactionMMDD.n 4
14Date, expirationYYMM. Note the order — the opposite of what most UIs collect.n 4
15Date, settlementn 4
16Date, conversionn 4
17Date, capturen 4
18Merchant type (MCC)ISO 18245 merchant category code.n 4
19Acquiring institution country coden 3
20PAN extended country coden 3
21Forwarding institution country coden 3
22Point of service entry modeFirst 2 digits = PAN entry mode (05 chip, 07 contactless chip, 81 e-commerce, 90 full mag-stripe read). Third digit = PIN entry capability.n 3
23Card sequence numbern 3
24Function code / network international identifierRedefined as Function Code in the 1993 edition.n 3
25Point of service condition code00 = normal, 01 = cardholder not present, 08 = mail/telephone order, 59 = e-commerce (scheme-dependent).n 2
26Point of service PIN capture coden 2
27Authorising identification response lengthn 1
28Amount, transaction feex+n 8
29Amount, settlement feex+n 8
30Amount, transaction processing feex+n 8
31Amount, settlement processing feex+n 8
32Acquiring institution identification codevariableThe acquirer BIN. Also the first component of the ARN.n ..11
33Forwarding institution identification codevariablen ..11
34PAN extendedsensitivevariablens ..28
35Track 2 datasensitivevariableFull track 2 read from the stripe or chip equivalent. Storing this post-authorisation breaches PCI DSS.z ..37
36Track 3 datasensitivevariablez ..104
37Retrieval reference number (RRN)Often YDDDhhmmssss or acquirer-proprietary. Used to match auth to clearing — but not globally unique.an 12
38Authorisation identification responseThe auth code the issuer returns. Six characters, alphanumeric.an 6
39Response code00 = approved. Everything else is scheme-specific — see the decline code translator.an 2
40Service restriction codean 3
41Card acceptor terminal identificationans 8
42Card acceptor identification codeThe merchant id (MID).ans 15
43Card acceptor name / locationPositional: name, city, state, country. This is what shows on the cardholder statement.ans 40
44Additional response datavariableCommonly carries AVS and CVV result codes.an ..25
45Track 1 datasensitivevariablean ..76
46Additional data — ISOvariablean ...999
47Additional data — nationalvariablean ...999
48Additional data — privatevariableHeavily used and completely processor-specific. Usually a nested TLV or positional structure.an ...999
49Currency code, transactionISO 4217. Numeric in most implementations.a/n 3
50Currency code, settlementa/n 3
51Currency code, cardholder billinga/n 3
52PIN datasensitiveEncrypted PIN block. Never log this.b 64
53Security related control informationn 16
54Additional amountsvariable20-character groups: account type, amount type, currency, sign, amount. Carries the account balance on ATM responses.an ...120
55ICC data — EMV datavariableBER-TLV. Paste it into the TLV parser.b ...999
56Reserved — ISOvariablean ...999
57Reserved — nationalvariablean ...999
58Reserved — nationalvariablean ...999
59Reserved — nationalvariablean ...999
60Reserved — privatevariableProcessor-specific. Often terminal or POS capability data.an ...999
61Reserved — privatevariableProcessor-specific. Often point-of-service or authorisation data.an ...999
62Reserved — privatevariableProcessor-specific. Visa uses it for transaction identifiers.an ...999
63Reserved — privatevariableProcessor-specific. Frequently a nested TLV structure.an ...999
64Message authentication code (MAC)b 64
65Extended bitmap indicatorPresence signals a tertiary bitmap for fields 129-192.b 64
66Settlement coden 1
67Extended payment coden 2
68Receiving institution country coden 3
69Settlement institution country coden 3
70Network management information code001 = sign-on, 002 = sign-off, 161 = key change, 301 = echo test.n 3
71Message numbern 4
72Message number, lastn 4
73Date, actionn 6
74Credits, numbern 10
75Credits, reversal numbern 10
76Debits, numbern 10
77Debits, reversal numbern 10
78Transfer, numbern 10
79Transfer, reversal numbern 10
80Inquiries, numbern 10
81Authorisations, numbern 10
82Credits, processing fee amountn 12
83Credits, transaction fee amountn 12
84Debits, processing fee amountn 12
85Debits, transaction fee amountn 12
86Credits, amountn 16
87Credits, reversal amountn 16
88Debits, amountn 16
89Debits, reversal amountn 16
90Original data elementsIdentifies the message being reversed: original MTI, STAN, transmission date/time, acquirer id.n 42
91File update codean 1
92File security codean 2
93Response indicatoran 5
94Service indicatoran 7
95Replacement amountsUsed on partial reversals to state the corrected amounts.an 42
96Message security codeb 64
97Amount, net settlementx+n 16
98Payeeans 25
99Settlement institution identification codevariablen ..11
100Receiving institution identification codevariablen ..11
101File namevariableans ..17
102Account identification 1sensitivevariableans ..28
103Account identification 2sensitivevariableans ..28
104Transaction descriptionvariableans ...100
105Reserved for ISO usevariableans ...999
106Reserved for ISO usevariableans ...999
107Reserved for ISO usevariableans ...999
108Reserved for ISO usevariableans ...999
109Reserved for ISO usevariableans ...999
110Reserved for ISO usevariableans ...999
111Reserved for ISO usevariableans ...999
112Reserved for national usevariableans ...999
113Reserved for national usevariablen ..11
114Reserved for national usevariableans ...999
115Reserved for national usevariableans ...999
116Reserved for national usevariableans ...999
117Reserved for national usevariableans ...999
118Reserved for national usevariableans ...999
119Reserved for national usevariableans ...999
120Reserved for private usevariableans ...999
121Reserved for private usevariableans ...999
122Reserved for private usevariableans ...999
123Reserved for private usevariableOften POS data code in Visa implementations.ans ...999
124Reserved for private usevariableans ...999
125Reserved for private usevariableans ...999
126Reserved for private usevariableans ...999
127Reserved for private usevariableans ...999
128Message authentication code (MAC)b 64

Reading the format notation

n
Numeric digits only
a
Alphabetic characters only
s
Special characters
an / ans
Combinations of the above
b
Binary data
z
Track data as defined by ISO 4909 / 7813
n 6
Fixed length — exactly 6 digits
n ..19
Variable, LLVAR — a 2-digit length prefix, up to 19
an ...999
Variable, LLLVAR — a 3-digit length prefix, up to 999
x+n 8
A C/D sign character followed by 8 digits
These are the ISO 8583:1987 definitions. Schemes and processors redefine fields freely — especially 48, 60-63 and 120-127, which are reserved for private use and mean something different on every endpoint. Always check your acquirer's own specification before building against them.

The fields you will actually touch

DE 3, processing code. Six digits in three pairs: transaction type, from-account and to-account. 00 purchase, 01 cash withdrawal, 09 purchase with cashback, 20 refund. The account digits matter for ATMs and are usually zeros elsewhere.

DE 4, amount. Twelve digits, minor units of the DE 49 currency, zero-padded, no decimal point. See the minor units reference for why this bites.

DE 22, POS entry mode. The first two digits say how the card data was captured — 05 chip, 07 contactless chip, 81 e-commerce, 90 full mag-stripe read. Interchange depends heavily on this, so an incorrect value is expensive rather than merely wrong.

DE 39, response code. Two characters. 00 is approval; everything else is scheme-specific and the published meanings are often less useful than the processor's own documentation.

DE 55, ICC data. BER-TLV chip data — feed it to the TLV parser.

Length notation

A fixed field like n 6 is always exactly six digits. A variable field written n ..19 is LLVAR: two length digits followed by up to nineteen data digits. Three dots, as in an ...999, means LLLVAR with a three-digit length prefix. Whether those length prefixes are ASCII digits or packed BCD is, once again, an endpoint decision.

The identifiers that get confused

DE 11 (STAN) is set by the acquirer and echoed back unchanged. It is only unique within a day, per acquirer — it is a matching key, not a transaction id. DE 37 (RRN) is a twelve-character retrieval reference used to tie an authorisation to its clearing record. DE 38 is the six-character authorisation code the issuer returns. None of these is globally unique, and building a system that assumes otherwise is a well-trodden path to duplicate-detection bugs.

A warning about private fields

DE 48, 60-63 and 120-127 are reserved for private use. Two processors will use the same field number for entirely unrelated data. Never assume; always read the specification for the specific endpoint you are integrating with.

More ISO 8583 tools