Authorization
What is authorization?
Authorization is the step in a card payment where the issuing bank checks the account and reserves the transaction amount before any money moves. The merchant sends an authorization request through its and the , and the answers with an approval or a refusal.
Authorization confirms two things: the card is valid and in good standing, and the account holds enough funds or credit to cover the purchase. An approval places a hold on the amount instead of transferring it. The transfer happens later, at and . In the window between the two, the merchant can adjust the amount, release the reservation, or let it lapse.
Key facts
- Also known as: auth, authorization request
- Decided by: the issuer that issued the card
- Effect on funds: the amount is held against the available balance until capture, release, or expiry
- Result: an approval carrying an authorization code, or a refusal carrying a
- Response time: seconds, because the request travels the card network as a single online message
- Duration of the hold: varies by card scheme, issuer, and merchant type
- Applies to: card-present and card-not-present payments, including recurring charges
How it works
- Card details collected. The enters card data at checkout or presents the card at a terminal.
- Request assembled. The merchant's builds an authorization request carrying the card number, amount, currency, and merchant identifiers.
- Routing to the network. The acquiring bank passes the request to the relevant card network, which routes it to the issuing bank.
- Issuer checks. The issuer validates card status, confirms available funds or credit, and screens the transaction for .
- Response returned. The issuer sends back an approval with an authorization code, or a refusal with a decline code naming the reason.
- Hold placed. On approval, the amount is reserved against the cardholder's balance until the merchant captures it, it, or the reservation expires.
Why it matters
- Authorization is the point where the issuer commits to the funds. Fulfilling an order without a valid approval leaves the merchant delivering goods that no bank has agreed to pay for.
- Splitting authorization from capture lets a merchant charge only what it ships. A retailer authorizes the full basket at order time and captures each item as it leaves the warehouse.
- The decline code returned here drives retry logic. A soft decline reflects a temporary condition and can be retried; a hard decline reflects a permanent one, and repeating the request won't change the answer.
- An approved authorization becomes an in the merchant's records, which is what reconciliation, refunds, and dispute responses are matched against later.
Common issues
- Insufficient funds or credit. The account can't cover the amount at the moment of the request. The balance may change within hours, which is why this decline type is a candidate for a scheduled retry.
- Expired reservation. The hold lapses before the merchant captures it. Collecting then requires a fresh authorization or a .
- Amount mismatch. The final charge differs from the approved amount because of tips, shipping, or partial fulfilment. An updates the reserved amount without a new request.
- Authentication required. The issuer refuses the request until the cardholder completes , common where applies.
- Risk-model refusals. The issuer's rejects the transaction on velocity, geography, or device signals. The cardholder sees a generic refusal with no indication of which rule fired.


