Decline code
What is a decline code?
Decline code is a numerical or alphanumeric identifier a card returns when it refuses an request. Each code corresponds to a specific reason for the rejection, such as insufficient funds, an expired card, suspicious activity, or a credit limit already reached.
The code travels back through the to the and the , which surfaces it to the merchant in the API response and in reporting. It sits in ISO 8583 data element 39, a two-character field, so the same value can be read slightly differently depending on the issuer's region and the card brand's own interpretation. Merchants read it to decide what the checkout should tell the and whether a retry has any chance of succeeding.
Key facts
- Also known as: response code, authorization response code, issuer response code
- Where it sits: ISO 8583 data element 39, a two-character alphanumeric field
- Returned by: the issuer, or by the card network on the issuer's behalf when the issuer host is unreachable
- Two categories: soft declines (temporary, retryable) and hard declines (permanent, not retryable)
- Mastercard supplement: accompany some Mastercard declines and carry explicit retry timing that overrides the ISO code
Types of decline codes
Soft declines report a temporary condition on the issuer's side: not enough balance, a velocity limit that resets, or an issuer host that is offline. Codes 51 (insufficient funds), 61 (exceeds withdrawal limit), 91 (issuer or switch inoperative) and 96 (system malfunction) sit in this group. A later attempt can clear, which is why schedules in subscription billing are built around them.
Hard declines report a permanent condition on the account or the card itself. Codes 14 (invalid card number), 41 (lost card), 43 (stolen card), 46 (closed account) and 54 (expired card) return the same result on every attempt with the same credentials. Repeated retries against a hard decline add and pull the merchant's approval rate down without recovering revenue.
Code 05, do not honor, sits between the two. Issuers use it as a catch-all when they don't want to reveal the real reason, and a block frequently arrives under it. Classification varies by acquirer and card brand, so a code treated as retryable on one processing path can be final on another.
Common decline codes
The values below follow the ISO 8583 definitions Visa and Mastercard use; a regional issuer can apply a code more narrowly than the standard suggests.
| Code | Meaning | Category |
| 04 | Pick up card | Hard |
| 05 | Do not honor | Soft, issuer catch-all |
| 14 | Invalid card number | Hard |
| 41 | Lost card | Hard |
| 43 | Stolen card | Hard |
| 46 | Closed account | Hard |
| 51 | Insufficient funds | Soft |
| 54 | Expired card | Hard, needs updated card data |
| 57 | Transaction not permitted to cardholder | Hard |
| 59 | Suspected fraud | Soft |
| 61 | Exceeds withdrawal limit | Soft |
| 62 | Restricted card | Soft |
| 65 | Exceeds withdrawal frequency | Soft |
| 82 | CVV mismatch | Data quality |
| 91 | Issuer or switch inoperative | Soft |
| 96 | System malfunction | Soft |
Why it matters
- Retry logic depends on it. A resubmitted against code 54 fails every time, while the same resubmission against 91 clears once the issuer host is back online.
- Card brands cap resubmissions. Visa and Mastercard each limit how many times a declined authorization can be retried within a rolling window, and attempts past the cap are blocked until the window resets. The exact limits differ by scheme and acquirer.
- The decline mix exposes integration faults. A spike in code 14 or 82 points at checkout data capture rather than at issuer behavior, which separates a from a genuine issuer refusal.
- Messaging changes with the reason. Code 51 and code 54 need different checkout copy: one sends the cardholder to another funding source, the other to updated card details.

