Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
GlobalPlatform 2.3.1

GlobalPlatform Status Words

Status words returned by GlobalPlatform 2.3.1 card-management commands (INSTALL, LOAD, DELETE, GET STATUS, GET DATA). Drawn from GPC §11.

What this reference covers

Spec

GlobalPlatform Card Specification 2.3.1 §11.

What this reference does not cover

The status words here are those returned by GlobalPlatform card-management commands. They are not application status words: once your applet is selected and running, the codes it returns are defined by that applet's own specification, not by GlobalPlatform. If a value is missing from this table, check whether the command was actually addressed to a security domain rather than to an application.

Version matters too. This tracks GlobalPlatform 2.3.1; earlier cards may return values since redefined, and vendor security domains routinely add proprietary codes outside the specified ranges. Treat an unrecognised value as vendor-specific and consult the card documentation rather than assuming a generic meaning.

Frequently asked questions

What does GlobalPlatform define?

Card content management: how applications are loaded, installed, made selectable and deleted, and the security domains and secure channel protocols that authorise those operations.

Which commands do these status words cover?

The card-management set — INSTALL, LOAD, DELETE and GET STATUS — as used against a security domain.

Why does a management command return 6982?

Security status not satisfied: no authenticated secure channel, or a security domain without the privilege for the operation.

What does 6A88 mean?

Referenced data not found — typically an AID that is not present on the card, which usually means a load order problem rather than a malformed command.

What is the Issuer Security Domain?

The on-card representation of the card issuer, holding the keys and privileges that authorise content management.