Message extensions carry data the core specification does not define, as a JSON list in the Message Extension element: at most 15 extensions and 81,920 characters in total, each with a name and an identifier of up to 64 characters (prefixed with the payment system's registered application provider identifier), a criticality flag and data of up to 8,059 characters. The party that defines an extension sets its format and identifier. A critical extension (criticality true) must be recognised and processed by every recipient: an application that meets an unrecognised critical extension treats the message as invalid and returns Error Code 202, and only EMVCo assigns critical extensions; a non-critical one that a recipient does not recognise is ignored and passed on unchanged. Each ACS protocol version entry in the card range data can list up to 15 supported extensions by EMVCo identifier and version number (per Bulletin 255). EMVCo's own extensions named in 2.3.1.1 are Bridging, Device Acknowledgement, Payment Token and Travel Industry; the Attribute Verification extension came later (V.16).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.