Mastercard Reason Code 4837 (No Cardholder Authorization) Explained
Mastercard reason code 4837 covers transactions a cardholder claims were not authorized — the core fraud dispute. You fight it with proof the legitimate cardholder made the purchase: AVS and CVV matches, 3-D Secure authentication, a history of prior undisputed transactions, and delivery to the cardholder's address. Much of it is actually friendly fraud.
Mastercard reason code 4837 is the one that stings, because the customer isn’t complaining about your product — they’re telling their bank they never bought anything from you at all. Understanding what the code actually alleges, and how much of it is really the cardholder crying fraud on their own purchase, is how you stop losing winnable cases.
What Mastercard reason code 4837 means
Mastercard 4837 — No Cardholder Authorization is filed when a cardholder claims a transaction on their account was never authorized by them. It is Mastercard’s primary fraud dispute code. The allegation is that someone other than the legitimate cardholder made the purchase — through a stolen card number, a compromised account, or unauthorized use.
Under Mastercard’s current dispute framework (the reason codes sit in the 48xx family), 4837 applies to both card-present and card-not-present environments, though the vast majority of the ones merchants see are card-not-present ecommerce transactions.
When a 4837 comes in, the issuer has already sided with its cardholder provisionally and pulled the funds. Your path to recovery is representment: submitting evidence that the authentic cardholder — not a fraudster — made and benefited from the purchase.
How 4837 differs from 4863
These two Mastercard codes get confused constantly, and treating them the same way loses cases.
| 4837 — No Cardholder Authorization | 4863 — Cardholder Does Not Recognize | |
|---|---|---|
| Core claim | “I did not authorize this transaction” | “I don’t recognize this charge” |
| Implied allegation | Outright fraud / stolen credentials | Confusion, often over the billing descriptor |
| Typical root cause | Real fraud or friendly fraud | Unclear statement descriptor, forgotten purchase |
| Winning angle | Prove the real cardholder transacted | Jog recognition: descriptor, order details, usage |
With 4863, the customer isn’t accusing you of fraud — they just don’t recognize the line on their statement. Your winning move is to help them recognize it: show the clear billing descriptor, the order, the products, and any account activity. Many 4863 disputes evaporate once the customer connects the charge to a purchase they genuinely made.
With 4837, the accusation is sharper, so your evidence has to directly rebut the idea that a stranger made the purchase. For the full family of Mastercard codes and how they map together, see the Mastercard chargeback reason codes guide and the cross-network reason codes overview.
The evidence that wins a 4837 dispute
Because 4837 alleges the wrong person transacted, everything you submit should tie the purchase to the legitimate cardholder. Assemble as many of these as the order supports:
- 3-D Secure authentication record. If the transaction was authenticated through Mastercard Identity Check and the issuer approved it, liability for the fraud dispute generally shifts to the issuer. This is often the single most decisive piece.
- AVS match. The address the customer entered matched the address on file with the issuing bank — evidence the buyer knew the cardholder’s billing details.
- CVV match. The security code from the physical card was entered correctly, indicating card possession.
- IP address and device fingerprint tying the order to the customer’s location, or to a device they’ve used before.
- Prior transaction history. A record of previous purchases on the same card that were never disputed is powerful — it shows an established, legitimate relationship, not a one-off fraud.
- Proof of delivery to the cardholder’s verified address. If the goods shipped to the address the cardholder controls, a fraudster gaining nothing is a hard story to tell.
- Customer account activity — logins, matching email, phone verification, loyalty history.
The written rebuttal should connect these into one narrative: this transaction was authenticated, the card details matched, the buyer used the cardholder’s address and device, and the goods went to the cardholder — consistent with the real cardholder purchasing, not fraud.
How much of 4837 is actually friendly fraud
Here’s the part that changes how you treat these disputes: a large share of 4837 chargebacks are friendly fraud — the genuine cardholder did authorize the purchase but disputes it anyway. The common drivers:
- Buyer’s remorse repackaged as “I didn’t authorize this”
- Forgotten subscriptions the customer set up and stopped noticing
- Family member use — a spouse or child made the purchase
- Deliberate abuse to keep the product and claw back the money
Because 4837 is a fraud code, these disputes are filed under a fraud banner even when no fraud occurred. That’s frustrating, but it’s also your opening: when your evidence shows the authentic cardholder transacted, authenticated, and received the goods, a “fraud” claim that is really friendly fraud falls apart at representment.
We go deep on the psychology and detection of this in the friendly fraud guide. The practical takeaway: don’t reflexively write off 4837s as unwinnable fraud losses. Check the authentication and delivery evidence first — a meaningful portion are recoverable.
Prevention: stop 4837s before they start
Winning representment is reactive. A few upstream habits cut 4837 volume:
- Enable 3-D Secure for higher-risk or higher-value transactions to shift liability.
- Use a clear billing descriptor so charges are recognizable — this alone prevents many disputes from ever being filed.
- Require CVV and enforce AVS to reject transactions that fail card-possession checks.
- Send detailed receipts and shipping confirmations so the customer always has a record.
Bottom line
Mastercard 4837 alleges no cardholder authorization, but a big slice of it is really the cardholder disputing their own purchase. The winning evidence is anything that proves the legitimate cardholder transacted: 3-D Secure, AVS/CVV, device and IP data, prior undisputed history, and delivery to the cardholder’s address.
Gathering all of that under a tight deadline is where cases are won or lost. DisputeDash detects each 4837 as soon as your processor reports it, pulls the AVS/CVV results, authentication records, IP data, and prior transaction history automatically, builds the fraud-code rebuttal, and submits on time — turning friendly-fraud “fraud” claims back into recovered revenue.
Win more chargebacks, automatically.
DisputeDash gathers the evidence, builds the rebuttal, and submits before the deadline — across Stripe, PayPal, Braintree, PayArc and more. Flat fee, no commission.
Start free — keep 100%