DEV Community

Payneteasy
Payneteasy

Posted on

The hold expired before we tried to capture it

Ran into this reconciling a subscription billing system: authorize now, capture in 48 hours after fraud review clears. Worked fine in testing. In production, roughly 2% of captures started failing with a decline code that looked like insufficient funds but wasn't.

Turned out the issuer had already released the authorization hold. Visa's guideline is 7 days for most MCCs, but individual issuers set their own expiry, and we saw holds die anywhere from 3 to 10 days depending on the card's bank. Nothing in the original auth response tells you when that hold actually dies. You find out when the capture bounces.

Our fraud review queue had a 72-hour SLA on paper. Average was fine. The tail wasn't. A subset of manual reviews sat for 4-6 days, long enough to cross into issuer-specific expiry windows we had no visibility into.

Fix ended up being boring: track auth timestamp separately from order status, re-authorize automatically if capture attempt fails with that specific decline pattern and the auth is older than 3 days, and stop treating "authorized" as a stable state past 72 hours.

Curious how other teams handle this. Do you re-auth automatically, or push the delay back to the review queue instead?

Top comments (0)