Ecommerce payment basics

How do online credit card payments work?

Online credit card payments move through several connected systems. A shopper enters payment details at checkout, the merchant's payment technology sends an authorization request, and the card issuer returns an approval or decline. An approval is an important checkpoint, but it is not the same as the later capture, clearing, and settlement steps that complete the transaction workflow.

The online payment flow at a glance

The exact software and service providers differ by merchant, but the basic flow is usually recognizable:

  1. The customer confirms an order and submits payment information through a payment page.
  2. The checkout passes the transaction to a gateway, payment service, or other payment technology.
  3. The request travels through the processor and card network to the card issuer.
  4. The issuer approves or declines the authorization request.
  5. When the merchant is ready to complete the charge, the approved transaction is captured.
  6. Clearing and settlement reconcile the transaction among the participating financial institutions.

This overview is intentionally provider-neutral. Feature names, transaction states, and operational steps can vary, so a merchant should compare the general flow with its own gateway, processor, ecommerce platform, and order-management documentation.

Checkout and the payment page

The customer-facing process begins at checkout. The order total, contact or shipping details, and selected payment method are assembled before payment information is submitted. PCI Security Standards Council guidance defines a payment page as the web interface containing elements used to collect or process payment card data. Depending on the implementation, that experience may be a hosted page, a redirect, or an embedded component.

Where the payment fields come from matters because it affects which systems handle card data and which parties have security responsibilities. A polished checkout alone does not establish that an implementation is secure or compliant. Merchants should document who supplies every payment-page element, who can change it, and where payment data travels. Questions about a particular environment should be addressed with the merchant's acquirer, payment provider, and qualified security adviser.

For broader checkout planning, visit the Ecommerce & Online Payments FAQ.

Authorization: asking the issuer for a decision

After the shopper submits the order, the payment technology creates an authorization request. Visa Acceptance Solutions documents a typical path in which the service validates order information, contacts the payment processor, and the processor routes the transaction through the card network to the issuing bank. The issuer then returns an approval or decline through the same general chain.

An approved authorization indicates that the issuer accepted the request and generally reserves the authorized amount against the cardholder's available credit. It does not guarantee that the order is legitimate, that fulfillment should ignore the merchant's review process, or that later transaction activity cannot change. A decline also should not be interpreted or described beyond the response information made available by the merchant's provider.

Merchants should preserve the transaction and order references returned by their systems. Those identifiers help connect the ecommerce order with authorization, capture, customer-service, and reconciliation records without placing full card numbers in ordinary notes or support tools.

Capture, clearing, and settlement

Capture is the step that follows an authorization when the merchant submits the approved transaction for completion. Visa Acceptance Solutions describes capture as a follow-on transaction linked to the authorization. Some payment configurations combine authorization and capture as a sale, while other workflows keep them separate. The appropriate timing and method depend on fulfillment practices, provider configuration, and applicable operating rules.

After capture, clearing exchanges transaction details so the parties can reconcile what is owed. Mastercard describes clearing as the exchange of financial transaction details between an acquirer and issuer, while settlement facilitates the exchange of funds on behalf of those institutions. Merchant-facing reports may group or label these states differently, which is why the ecommerce order record should be matched to the provider's transaction record and settlement reporting.

A status such as authorized, captured, pending, or settled has a specific meaning within a given system. Teams should use the provider's definitions rather than assuming that similar labels are interchangeable.

What the merchant should review

Payment-page ownership

Identify who hosts or supplies the payment fields, who maintains checkout scripts, and which systems receive payment data.

Order and transaction matching

Use durable order, authorization, and capture references so customer-service and accounting teams can trace activity accurately.

Fulfillment triggers

Document when an order is reviewed, when it is captured, and how cancellations or incomplete fulfillment are handled within the provider's supported workflow.

Exception handling

Define how staff respond to declines, duplicate submissions, interrupted checkouts, and mismatched order or transaction states.

A merchant evaluating the complete processing chain can also read how credit card processing works.

Online card entry is not the only checkout option

Some customers may use a digital wallet or another supported checkout method instead of manually entering card details. The visible customer experience can differ, but the merchant still needs clear order records, transaction statuses, and reconciliation procedures. Support depends on the merchant's actual ecommerce platform and payment configuration, so it should be verified before being advertised.

For a careful overview of that path, see how merchants accept digital wallets online and what wallet tokenization means.

Common questions

Is an approved online payment complete?

Not necessarily. Approval refers to authorization. Capture and the later clearing and settlement stages are separate parts of many online card-payment workflows.

Does every merchant use the same payment flow?

No. Providers may combine or separate steps, use different status labels, and support different checkout designs. The merchant should verify its actual configuration and operating procedures.

Should staff copy card numbers into an order note?

No. General order notes, email, chat, and ordinary support forms should not be used to collect full card numbers, passwords, bank credentials, or secret API keys. Use the approved payment interface and privacy-safe transaction references.

Choose the next step from the actual workflow

Map the journey from checkout submission through authorization, capture, and reconciliation. Then compare that map with the documentation for the ecommerce platform and payment services already under consideration. Payments Max can help organize the questions to ask, but provider support, security responsibilities, and configuration details should be confirmed before launch.

Explore ecommerce payment guidance

Privacy reminder: do not send cardholder data, passwords, bank credentials, complete account numbers, or secret API keys through a general contact form.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US