How online payments work
A plain-English walkthrough of what happens between a customer clicking "Buy" and the money arriving in your bank account.
- Difficulty
- Beginner
When a customer clicks "Pay now" on your website, a lot happens in the seconds before the page tells them it worked. Understanding the journey helps you make better decisions about your payment setup and troubleshoot problems when they arise.
Quick summary
A customer's card details travel through several systems — your website, a payment gateway, a payment processor, and the card networks — before the money settles in your bank. Each step adds a small fee. Authorization takes seconds. Getting the money into your bank takes longer: with Stripe in the US, funds from a card payment settle about two business days after the payment, and your own bank can add time on top.
The players involved
Before we trace the journey, here are the main parties:
| Party | What they do |
|---|---|
| Customer | Enters their card details and confirms the purchase |
| Your website | Collects the payment form and sends it securely onward |
| Payment gateway | The secure tunnel that moves card data to the processor |
| Payment processor | Requests authorization from the card network |
| Card network | Visa, Mastercard, American Express — routes the request to the bank |
| Issuing bank | The customer's bank — approves or declines the charge |
| Your bank | Where the money lands after the processor pays out |
Modern tools like Stripe combine the gateway and processor roles into one product, which simplifies things considerably.
The payment journey, step by step
Not one continuous action, but separate events on separate clocks. The approval round trip is over in about two seconds — and it only reserves the money. Capture moves it. Your payout is batched at the end of the business day and reaches your bank one to three business days later, already net of fees.
Read this as text
The customer clicks “Pay now” on your website. The payment form your site shows is usually hosted by your payment gateway and processor — Stripe, for example, combines those two roles in one product — so the card details go straight there and the raw card number never sits on your own server. The processor asks the card networkto authorize the charge, and the network routes the request to the customer’s own bank, which checks the available balance and looks for fraud signals. The approval or decline comes back to the customer in about two seconds.
Authorization only reserves the money. Capture actually moves it, and it is a separate event. Most online stores capture immediately at checkout, which is why the two are so easily confused. A business that ships goods after confirming stock can authorize first and capture when the item ships.
Getting paid runs on a different clock again. At the end of each business day the processor batches and settles all the captured transactions, and the net amount — the sale minus fees — moves toward your bank account. Depending on your processor and your settings, it arrives one to three business days later. The card network and the customer’s bank are not your systems: the customer’s bank is the one that approves or declines the charge.
Customer enters their card details. Your website shows a secure payment form. The form is usually hosted by your payment processor (Stripe, PayPal, etc.) rather than your own server — this keeps sensitive card data off your systems.
The payment gateway encrypts and forwards the data. The card number, expiry, and security code are encrypted and sent to the payment processor. This happens over a secure connection (HTTPS/TLS).
The processor asks the card network to authorize the charge. The processor sends an authorization request to Visa, Mastercard, or whichever network issued the card.
The card network routes the request to the customer's bank. The issuing bank checks the customer's available balance, looks for fraud signals, and sends back an approval or a decline.
The result returns in seconds. If approved, the customer sees a success message. If declined, they see an error and can try another card.
The funds are "captured." Authorization holds the money. Capture actually moves it. Most online stores capture immediately at checkout. Some (hotels, for example) authorize first and capture later.
The payment settles. After capture, the net amount (sale minus fees) takes a few days to become available to pay out. Stripe calls this the settlement timing and writes it as "T+X" days, counted from the moment the payment was confirmed or captured.
The money arrives in your bank. How long this takes depends on your processor and your payout settings. In the US, Stripe's standard settlement timing is two business days, and your own bank may take extra time to make the funds available once it has them.
Authorization vs capture
These two steps are easy to confuse.
- Authorization reserves the funds on the customer's card. The money has not moved yet.
- Capture actually moves the money. This is when the charge appears on the customer's statement.
For most e-commerce stores, authorization and capture happen at the same moment. But if you run a business that ships goods after confirming stock, you may want to authorize first and capture only when the item ships.
Why you might see two entries on a bank statement
Sometimes customers see a "pending" charge (the authorization) and then a "completed" charge (the capture). The pending entry usually disappears within a few days once the capture settles.
Why payments sometimes fail
A declined payment does not always mean the customer lacks funds. Common reasons include:
- The card number, expiry date, or security code was entered incorrectly
- The customer's bank flagged the transaction as potentially fraudulent
- The card does not support this type of purchase, or the currency you charged in
- The billing address or postal code did not match the bank's records
- The card has hit a balance, credit or transaction-amount limit
Most processors return a decline code, and your dashboard shows whatever the issuer sent back. When the issuer gives a specific explanation — wrong card number, insufficient funds, expired card — you see it. A good number of Stripe's decline codes mean only "the card was declined for an unknown reason," and Stripe's own advice for those is that the customer needs to contact their card issuer. So a decline sometimes genuinely does just mean "ask your customer to call their bank."
What "processing fees" are
Every party in the chain charges a small fee for their role. These fees are usually bundled together and deducted from your payout. You never pay them separately — you simply receive slightly less than the full sale amount.
See Payment fees explained for a full breakdown of every fee type.
Common questions
How long does it take for money to reach my account?
It depends on your processor and your account settings. In the US, Stripe's standard settlement timing is two business days, after which the funds are paid out on your account's payout schedule. With PayPal you move money out yourself: PayPal says a standard transfer to a bank account typically completes in 1–3 business days, and that weekends and holidays add at least another business day. Both offer a faster option for a fee — Stripe charges a percentage of the amount for its Instant Payouts, so check stripe.com/pricing for the current rate, and PayPal's Instant Transfer typically completes within minutes.
Your very first payout is the slow one. Stripe says it typically schedules the first payout to complete within 7–14 days of your first live payment, and that it can take longer depending on your industry, country and risk level.
Can a customer pay without a card?
Yes. Many processors support digital wallets (Apple Pay, Google Pay), bank transfers (ACH), and buy-now-pay-later services. Your available options depend on your processor and your website platform.
What happens if a customer's payment is authorized but my site crashes before confirming?
The authorization may sit pending. Processors cancel an uncaptured authorization after a set period, and the hold is released — with Stripe that period is seven days by default. Your processor dashboard will show any open authorizations so you can capture or cancel them manually.
Is it safe for my customers to enter card details on my site?
Yes, when your site uses a properly configured payment processor. Their hosted payment forms mean raw card data never touches your server. Check that the address in the browser bar starts with https:// — that confirms the connection is encrypted. Stripe requires payment pages to use TLS 1.2 or above. See Payment security & PCI compliance for more.
Related guides
- Payment processors explained
- Payment fees explained
- What we need to set up Stripe
- Stripe basics for business owners
- PayPal basics for business owners
- Payment security & PCI compliance
- Accepting credit cards (WooCommerce)
Need a hand?
Learn more
Last updated
Accepting payments online, explained
Everything you need to know about taking payments on your website — from how money moves to fees, security, and common processors like Stripe and PayPal.
Payment processors explained
What a payment processor does, how it differs from a payment gateway, and how to choose the right one for your business.