# Authorization Hold: How Card Pre-Authorization Works

> What an authorization hold is, how auth and capture differ from settlement, how long holds last, and why customers see pending and double charges.
- **Author**: Deepak Jangir
- **Published**: 2026-10-09
- **Category**: Payments
- **URL**: https://dodopayments.com/blogs/en/authorization-hold

---

A customer emails support with a screenshot of their banking app: two charges for your product, one marked "pending", one posted. They are sure you billed them twice. You check your dashboard and see one successful payment. Both of you are looking at the same transaction, just at different stages of its life. The thing in between is an authorization hold.

An authorization hold is a temporary reservation of funds that a card issuer places on a cardholder's account when a merchant requests approval for a payment. The issuer confirms the card is valid and has enough available credit or balance, then reduces the available amount by the authorized sum. No money moves at this point. The funds only leave the account when the merchant captures the authorization and the transaction settles.

This guide covers how pre-authorization works, how long holds last, and what it means for trials, subscriptions, and usage-based billing.

## What is an authorization hold?

An authorization hold is the issuer's promise to honor a payment up to a specific amount for a limited time. The issuer earmarks the funds so the cardholder cannot spend them elsewhere, but the transaction is not complete. It is also called a pre-authorization, a card hold, or a pending charge.

Every card payment goes through three distinct steps, and most confusion comes from treating them as one event.

| Step              | What happens                                                                 | Money moves? | What the customer sees                     |
| ----------------- | ---------------------------------------------------------------------------- | ------------ | ------------------------------------------ |
| Authorization     | Issuer checks the card, approves the amount, reduces available credit        | No           | A "pending" line item, lower available balance |
| Capture           | Merchant confirms it wants to collect the authorized amount (full or partial) | Not yet      | Usually still "pending"                     |
| Settlement        | Funds are cleared through the network and transferred to the merchant's side  | Yes          | Pending item replaced by a posted charge    |

Authorization is a reservation, capture is an instruction, and settlement is the transfer. For what happens after settlement, read our breakdown of [MoR payouts and settlement](https://dodopayments.com/blogs/mor-payouts-settlement-explained).

## How pre-authorization works step by step

Pre-authorization is a round trip from the merchant to the cardholder's bank and back, followed later by a capture request that kicks off settlement. The authorization leg usually completes in a couple of seconds, while settlement runs in batches afterward.

Here is the sequence:

1. The customer enters card details at checkout.
2. The merchant's payment gateway sends an authorization request to the acquirer.
3. The acquirer routes the request through the card network to the issuing bank.
4. The issuer runs its checks (card status, available funds, fraud signals, sometimes a 3D Secure challenge) and returns an approval or decline.
5. If approved, the issuer places the authorization hold and returns an authorization code.
6. The merchant captures the authorization, either immediately or later.
7. Captured transactions are submitted for clearing and settlement, and the hold is replaced by a posted charge.

```mermaid
flowchart LR
    A["Customer"] --> B["Merchant / Checkout"]
    B --> C["Acquirer"]
    C --> D["Card Network"]
    D --> E["Issuer: approve + hold funds"]
    E -->|"auth code"| B
    B --> F["Capture request"]
    F --> G["Clearing and settlement"]
```

If the acquirer, network, and issuer roles blur together, our guide on [payment gateway vs payment processor](https://dodopayments.com/blogs/payment-gateway-vs-payment-processor) separates the layers clearly. For the two banks specifically, our breakdown of [the acquiring bank vs the issuing bank](https://dodopayments.com/blogs/acquiring-bank-vs-issuing-bank) explains who approves the hold and who settles the funds.

At step 4, the issuer may ask the cardholder to authenticate before approving the hold. We cover that flow in our explainer on [3D Secure payment authentication](https://dodopayments.com/blogs/3d-secure-3ds-payment-authentication).

## Auth and capture: one step or two?

Auth and capture can happen together or separately. When they happen together, it is often called a "sale" or immediate capture: the merchant authorizes and captures in one go, which is the default for most digital goods. When they are separated, the merchant authorizes first and captures later, once the final amount is known or the goods ship.

Separate auth and capture is common in industries where the final amount is uncertain at checkout:

- Hotels authorize an estimated stay plus incidentals at check-in and capture the final bill at checkout.
- Car rental companies hold a deposit and capture the real cost when the car is returned.
- Physical retailers may authorize at order time and capture when items ship.

SaaS and digital products are delivered instantly, so there is little reason to delay capture, and immediate capture avoids holds expiring before collection.

## How long does an authorization hold last?

How long an authorization hold lasts is set by card network rules and the issuing bank, not by the merchant. For typical online purchases, holds commonly last from a few days to about a week. For certain merchant categories, such as hotels, car rentals, and some travel services, holds can be allowed to stay open longer because the final amount is not known until later.

There is no single universal number. The window depends on the network, the card type, the merchant category, and the issuer's policies, and some issuers take longer to drop a hold from the cardholder's view even after it is voided.

What matters operationally:

- If the merchant captures within the valid window, the hold converts into a settled charge.
- If the merchant voids or reverses the authorization, the issuer should release the hold, though the customer's banking app may lag.
- If the merchant never captures, the hold eventually expires and the funds become available again.

When customers ask when a pending charge will disappear, the honest answer is "it depends on your bank". Put that in your support macros so agents do not promise dates.

## Authorization hold vs pending charge

An authorization hold and a pending charge are usually the same thing seen from two sides. The merchant sees an authorization, and the cardholder's bank shows it as a pending transaction. The difference is perspective, not mechanics.

| Term                 | Who uses it      | What it means                                                    |
| -------------------- | ---------------- | ---------------------------------------------------------------- |
| Authorization hold   | Merchant, issuer | Funds reserved after approval, not yet captured or settled       |
| Pending charge       | Cardholder, bank app | A transaction that has not posted yet, often an active hold  |
| Posted charge        | Cardholder, bank app | A settled transaction that appears on the statement           |
| Voided authorization | Merchant         | Hold cancelled before capture, funds released by issuer          |

### Why customers see double charges

The "double charge" support ticket usually comes from one of three patterns:

- A hold and the settled charge briefly appear at the same time, before the issuer drops the pending entry.
- The customer retried checkout after a slow or failed attempt, and the first attempt left a hold that was never captured.
- A small verification authorization was placed when the card was saved, and the real charge followed.

In all three, only one charge is collected. If the customer disputes with their bank instead, our guide on [chargeback vs refund](https://dodopayments.com/blogs/chargeback-vs-refund) covers why proactive explanations and refunds beat disputes.

## Card verification authorization: zero-amount and small holds

A card verification authorization is a request that checks whether a card is valid without collecting money. Many networks support zero-amount verification, where the issuer confirms the card details and returns approval or decline with no funds held. Where zero-amount checks are not supported, merchants sometimes authorize a small amount and then void it.

They are common when saving a card for future subscription charges, starting a free trial, or updating a payment method. Checkout copy like "your card will be verified, you will not be charged today" prevents mystery-charge tickets. Verification requests are also a favorite tool of fraudsters testing stolen numbers, which we explain in our piece on [card testing fraud](https://dodopayments.com/blogs/card-testing-fraud).

## Partial and incremental authorizations

Partial and incremental authorizations adjust the authorized amount after the initial request. A partial authorization happens when the issuer approves less than the requested amount, typically because the card (often a prepaid or debit card) does not have enough balance for the full sum. The merchant then decides whether to accept the partial amount and collect the rest another way, or cancel.

An incremental authorization increases the amount on an existing hold. A hotel might authorize an estimated stay, then add an incremental authorization when the guest extends by a night. Support for incremental authorizations depends on the card network, merchant category, and acquirer.

Partial capture is the mirror image: authorize more, capture less, release the rest. Most SaaS businesses never need these mechanics.

## What happens when an authorization expires before capture?

When an authorization expires before capture, the issuer releases the hold and the merchant's right to collect against that approval lapses. Attempting to capture an expired authorization may fail outright or be declined, and the merchant typically needs to request a fresh authorization.

A fresh authorization means the issuer runs its checks again. The card might now be expired, over limit, or flagged, so the second attempt can decline even though the first succeeded.

Practical rules for anyone separating auth from capture:

- Capture as soon as the final amount is known.
- Track the authorization timestamp and alert before the typical expiry window.
- Void authorizations you will not use so the customer's funds are released promptly.
- Treat a re-authorization as a brand new payment that can fail, with its own retry and messaging logic.

## Authorization holds in SaaS and digital products

For SaaS, the authorization step matters less as a "hold" and more as the moment the issuer decides whether to approve. Trials, renewals, credits, and metered usage all depend on that decision going the right way.

### Free trials and trial abuse

Free trials that require a card usually rely on a verification authorization at signup and a real authorization plus capture when the trial converts. If the conversion charge declines, the customer slides into dunning or churns. Our comparison of [SaaS free trial vs freemium](https://dodopayments.com/blogs/saas-free-trial-vs-freemium) covers when requiring a card at signup is worth the friction.

Trials also attract abuse: the same person creating account after account with new cards or prepaid numbers. Dodo Payments added paid trials and trial-misuse prevention in July 2026, which lets you charge a small amount upfront or block repeat trial signups instead of relying on a verification hold alone.

### Subscription renewals

A subscription renewal is typically a fresh authorization and capture, not a reuse of the original signup authorization. Each billing cycle the stored card goes back through the issuer, which re-checks the card and balance. That is why a card that worked for months can suddenly decline on renewal.

Renewal declines are the main driver of [involuntary churn from failed payments](https://dodopayments.com/blogs/involuntary-churn-failed-payments). Smart [payment retry logic](https://dodopayments.com/blogs/payment-retry-logic) and a well-paced [subscription dunning sequence](https://dodopayments.com/blogs/subscription-dunning-recovery-sequence) recover a meaningful share of them. Dodo handles automatic subscription payment retries, and the Sep 2026 release added subscription grace periods and manual payment retry. See the [subscription docs](https://docs.dodopayments.com/features/subscription) and [payment retries docs](https://docs.dodopayments.com/features/recovery/payment-retries) for configuration.

### Usage-based billing and prepaid credits

Usage-based billing creates a timing gap: you deliver value first and charge later, so the authorization happens after the cost is incurred. If that charge declines, you have already served the usage. Prepaid credits flip the order, authorizing and capturing upfront before consumption.

Many AI and API products blend both, selling credit packs and billing overages. The [credit-based billing docs](https://docs.dodopayments.com/features/credit-based-billing) show how to set it up on Dodo.

### Why declined authorizations happen

An authorization declines when the issuer refuses to place the hold. Common causes include insufficient funds, an expired or cancelled card, incorrect details, a failed authentication challenge, or the issuer's fraud model flagging the transaction.

The response code tells you which bucket a decline falls into, and that determines whether a retry makes sense. Our reference on [credit card decline codes](https://dodopayments.com/blogs/credit-card-decline-codes) maps the common codes to actions, and [how to reduce payment declines](https://dodopayments.com/blogs/reduce-payment-declines) covers the prevention side. Dodo also introduced customer-friendly payment failure messages in August 2026, so buyers see an actionable explanation instead of a bare "card declined".

## Grant access on capture, not on redirect

A common integration bug is granting access when the customer lands on your success page. A redirect does not prove the payment succeeded, and it can be spoofed or skipped.

The safe pattern is to grant access only when your server receives a verified `payment.succeeded` webhook, and to handle `payment.failed` explicitly. Dodo webhooks follow the Standard Webhooks spec, so you verify the `webhook-id`, `webhook-timestamp`, and `webhook-signature` headers against your webhook secret before trusting the payload.

```typescript
import express from "express";
import { Webhook } from "standardwebhooks";

const app = express();
const webhook = new Webhook(process.env.DODO_WEBHOOK_SECRET as string);

// Use the raw body: signature verification fails on re-serialized JSON
app.post(
  "/webhooks/dodo",
  express.raw({ type: "application/json" }),
  async (req, res) => {
    const rawBody = req.body.toString("utf8");
    const headers = {
      "webhook-id": req.header("webhook-id") ?? "",
      "webhook-timestamp": req.header("webhook-timestamp") ?? "",
      "webhook-signature": req.header("webhook-signature") ?? "",
    };

    let event: { type: string; data: Record<string, any> };
    try {
      event = webhook.verify(rawBody, headers) as typeof event;
    } catch {
      return res.status(401).send("Invalid signature");
    }

    // Deduplicate: webhooks can be delivered more than once
    if (await alreadyProcessed(headers["webhook-id"])) {
      return res.status(200).send("Already processed");
    }

    switch (event.type) {
      case "payment.succeeded":
        // Authorized and captured: safe to provision access
        await grantAccess(event.data.payment_id, event.data.customer?.email);
        break;

      case "payment.failed":
        // Issuer declined or payment could not complete: do not provision
        await markPaymentFailed(event.data.payment_id);
        await notifyCustomer(event.data.customer?.email);
        break;

      case "payment.processing":
        // Still in flight: show a pending state, grant nothing yet
        await markPending(event.data.payment_id);
        break;
    }

    await recordProcessed(headers["webhook-id"]);
    return res.status(200).send("ok");
  },
);

// alreadyProcessed, recordProcessed, grantAccess, markPaymentFailed,
// markPending and notifyCustomer are your own database/email helpers
```

Verification needs the raw body, so the route uses `express.raw`. The handler is idempotent on `webhook-id` because redeliveries are normal, and `payment.processing` is treated as "not yet", mirroring the hold itself.

For payment events and payloads, see the [payment webhook reference](https://docs.dodopayments.com/developer-resources/webhooks/intents/payment). For subscriptions, handle `subscription.active`, `subscription.renewed`, and `subscription.on_hold` the same way.

## Where Dodo Payments fits

Dodo Payments is a Merchant of Record, which means it is the legal seller for your transactions. It runs the hosted checkout, routes the authorization through the card networks, handles payment retries, and takes on sales tax, VAT, and GST calculation and remittance, plus chargebacks and compliance. You integrate once and react to webhooks instead of managing acquirer relationships yourself.

It accepts payments from 220+ countries and regions. For card specifics and how payments appear in your dashboard, see the [cards documentation](https://docs.dodopayments.com/features/payment-methods/cards) and the [payments overview](https://docs.dodopayments.com/features/transactions/payments).

## FAQ

### What is an authorization hold on a credit card?

An authorization hold is a temporary reservation the card issuer places on a cardholder's available credit or balance after approving a payment request. No money moves until the merchant captures the authorization and the transaction settles, at which point the hold becomes a posted charge.

### How long does an authorization hold last?

The duration is set by card network rules and the issuing bank. For typical online purchases it is commonly a few days to about a week, while categories like hotels and car rentals can keep holds open longer. If the merchant never captures, the hold expires and the funds are released.

### What is the difference between authorization and capture?

Authorization is the issuer approving the payment and reserving funds. Capture is the merchant confirming it wants to collect that authorized amount, which sends the transaction into clearing and settlement. Most digital products authorize and capture at the same time.

### Why do I see two charges for one purchase?

Usually you are seeing a pending authorization hold alongside the final posted charge, or a leftover hold from an abandoned checkout attempt. Only one charge is collected, and the extra pending entry drops off once the issuer releases it.

### Is a subscription renewal a new authorization?

Yes, a subscription renewal is typically a fresh authorization and capture against the stored card. The issuer re-checks the card each cycle, which is why renewals can decline even when earlier payments succeeded.

## Final Take

An authorization hold is the issuer saying "yes, for now". Capture turns that yes into an instruction, and settlement turns it into money. Keeping those three steps separate in your head explains pending charges, phantom double charges, failed renewals, and why access should follow a verified webhook rather than a redirect.

If you would rather not manage acquirers, retries, and tax compliance yourself, [Dodo Payments](https://dodopayments.com) handles checkout and payment operations as your Merchant of Record. Review [Dodo's pricing](https://dodopayments.com/pricing) to see what that costs for your volume.
---
- [More Payments articles](https://dodopayments.com/blogs/category/payments)
- [All articles](https://dodopayments.com/blogs)