Failover routing
Payment failover routing ensures that e-commerce checkouts continue to process orders when a primary acquiring partner experiences downtime. Cardflo detects gateway latency or soft declines and automatically redirects the transaction to a secondary route, rescuing revenue without merchant intervention.
- Category
- Routing
- Capabilities
- 6
- Available on
- All plans
E-commerce technical directors face sudden revenue loss when an acquiring partner encounters technical degradation or goes offline completely. Gateway timeouts and repeated soft declines abandon legitimate shoppers at the checkout stage. A static payment stack cannot recover these failed attempts without forcing the customer to re-enter their card details.
Cardflo monitors checkout connections and deploys automatic retry logic when primary endpoints fail. The platform identifies soft decline codes or latency breaches and instantly cascades the transaction to a secondary acquirer partner. This underlying safety net preserves the buyer experience while providing merchants with granular acquirer downtime protection.
Failover routing automatically reroutes transactions to operational MIDs in the event of an acquirer outage or technical failure. This proactive approach ensures merchant uptime and protects against lost revenue from processing interruptions.
Failover routing overview
Merchants rely on automated secondary logic to salvage transactions that fail due to endpoint unavailability or temporary network timeouts. While initial acquirer selection occurs via smart payment routing, failover mechanisms exist purely to rescue traffic after the first attempt encounters an error.
Cardflo orchestrates this decline recovery process by parsing acquirer response codes in real time. If a provider returns a soft decline or fails to respond within a stipulated millisecond threshold, the gateway automatically repackages the payload and transmits it to an alternative acquirer partner.
E-commerce platforms maintain conversion integrity without exposing the technical friction to the end user. Technical directors retain complete visibility over all rescue sequences, enabling detailed analysis of failover success rates alongside individual provider uptime logs.
How failover routing works
Latency detection and timeout initiation
The platform continuously measures the millisecond response time of the primary acquiring endpoint. If the provider exceeds the merchant-defined latency threshold during an authorisation request, Cardflo aborts the connection. The system immediately registers this timeout as a temporary failure, preventing the checkout application from hanging indefinitely and keeping the user session active for a secondary attempt.
Response code parsing
When an acquiring partner actively rejects a transaction, the platform intercepts the specific ISO 8583 response code. Cardflo evaluates whether the failure represents a hard decline, such as a stolen card, or a soft decline, such as a generic system error. Hard declines end the transaction immediately, while soft declines automatically qualify for the failover sequence.
Secondary acquirer payload transmission
Qualified soft declines and timed-out requests proceed directly to the designated backup acquirer partner. Cardflo reformats the transaction payload to meet the secondary provider's specific API requirements before transmitting the authorisation request. The buyer sees only a marginal extension in processing time, remaining entirely unaware that a payment gateway failover occurred behind the scenes.
Why failover routing matters
Revenue rescue during provider outages
Acquiring partners occasionally suffer unscheduled downtime or degraded API performance. Without a designated fallback process, every transaction attempted during this window becomes a lost sale. Payment failover routing ensures that technical failures at a single provider do not compromise checkout availability, preserving cart conversions and protecting the primary revenue stream.
Reduced friction for legitimate shoppers
Asking buyers to manually re-enter their card details after an initial rejection often leads to cart abandonment. Automatic retry logic shifts the burden of error handling from the consumer to the gateway layer. Retailers maintain a high-quality user experience while technical teams avoid the manual operational overhead associated with investigating and recovering isolated soft declines.
Regulatory notes for failover routing
Scheme rules regarding transaction retries
Visa and Mastercard enforce strict guidelines concerning the resubmission of declined authorisation requests. These network rules aim to protect issuing banks from excessive processing loads and prevent merchants from repeatedly hammering the network with fundamentally invalid card details.
Exceeding scheme retry limits can result in substantial non-compliance fines.
Cardflo structures all cascading sequences to respect these network restrictions natively. The gateway terminates any sequence involving a Category A hard decline instantly.
For permitted soft declines, the platform enforces maximum attempt limits across all configured acquirer partners, ensuring that automated rescue operations remain fully compliant with current card scheme mandates.
Authorisation hold management during timeouts
When an acquiring endpoint times out rather than returning a definitive decline, there is a small risk that the issuing bank has already placed an authorisation hold on the cardholder's funds.
If the failover routing then secures a successful charge via a secondary partner, the customer might temporarily see two pending transactions on their account.
To mitigate this scenario, the orchestration layer relies on precise status mapping and automated reversal messaging. If a timed-out primary transaction is later confirmed as partially authorised by the original provider, the system initiates an immediate void request.
This technical compliance ensures cardholders are not subjected to double authorisations and protects merchants from ensuing chargeback disputes.
Failover routing use cases
Flash sale timeout recovery
Limited-release product drops can produce abrupt checkout bursts, causing gateway requests to exceed latency thresholds while stock remains reserved for only minutes. Cardflo monitors endpoint response times, stops retries that risk duplicate authorisations and cascades timed-out transactions to an available acquirer partner before basket reservations expire.
Soft decline rescue rules
Card-not-present checkouts may return temporary decline responses such as issuer unavailable or processing error, although the shopper’s card remains valid. Cardflo classifies eligible response codes, applies controlled retry triggers through another acquirer partner and records whether the failover attempt recovered the sale without creating duplicate transactions.
Maintenance window continuity
Planned gateway or acquirer maintenance can interrupt overnight orders when technical teams have limited capacity to intervene. Cardflo uses health checks and configurable latency timeouts to identify an unavailable endpoint, divert new authorisation requests through the acquirer partner network and restore the standard route only after service has stabilised.
Peak checkout outage bypass
Major product launches can coincide with an acquirer endpoint failure, leaving otherwise valid card payments pending or declined during the busiest trading period. Cardflo detects elevated timeout and connection-error rates, activates secondary acquirer cascading for affected authorisations and provides failover success analytics so technical teams can assess recovered sales and residual failures.
Failover routing by the numbers
Typical availability achieved by merchants using multi-acquirer redundancy to bypass individual provider outages, based on industry-standard infrastructure reliability.
The estimated volume of transactions usually lost to technical declines and service timeouts. It can be recovered through automated path redirection.
The standard duration required for a modern orchestration engine to identify a gateway timeout. The engine then initiates an alternative routing path.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with Failover routing
- Establish strict latency timeout rules that trigger secondary transaction attempts when a primary provider delays responses.
- Parse specific scheme decline codes to distinguish soft failures from hard declines before initiating retry sequences.
- Configure cascading pathways that push rejected transactions through a tiered list of alternative acquirer partners automatically.
- Protect checkouts from total outages by detecting gateway unresponsiveness and redirecting payloads to operational backup endpoints.
- Access failover success analytics to track exactly how much revenue the automatic retry logic rescues monthly.
- Maintain distinct retry configurations for different payment methods to respect individual scheme rules regarding secondary attempts.
A short scoping call, then a written plan for your MIDs.
Questions about Failover routing
How does the gateway distinguish between soft and hard declines?
The platform evaluates the exact response codes returned by the acquiring partner or issuing bank. Hard declines, such as codes indicating a lost card or insufficient funds, mean the transaction cannot proceed under any circumstances.
Soft declines typically involve temporary network issues, generic processor errors or timeout responses. Cardflo maps these raw acquirer responses against a central matrix to determine whether a transaction qualifies for a retry.
Administrators can adjust these definitions within the dashboard to align with their specific risk tolerance and technical setup.
Which outage signals activate payment failover routing between acquirer partners?
Payment failover routing can react to connection failures, unavailable endpoints, repeated HTTP errors and authorisation responses that indicate a temporary service problem. Cardflo’s gateway orchestration applies configured health checks and response rules before directing an eligible transaction through the acquirer partner network.
A failover is not triggered merely by slower-than-usual processing unless the defined latency timeout is reached.
How are latency timeouts configured for failover routing during acquirer downtime?
Technical teams can set timeout rules that define how long the orchestration layer waits for an acquirer partner response before treating the attempt as unavailable. Thresholds should reflect normal endpoint latency, checkout tolerance and the risk of an authorisation arriving after the timeout.
Cardflo applies these rules to eligible transactions and records the timeout event, route used and eventual outcome for analysis.
Which metrics show whether acquirer cascading recovers failed payment attempts?
Failover reporting can separate the original attempt from the subsequent acquirer partner attempt while linking both to the same payment journey. Finance and technical teams can analyse recovery rate, response time, decline reason, timeout frequency, route sequence and final authorisation outcome.
These metrics show whether cascading is rescuing eligible payments or merely extending checkout time without producing additional approvals.
Related guides.
See how Cardflo compares.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.