Solidgate logo in black and white.

Authorization

What is authorization?

Authorization is the step in a card payment where the issuing bank checks the account and reserves the transaction amount before any money moves. The merchant sends an authorization request through its and the , and the answers with an approval or a refusal.
Authorization confirms two things: the card is valid and in good standing, and the account holds enough funds or credit to cover the purchase. An approval places a hold on the amount instead of transferring it. The transfer happens later, at and . In the window between the two, the merchant can adjust the amount, release the reservation, or let it lapse.

Key facts

  • Also known as: auth, authorization request
  • Decided by: the issuer that issued the card
  • Effect on funds: the amount is held against the available balance until capture, release, or expiry
  • Result: an approval carrying an authorization code, or a refusal carrying a
  • Response time: seconds, because the request travels the card network as a single online message
  • Duration of the hold: varies by card scheme, issuer, and merchant type
  • Applies to: card-present and card-not-present payments, including recurring charges

How it works

  1. Card details collected. The enters card data at checkout or presents the card at a terminal.
  2. Request assembled. The merchant's builds an authorization request carrying the card number, amount, currency, and merchant identifiers.
  3. Routing to the network. The acquiring bank passes the request to the relevant card network, which routes it to the issuing bank.
  4. Issuer checks. The issuer validates card status, confirms available funds or credit, and screens the transaction for .
  5. Response returned. The issuer sends back an approval with an authorization code, or a refusal with a decline code naming the reason.
  6. Hold placed. On approval, the amount is reserved against the cardholder's balance until the merchant captures it, it, or the reservation expires.

Why it matters

  • Authorization is the point where the issuer commits to the funds. Fulfilling an order without a valid approval leaves the merchant delivering goods that no bank has agreed to pay for.
  • Splitting authorization from capture lets a merchant charge only what it ships. A retailer authorizes the full basket at order time and captures each item as it leaves the warehouse.
  • The decline code returned here drives retry logic. A soft decline reflects a temporary condition and can be retried; a hard decline reflects a permanent one, and repeating the request won't change the answer.
  • An approved authorization becomes an in the merchant's records, which is what reconciliation, refunds, and dispute responses are matched against later.

Common issues

  • Insufficient funds or credit. The account can't cover the amount at the moment of the request. The balance may change within hours, which is why this decline type is a candidate for a scheduled retry.
  • Expired reservation. The hold lapses before the merchant captures it. Collecting then requires a fresh authorization or a .
  • Amount mismatch. The final charge differs from the approved amount because of tips, shipping, or partial fulfilment. An updates the reserved amount without a new request.
  • Authentication required. The issuer refuses the request until the cardholder completes , common where applies.
  • Risk-model refusals. The issuer's rejects the transaction on velocity, geography, or device signals. The cardholder sees a generic refusal with no indication of which rule fired.

Related terms