Authorization: the first journey
How a tap becomes an approval in seconds: the ISO 8583 request and response, the authorisation hold, and what happens when the issuer cannot answer.
IN ONE LINE
An everyday analogy: authorisation is a phone call, not a payment.
When a card is tapped, the terminal in effect rings the cardholder's bank and asks: will you stand behind this amount? The answer comes back within seconds — yes with a code, or no with a reason.
Nothing has been paid yet; the bank has only promised, and set the amount aside so the promise can be kept.
At Demo Coffee Ltd, Maya Chen's tap travels from the terminal to Meridian Bank, the merchant's acquirer, through the Cardnet network — a fictional stand-in for Visa- or Mastercard-style networks — to Bank Alfa, her issuer; the answer retraces the same path.
(SYNTHETIC / TRAINING ONLY — all names fictional.) The money itself makes a separate, slower journey later — that second journey is the next topic.
WHAT IT ACTUALLY IS
Authorisation runs on a messaging standard called ISO 8583.
The terminal reads the card — EMV chip, contactless tap, or typed-in details online — and builds an authorization request, message type 0100, carrying the PAN (primary account number), the amount, merchant details and, for chip and contactless, a one-time cryptogram.
The acquirer forwards it to the network, which reads the BIN (bank identification number — the PAN's leading digits) to route it to the right issuer.
The issuer checks the account, limits and fraud signals, then answers with a 0110 response: approved, carrying an authorisation code, or declined with a reason.
Approval creates an authorisation hold: the amount is earmarked and reduces what the cardholder can spend, but no money has moved.
Card-present and card-not-present payments ride the same message legs; they differ in how the card is proven genuine.
HOW IT WORKS
Operationally, authorisation is engineered to produce an answer in seconds, every time — so the interesting cases are the ones where it cannot.
When an issuer is unreachable or too slow, the network can answer on its behalf: stand-in processing, approving or declining within limits the issuer agreed in advance, then sending the issuer an advice message once it is back.
An approval, note, is not a guarantee of final payment: it can expire unused, be reversed when a basket is abandoned, or be followed at clearing by a different amount — fuel pumps and hotels authorise estimates.
Practitioners therefore manage the authorisation hold as a lifecycle of its own; holds that outlive their purchase are a steady source of cardholder complaints.
And at the margins, offline authorisation survives: chip and terminal can approve small payments between themselves without going online, trading issuer certainty for speed under rules the schemes define.
THE WORDS
- ISO 8583
- The international standard for card-originated financial transaction messages, used between terminals, acquirers, schemes, and issuers.
- Authorisation hold
- The earmark an issuer places on the cardholder's available balance when it approves an authorisation — money reserved, not yet moved.
- Authorisation code
- The short code an issuer returns with an approval — proof the authorisation happened, quoted on receipts and matched again at clearing.
- Stand-in processing
- The card network answering authorisations on the issuer's behalf when the issuer is unreachable, within limits the issuer agreed in advance.
- Card-present
- A payment where the card (or its device token) meets the merchant's terminal — chip, contactless, or swipe — giving strong evidence the real card was there.
- Card-not-present
- A payment made without the physical card at a terminal — online, in-app, or by phone — where the merchant receives card details remotely.
- EMV chip
- The microprocessor on a payment card that proves the card is genuine by computing a fresh cryptogram for every transaction — unlike a copyable magnetic stripe.
- Contactless payment
- A card-present payment made by holding a card or device near the terminal; EMV cryptography runs over a short-range radio link instead of chip contacts.
- PAN
- The card number itself — typically 16 digits identifying the issuer (via the BIN) and the individual card account, with a check digit at the end.
- BIN
- The leading digits of a card number that identify the issuing bank and card product — the key every system uses to route an authorisation to the right issuer.
READ FIRST
CONNECTED TO
SOURCES
- A glossary of terms used in payments and settlement systems — CPSS (now CPMI), Bank for International Settlements
- Payments Signal editorial teaching models — Payments Signal
Derived from Authorization: the first journey. Every claim on this card is sourced on that page.