Authorization
Process where issuing bank approves or declines a transaction. Happens in real-time (typically under 3 seconds).
Overview
What is Authorization?
Authorization is the real-time process where the customer's issuing bank approves or declines a payment transaction. When a customer submits payment information, authorization request flows from your merchant account → acquirer → card network → issuing bank, which responds with approval or decline - all within 1-3 seconds. This instant decisioning determines whether the transaction proceeds to settlement (fund transfer) or fails at checkout.
The issuing bank evaluates multiple factors during authorization: available credit (does customer have sufficient funds/limit), account status (is card active, not reported stolen), merchant risk profile (your MCC code and chargeback history), transaction characteristics (amount, geography, velocity), and fraud scoring (does this transaction match customer's normal behavior). High-risk merchants face more aggressive decline decisions because issuers know high-risk MCCs have elevated fraud and dispute rates.
Authorization is not settlement. Authorization simply reserves funds on the customer's card - actual fund transfer happens during settlement 1-2 days later. The authorization places a "hold" on customer credit preventing them from spending those funds elsewhere, but money doesn't move to your account until batch settlement occurs. For high-risk merchants with extended settlement delays (T+3 to T+7), this means 3-7 days between authorization and receiving funds.
Understanding authorization mechanics helps optimize approval rates: soft declines (issuer policies, velocity limits) can be retried through cascading, hard declines (insufficient funds, stolen card) won't succeed regardless of retry attempts, and authorization codes provide evidence for chargeback defense when customers later claim they didn't authorize transactions.
In depth
Everything you need to know.
When a customer clicks "Pay," your payment gateway encrypts card data and sends an authorization request to your PSP. The request includes: card number, expiration date, CVV, transaction amount, currency, merchant identification number (MID), customer billing address, and device/IP information. Your PSP routes the request to the appropriate card network (Visa/Mastercard) based on card BIN. The network forwards to the issuing bank, which runs real-time decisioning algorithms: checking if card is active and not reported stolen, verifying available credit exceeds transaction amount, evaluating merchant risk score (your MCC and chargeback history), analyzing transaction characteristics (amount, location, time), comparing against cardholder's spending patterns for fraud detection, and applying velocity rules (limits on transaction frequency). This entire process takes 500ms-3 seconds. The issuing bank returns a response code: approved (with authorization code for settlement), declined (with reason code), or error. Your gateway receives the response and displays appropriate message to customer.
Authorization approval rates directly determine revenue. A merchant with $2M monthly in attempted transactions at 70% approval rate generates $1.4M revenue - 30% of sales ($600K monthly) fail at authorization. Improving approval to 80% recovers $200K monthly or $2.4M annually with zero increase in customer acquisition costs. For high-risk merchants, understanding authorization decline reasons enables optimization: soft declines from fraud filters can be addressed with 3D Secure authentication, issuer risk policy declines can be mitigated with smart routing to acquirers with better issuer relationships, velocity limit declines suggest need for multiple MIDs to distribute transaction load. Authorization speed impacts conversion rates. Customers abandon checkout if authorization takes over 5 seconds - slow PSP response times (3-5 seconds) combined with multiple retry attempts (cascading) can push total checkout time to 8-12 seconds, increasing abandonment by 15-30%. Premium PSPs with optimized network connections maintain <1.5 second authorization times.
Illustrative example — not a specific client engagement.
- A nutra merchant with 65% approval rate analyzed decline codes and discovered 40% were soft declines (fraud filters, velocity limits). Implementing cascading to retry soft declines through a backup PSP improved overall approval rate to 74%, recovering $180K monthly in previously lost revenue.
- An iGaming operator noticed authorization times averaging 3.8 seconds during peak hours, correlating with 12% checkout abandonment. Switching to a premium PSP with optimized network routing reduced authorization times to 1.2 seconds, decreasing abandonment to 8% and recovering $85K monthly.
- A supplement merchant stored authorization codes for all transactions. When hit with 50 friendly fraud chargebacks monthly (customers claiming they never authorized purchases), they successfully won 68% of representments by providing authorization codes proving issuing banks approved the transactions - recovering $18K monthly.
- Implement cascading to retry soft declines through backup PSPs - recovers 10-15% of initially declined transactions
- Track authorization metrics by card type, geography, transaction amount - identify patterns in declines to optimize routing
- Include comprehensive fraud data in authorization requests: AVS, CVV, 3D Secure, device fingerprinting - improves approval rates
- Use smart routing to send transactions to PSPs with best approval rates for each card type and geography
- Monitor authorization response times - if average exceeds 2 seconds, investigate PSP performance issues
- Store authorization codes for chargeback defense - proves transaction was bank-approved when customers claim unauthorized charges
- For high-volume merchants: negotiate direct card network connections to reduce authorization latency by 200-500ms
- Treating all declines as final - 30-40% of soft declines approve when retried through different PSPs via cascading
- Not tracking decline reason codes - operating blind to whether declines are fraud filters, insufficient funds, or issuer policies
- Requesting authorization without adequate fraud data - sending requests without AVS/CVV increases issuer decline rates by 15-25%
- Not distinguishing authorization from settlement - thinking funds are in your account when authorization succeeds (actual funding is 1-7 days later)
- Accepting all authorizations regardless of fraud scores - approving high-risk transactions that will later chargeback
- Using single PSP for all authorizations - missing optimization from routing different transaction types to specialized acquirers
Keep exploring
Related terms
Put this to work
for your business.
MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.