Mastercard First-Party Trust: How It Works vs. CE3.0

Mastercard First-Party Trust shifts liability to the issuer when device, delivery, and identity data match, unlike CE3.0's prior-purchase requirement.

Mastercard First-Party Trust is a liability-shift program that lets you prove a disputed transaction was genuine, using data the cardholder already gave you. When enough of that data matches, liability for the dispute moves to the issuing bank instead of you.

The question merchants ask me most is whether it works differently from Visa's version. I built dispute evidence on my own stores, where the reason code decided everything I sent. Answer the wrong program's question and you lose a dispute you could have won.

This guide gives you the three data categories that decide whether a Mastercard dispute qualifies.

Key takeaways

  1. 01First-Party Trust shifts dispute liability to the issuing bank when your data matches.
  2. 02Qualifying needs one matching element from each of three data categories.
  3. 03Device, delivery, and identity are the three categories Mastercard checks.
  4. 04Visa CE3.0 requires a prior purchase within 120 to 365 days.
  5. 05Mastercard launched First-Party Trust in the US on October 27, 2024.
  6. 06Alerts stop many disputes earlier, so use First-Party Trust second.

Want fewer of these to reach the evidence stage? Refund a charge before it posts with our dispute alerts.

What is Mastercard First-Party Trust?

Mastercard First-Party Trust shifts dispute liability to the issuing bank when your device, delivery, and identity data matches the disputed transaction. It's built for one case, where the cardholder really did buy it and disputed it anyway.

Mastercard and the issuer compare your data against the charge, and the match itself is the evidence. Your job is to hand over data you already hold. Proving a stranger used a stolen card is a different problem.

Merchants often call these disputes friendly fraud. Our friendly fraud explainer covers why customers file them and how to spot the pattern.

There's one case where this program is useless to you. A stolen-card dispute leaves no matching device, address, or account history for Mastercard to find.

The program does nothing there.

New to Mastercard's dispute rules?

Start with our Mastercard chargeback guide.

Summary: First-Party Trust moves liability to the issuer when your data matches a purchase the cardholder made.

How does First-Party Trust work?

First-Party Trust works by matching your device, delivery, and identity data to the disputed charge, and the issuer rules on that match. You can send the data before a dispute is filed or after it posts.

The two paths do different work. Send the data early and the issuer can show the cardholder what it found, which often gets the claim dropped before a chargeback posts.

Send it after the chargeback posts and the best you get is your money back. Check the notice's reason code first, since that's what tells you whether First-Party Trust is even the right program to try.

Timing decides which of those you get. If you aren't already collecting device and identity data, the late path is your only option, and by then you have paid the fee.

Summary: Data shared before a dispute can stop it, while data shared after can only reverse it.

Who can qualify, and what data do you need?

Any merchant already collecting device and identity data can qualify a transaction, by matching one element from each of three categories. One match per category is enough, and all three have to be covered. Here is what counts inside each one:

  1. Device identity: IP address, device ID, or device fingerprint.
  2. Delivery factor: Shipping address, email address, or telephone number.
  3. Additional identity factor: Account ID, login history, device name, device location, or billing address.

Say a disputed order came from a device the account has logged in with before. It shipped to an address that account has used, and it sat on an account with prior logins.

All three categories are covered, so the transaction qualifies for a liability shift.

Getting the data to Mastercard runs through one of two integration paths. You can send it yourself through Identity Check Insights, using your own 3DS server or the Smart Interface API.

Mastercard can also ask you for it after a chargeback, through the Ethoca Consumer Clarity Merchant Transactions API.

Our Ethoca Consumer Clarity guide covers what that path shows you.

Here is where most merchants guess wrong. A first-time buyer's dispute qualifies too, as long as all three categories match on the disputed order.

Summary: One match per category across device, delivery, and identity qualifies a transaction, new customer or not.

Mastercard First-Party Trust vs. Visa CE3.0

First-Party Trust matches three data categories on the disputed order, while Visa CE3.0 needs a prior undisputed purchase to match against. That difference tells you which disputes each program is worth using on.

Visa CE3.0 matches two data points from the cardholder's earlier undisputed sales, inside a 120 to 365 day window. That leaves first-time buyers out.

Our Visa CE3.0 guide covers its rules and evidence process in full.

First-Party Trust asks a different question. It matches data tied to the disputed order itself, so the history requirement never applies.

Here is how the two compare, point by point:

Mastercard First-Party TrustVisa CE3.0
Evidence requiredOne element each from three categories (device, delivery, identity)Two data points matched to a prior undisputed sale
Timing windowTied to the disputed transactionPrior sale must fall inside 120 to 365 days
New-customer eligibilityQualifies on the disputed order aloneRequires a prior sale, so first-time buyers are out
Integration pathIdentity Check Insights (3DS) or Ethoca Consumer Clarity APIVisa Secure or Data Only

Neither program works across networks.

Each one covers only its own network's cards. Run both Visa and Mastercard volume and you need both, since qualifying for one buys you nothing on the other.

First-Party Trust is a fallback, not a first line of defense

First-Party Trust fights a dispute the cardholder already raised, while alerts stop many of those disputes earlier.

Ethoca Alerts, Mastercard's alert product, matches a dispute inquiry to the transaction. You can then refund it before a chargeback posts.

You don't pay the chargeback fee, and the dispute never counts against your ratio. Both matter if you are watching the Mastercard monitoring program thresholds.

First-Party Trust starts only once the cardholder raises the inquiry. The issuer then has to weigh your data before anything resolves.

Our Ethoca alerts explainer covers what that product sees and how fast.

Alerts have their own limit. If no covered alert fires, the dispute is yours to fight. So is a cardholder who calls their bank directly.

First-Party Trust is what catches those.

Set up alert-based prevention first, then decide up front which alerts you auto-refund and which you fight.

FAQ

When did First-Party Trust launch and where is it available?

Mastercard launched the program in the United States on October 27, 2024. It expanded in 2025 to Canada, Latin America, the Caribbean, and the Asia Pacific region.

Does First-Party Trust stop chargebacks completely?

No. It shifts liability where your data matches, but a cardholder can still file, and any dispute that fails the test stays yours.

Is first-party fraud the same as friendly fraud?

Yes, the two terms describe the same thing. First-party fraud is the network's term and friendly fraud is the merchant's.

Can a first-time customer qualify for First-Party Trust?

Yes. The three-category match runs against the disputed order itself, so no earlier purchase is required.

Diminua sua taxa de disputas hoje

Junte-se a mais de 800 empresas que usam o Chargeback para evitar estornos automaticamente — a configuração leva menos de 2 minutos.