SardineCon SF/2026

Learn More
Card & payment fraud4 min de leitura

O que é Pre-authorization?

SUBSCRIBE

A pre-authorization is a temporary hold on a cardholder's funds to confirm the card is valid and money is available before a charge is finalized. Those small, low-friction holds are useful to merchants, but they are also a cheap and quiet way for criminals to test stolen cards.

What is pre-authorization, in plain English?

A pre-authorization is the first half of a card payment. Before a merchant actually takes the money, it asks the issuer to confirm the card is real and the funds are there, and to place a temporary hold for the expected amount. Hotels, gas stations, and rental firms use this constantly, holding an estimated sum that is finalized, or captured, later when the real total is known.

The hold is not a completed charge. If nothing is captured, it eventually falls off and the funds are released back to the cardholder. That gap between authorization and capture is normal business, but it is also a window that fraudsters exploit, because a pre-auth checks whether a card works without the friction or cost of a full purchase.

For fraud teams, the key point is that a pre-authorization is a validity test. A criminal holding a batch of stolen card numbers can fire small pre-auths to learn which cards are live before committing to bigger fraud, which makes a burst of pre-auth-only activity a card-testing signal.

Authorization versus capture

What changes

Pre-authorization

Capture

What it does

Places a temporary hold to confirm validity and funds

Finalizes the charge and moves the money

Effect on funds

Reserved, then released if not captured

Actually debited from the cardholder

Fraud use

Cheap way to test whether a stolen card is live

Where the real value is extracted

Key metric

Spike in auths without matching captures

Healthy auth-to-capture ratio

What it looks like in practice

In practice

A merchant's monitoring shows a sudden surge of tiny pre-authorizations overnight, hundreds of them, each for a small amount and almost none followed by a capture. The card numbers vary, many are declined, and the successful ones are never turned into actual purchases on this merchant.

The activity is card testing: a fraudster is using cheap pre-auths to sort a batch of stolen numbers into live and dead. The cards that authorize will be spent elsewhere for real value. The team spots it through the collapsed authorization-to-capture ratio and adds velocity limits to choke the testing before the validated cards leak out.

Why it matters to operators

Pre-authorizations sit in a blind spot because they are not completed charges, so teams focused on captured revenue can miss a testing attack running entirely in the auth layer. Watching the authorization-to-capture ratio turns that blind spot into a signal: a flood of auths with no matching captures is one of the clearest early indicators of card testing.

Holds also cause real customer pain. Stale or uncaptured pre-auths tie up a cardholder's available balance until they expire, generating complaints and, occasionally, disputes. Managing holds well is therefore both a fraud-detection task and a customer-experience one, and treating a burst of pre-auth-only activity as suspicious protects both.

What to watch in the data

  • Auth-to-capture gap. A spike in pre-authorizations without matching captures is a strong card-testing signal.
  • Tiny amounts. Very small holds are the cheapest way to test whether a stolen card is live.
  • High decline mix. Many declined pre-auths across varied card numbers point to testing, not genuine shoppers.
  • Stale holds. Uncaptured authorizations that linger tie up customer funds and drive complaints and disputes.
  • Velocity bursts. Rapid pre-auths from one source, device, or IP suggest automation working through a batch of cards.

Quick questions

Is a pre-authorization a real charge?

No. It is a temporary hold that confirms the card is valid and funds are available. The money is only actually taken when the transaction is captured; if nothing is captured, the hold is released.

Why do fraudsters like pre-authorizations?

Because they are a cheap, low-friction way to test whether stolen cards are live. A small hold confirms validity without completing a purchase, letting criminals sort good cards from dead ones.

What does a spike in pre-auths without captures mean?

Often card testing. A flood of authorizations that never turn into captures suggests someone is validating stolen numbers rather than buying anything, especially if declines are high.

Why do stale holds cause complaints?

A hold reserves the cardholder's funds until it is captured or expires. If it lingers uncaptured, it ties up their available balance, which frustrates customers and can lead to disputes.

How do teams contain pre-auth testing?

By monitoring the authorization-to-capture ratio and adding velocity limits, device checks, and rate controls that choke rapid bursts of small pre-auths before valid cards are harvested.

Is pre-authorization the same as an authorization hold?

Effectively yes. The terms are used interchangeably for the temporary reservation of funds placed before a charge is finalized, common in hotels, fuel, and car rental.

Go deeper

O que saber junto com Pre-authorization