You tap your card, wait about two seconds, and the terminal says “Approved.” In that gap your payment made a round trip through as many as five separate companies, and a decision was made about you. Understanding that trip explains almost everything users find mysterious about cards: why a charge shows up as “pending” at the wrong amount, why a card that works at a supermarket fails at a betting site, and why crypto cards charge a percentage on every purchase.
The five parties
- Cardholder — you, holding a physical card, a virtual card number, or a phone wallet.
- Merchant and acquirer — the shop, and the bank or processor that handles card payments on its behalf. The acquirer is the merchant’s entry point into the card networks.
- Card network — Visa or Mastercard. Not a bank and not a lender: a messaging system plus a rulebook plus a settlement mechanism.
- Issuer — the regulated institution holding your balance or credit line. The issuer alone decides yes or no.
- Processor / program manager — optional in theory, near-universal in practice. These companies run the technical stack on an issuer’s behalf. Nearly every crypto card program depends on one.
This arrangement is called the four-party model: cardholder, issuer, acquirer, merchant, with the network in the middle. It is worth knowing the name because the fee structure follows directly from it — see the four-party model.
The round trip
- Capture. The terminal or payment page reads the card and builds an authorization request: card number, amount, currency, merchant category code, and cryptographic proof the card is genuine. On a chip or contactless tap, that proof is a one-time cryptogram, which is why cloning a chip card is impractical.
- Acquirer to network. The acquirer formats the request and hands it to the network.
- Network to issuer. The network routes by the card’s BIN — the leading digits of the card number that identify the issuing program. The standard length is now eight digits, and Visa and Mastercard required everyone in the chain to support eight-digit BINs from April 2022. Older six-digit BINs remain valid and in circulation, so both lengths are live.
- The decision. The issuer checks whether the card is active, whether funds or credit cover the amount, and whether the transaction fits your pattern: country, merchant category, amount, how many transactions in the last hour. It answers with an approval code or a numeric decline reason.
- Back again. The answer retraces the path. The whole loop typically takes one to three seconds, most of it network latency rather than thinking.
The message carrying all this is usually ISO 8583, first standardised in 1987 and still the backbone of card payments today. It is not human-readable: fields are numbered rather than named, and a bitmap at the front of each message declares which of the numbered fields are present. Our field-by-field walkthrough dissects a real one, and the interactive auth flow demo animates the hops.
Authorization is not payment
This is the single most useful thing to understand about cards. The beep means the issuer promised to pay. No money has moved. Two further stages follow, and they are what actually settle the transaction.
- Authorization reserves an amount and returns a yes or no in seconds. No money moves.
- Clearing is the merchant submitting the real, final amount. Merchants typically batch this once a day; the networks run several clearing cycles daily. The authorized figure was an estimate, and clearing replaces it with the truth.
- Settlement is money genuinely moving between the acquirer’s and issuer’s accounts. The networks calculate what each bank owes each other on a net basis and settle it, generally the same day.
One point of frequent confusion: the “money takes days to arrive” complaint is usually about neither of these. Interbank settlement is fast; what takes one to three business days is the merchant’s own bank crediting their account, which is set by the acquirer’s contract, not by any network rule.
This three-stage picture describes the dual-message model used by credit and signature debit. PIN debit and ATM transactions use a single-message model, where authorization and clearing are the same message — which is why a PIN debit purchase often hits your balance as a final amount immediately rather than sitting pending.
Everything users find confusing lives in the gap between these stages:
- A pending charge that differs from your receipt. The pending line is the authorization; your receipt is what will clear. Restaurant tips are the classic case — the authorization is taken before you write the tip, and the cleared amount arrives a day or two later, higher.
- Fuel pumps. The pump cannot know your total before you pump, so it authorizes a placeholder and clears the real amount afterwards. The placeholder is larger than most people expect: under Visa’s rules a US fuel dispenser may run a status check for up to $175, or send an initial authorization for up to $500, before clearing your actual $43 fill-up. Outside the US the status-check figure is $100 or less.
- Hotels and car rentals. These place deliberately large estimated authorizations, and network rules let such an authorization stay valid for up to 30 days for lodging, vehicle rental and cruises. Those rules also say the estimate must be genuine and must not include any amount for potential damage, theft or insurance — worth knowing when a rental desk claims otherwise. How fast the hold disappears from your balance afterwards is up to your issuer, not the rules.
- A refund that takes a week. A refund is a fresh transaction travelling the same path, not an undo button.
This matters more on a crypto card than on a credit card. A hold consumes your available balance, and a crypto card balance is usually a small float. One hotel check-in can freeze everything you loaded. See clearing vs settlement.
Who pays whom
The purchase price does not reach the merchant intact. On a $100 purchase, the merchant receives less, and the difference splits three ways:
- Interchange — the fee the merchant’s bank pays your card’s issuer for accepting the card. It is the largest slice and flows toward the issuer, which is why issuers can fund rewards and why they care which card you use.
- Scheme fees — what Visa and Mastercard charge both banks for running the network. Much smaller than interchange.
- Acquirer markup — the merchant’s own processor’s margin.
Together these make up the merchant discount rate. Visa is blunt about the distinction in its own published schedule: merchants do not pay interchange, they pay a merchant discount to their own bank, and interchange is one input into it.
The relative sizes explain most card behaviour you notice. Credit interchange is materially higher than debit, premium rewards cards sit at the top of the credit range, and several regions cap consumer interchange by law — which is why a merchant may nudge you toward debit, and why the same card can cost a merchant very different amounts in different countries. The published schedules are issued by each network and change periodically; read the current one for your market rather than any figure quoted second-hand.
That gap is why merchants steer you toward debit, why surcharging exists where it is legal, why generous rewards cards are a US phenomenon far more than a European one, and why European card programs cannot fund the cashback rates American ones advertise. Interchange explained covers the economics in full.
Why transactions decline
“Insufficient funds” is a minority of declines. The common causes:
- Risk scoring. An unfamiliar country, an unusual merchant category, an unusual amount, or several transactions in quick succession. Issuers decline first and ask questions later, because a false decline costs them less than fraud.
- Merchant category blocks. Many prepaid and crypto card programs block gambling, money transfer and quasi-cash categories outright, at the program level. No amount of balance will fix this — it is policy, not funds.
- 3-D Secure friction. The online verification step timed out, was abandoned, or the issuer’s app failed to deliver the prompt. See 3DS and SCA explained.
- Address or CVV mismatch on online purchases, especially where the billing address on file does not match what you typed.
- Prepaid-unfriendly merchants. Some subscription and rental merchants reject prepaid BINs on principle, because they cannot rely on the balance being there next month.
- Issuer or processor downtime. Rare at the network level; more common at smaller program managers. When the issuer is unreachable, the network may answer on its behalf under pre-agreed limits — stand-in processing — which keeps cards working but has its own surprises. See stand-in processing and reversals.
A decline message at the terminal is almost always generic. The real reason is a numeric code that only your issuer can see, which is why the app or support line knows things the cashier does not.
Where crypto cards plug in
A crypto card adds exactly one step, and it sits in front of everything above:
- Your stablecoin balance is held by the card program’s provider, not on a chain you control.
- When an authorization arrives, the provider values your crypto balance, converts enough of it to cover the fiat amount, and approves against the result.
- From the acquirer’s, network’s and merchant’s point of view, this was an entirely ordinary prepaid or debit authorization. Nothing in the message says “crypto.”
Be aware that most providers publish very little about this step. Coinbase’s card terms state plainly that the sale happens when you use the card, at the rate on its trading platform at that moment. Several other well-known programs document none of it, so treat “the conversion happens at the moment you tap” as the common design rather than a promise your specific card makes.
Two consequences follow directly:
Crypto cards work anywhere Visa or Mastercard is accepted, because there is nothing special about them from the rails’ perspective.
Conversion costs are charged per transaction, because the conversion happens per transaction. There is no batch, no monthly settlement, no way to amortise it. This is structural, not a pricing choice, and it is why the fee stack on a crypto card is quoted in percentages.
Further reading
Authorization part 2 covers reversals, partial approvals and incremental authorizations. Chargebacks vs crypto explains what dispute rights you actually have on a card balance funded by stablecoins — the protection that on-chain transfers cannot offer.