One-Line Definition
Authorization Rate is the percentage of payment requests that a card issuer (the customer's bank) approves rather than declines — the single clearest signal of whether your checkout actually converts intent into money.
Real-Life Analogy
Think of an authorization request like a restaurant reservation.
You call the restaurant (the issuer) and ask for a table for four at 7 PM. The host checks the book and either confirms — "Yes, we have you down" — or turns you away: "Sorry, fully booked," "We don't take parties of four," or "We don't recognize this phone number."
The restaurant hasn't served you dinner yet. It has only agreed to hold the table. Payment works the same way: authorization is the *promise* to pay, not the payment itself. Settlement — the actual movement of funds — happens later, when the meal is over and the bill is settled.
Now imagine you run a restaurant where the host rejects 1 in 5 callers for reasons nobody can explain. That's a 20% authorization rate loss, and it's exactly the problem DTC merchants face when they blame "bad traffic" for revenue that never arrives.
Core Formula
Authorization Rate (%) = (Approved Transactions ÷ Total Authorization Attempts) × 100
A few precision notes that separate a useful metric from a vanity one:
- Denominator discipline matters. If you count only *submitted* attempts, you'll flatter yourself. The honest denominator includes every attempt your gateway sent — including retries, network tokens, and re-submissions after a soft decline.
- Segment before you judge. A blended rate hides everything. Split by issuer, card brand, BIN country, payment method, and new-vs-returning customer.
- Watch the companion metric. Approval rate without false decline rate is a half-truth. A 92% approval rate sounds excellent until you learn that 4% of those declines were "soft" declines on good cards that a smart retry would have recovered.
Worked example: A store processes 50,000 authorization attempts in a month. 45,500 are approved.
45,500 ÷ 50,000 = 0.91 → 91.0% Authorization Rate
If the industry benchmark for that vertical is 94%, the store is leaving roughly 1,500 sales per month on the table — at a $60 AOV, that's $90,000 in monthly revenue evaporating before a single fulfillment cost is incurred.
Comparison with Related Terms
| Term | What It Measures | Where It Sits in the Funnel | Typical Benchmark | Who Owns It |
|---|---|---|---|---|
| **Authorization Rate** | % of payment requests approved by the issuer | Immediately after checkout submission | 85–95% (varies by vertical/region) | Payments / Risk |
| **Approval Rate** | Often used interchangeably, but sometimes measured post-capture | Slightly downstream | Similar to auth rate | Payments |
| **Conversion Rate** | % of sessions that result in a completed order | Whole-funnel, top to bottom | 1–3% for DTC | Growth / CRO |
| **Capture Rate** | % of authorized transactions successfully captured/settled | After authorization | 98–99.5% | Payments Ops |
| **Checkout Completion Rate** | % of shoppers who finish checkout after starting | Before the payment request is even sent | 60–75% | Product / UX |
| **False Decline Rate** | % of declines that were wrongly rejected (good funds, good card) | A subset of all declines | 5–15% of declines | Risk / Payments |
The critical distinction: conversion rate tells you how many people wanted to buy. Authorization rate tells you how many were *allowed* to. Merchants obsess over the first and ignore the second, which is why so much revenue dies quietly at the last step.
Use Cases
1. Diagnosing revenue leaks without touching ad spend.
A merchant sees flat revenue and assumes CAC is the problem. Segmenting by issuer reveals that one European bank is declining 38% of attempts — a routing and 3DS configuration issue, not a demand issue. Fixing it lifts revenue with zero additional marketing spend.
2. Evaluating a new payment provider or PSP.
Before migrating, run both providers in parallel on a traffic split. If Provider A delivers 93.2% and Provider B delivers 88.7% on identical traffic, the difference is not noise — it's your margin. On 20,000 monthly attempts at $75 AOV, that 4.5-point gap equals roughly $67,500 in monthly revenue.
3. Optimizing retry logic.
Not all declines are equal. Hard declines (stolen card, closed account) should never be retried. Soft declines (insufficient funds, issuer timeout, velocity limits) often succeed on a second or third attempt. Merchants using intelligent retry typically recover 2–5% of initially declined volume — pure incremental revenue.
4. Cross-border expansion decisions.
A US merchant expanding into Brazil may see authorization rates drop from 94% to 78% overnight due to local card quirks, missing local acquiring, and installments expectations. Knowing the gap *before* launch changes the entire unit economics model.
5. Fraud-stack tuning.
Tightening fraud rules reduces chargebacks but also suppresses authorization rates. The goal is not maximum approval or minimum fraud — it's the optimal point where net revenue (approved volume minus fraud losses minus chargeback fees) is maximized.
Misconceptions
"High authorization rate = healthy payments."
Not necessarily. You can inflate approval rates by being too permissive, which simply shifts losses from declines to chargebacks. A 97% approval rate with a 2% chargeback ratio is a failing business, not a winning one.
"Declines are the customer's fault."
Most declines are infrastructure problems: stale card credentials, missing network tokens, misconfigured 3DS, wrong MCC codes, or an issuer's risk model flagging your descriptor. The customer did their part — they tried to pay.
"Authorization means I got paid."
No. Authorization reserves funds; capture and settlement move them. An authorized transaction can still fail at capture or be reversed. Treat authorization as a green light, not a deposit.
"One approval rate is enough."
Blended rates are averages that hide catastrophes. A 91% blended rate could mask 98% on domestic Visa and 61% on a single cross-border Mastercard corridor. Always segment.
"Retrying every decline is free money."
Retrying hard declines wastes fees, may trigger issuer penalties, and can flag your MID as high-risk. Retry strategy must be decline-code-aware, not blanket.
Related Terms
- Soft Decline — A temporary rejection (insufficient funds, timeout) that may succeed on retry.
- Hard Decline — A permanent rejection (stolen card, closed account) that should never be retried.
- Network Tokenization — Replacing raw card numbers with tokens to improve approval rates and security.
- 3D Secure (3DS) — Authentication protocol that shifts fraud liability but can suppress authorization if poorly implemented.
- Smart Retries — Automated, logic-driven re-submission of soft-declined transactions.
- Cascading — Routing a single transaction through multiple acquirers to maximize approval.
- False Decline — A wrongful rejection of a legitimate transaction; a direct, invisible revenue leak.
- Issuer — The customer's bank; the party that ultimately approves or declines.
- PSP (Payment Service Provider) — The intermediary that submits transactions to issuers on your behalf.
- Chargeback Ratio — The counterweight metric; rising approvals often precede rising chargebacks if risk controls slip.
Bottom line: Authorization Rate is the most under-managed revenue lever in DTC e-commerce. Every point you recover is margin you already paid to acquire — no new ad spend, no new traffic, just money that was always yours to collect.