DEV Community

Payneteasy
Payneteasy

Posted on

Authorization holds expire before capture, and the error message won't tell you that

Ran into this on a build-to-order furniture marketplace: authorize at checkout, capture when the item ships from the workshop, sometimes 10-14 days out.

Captures started failing on orders older than 7 days with a generic decline, no useful reason code. Took a support ticket with the acquirer to learn that Visa's default authorization validity window is 7 days for most MCCs (30 for a handful, lodging and auto rental get special treatment). After that window, the issuer is free to release the hold and decline a capture against it, even though nothing on our side ever called void.

The fix wasn't retry logic, it was re-authorizing before the original hold expired: a scheduled job that checks auth age daily and fires a fresh authorization at day 6 if capture hasn't happened yet, chaining the new auth ID into the order record. Customer never sees a second charge, just a second temporary hold.

What made this expensive to find is that the decline code didn't say "authorization expired" anywhere, it came back as a standard do-not-honor, identical to a dozen other failure modes we already had handlers for. We only connected it to hold age by sorting failed captures by days-since-auth and seeing the cliff at day 7-8.

Anyone else building re-auth logic for long fulfillment windows? Curious how others picked the refresh threshold.

Top comments (0)