Failover routing
Payment failover routing ensures that e-commerce checkouts continue to process orders when a primary acquiring partner experiences downtime. Cardflo detects gateway latency or soft declines and automatically redirects the transaction to a secondary route, rescuing revenue without merchant intervention.
- Category
- Routing
- Capabilities
- 10
- Available on
- All plans
Maintain payment processing continuity by automatically redirecting transactions when an acquirer or gateway experiences an outage or performance degradation. Cardflo's failover routing prevents lost sales and provides uninterrupted service, even during unforeseen disruptions.
Configure primary and secondary routing paths for specific transaction types, MIDs, or geographic regions. Health checks continuously monitor the status of all configured endpoints, enabling rapid and intelligent failover to maintain processing integrity.
Failover routing automatically reroutes transactions to operational MIDs in the event of an acquirer outage or technical failure. This proactive approach ensures merchant uptime and protects against lost revenue from processing interruptions.
Failover routing overview
Payment reliability is crucial for all merchants, yet outages and performance issues with acquirers or gateways are an operational reality. Cardflo’s failover routing proactively addresses these challenges by continuously monitoring the health and responsiveness of all configured payment service providers.
This mechanism ensures that transactions are always directed to healthy, operational endpoints, safeguarding against processing interruptions and protecting revenue streams.
The system employs a combination of passive and active health checks to detect issues ranging from complete service outages to elevated response times that could impact customer experience. Upon detecting a problem, traffic is automatically diverted to pre-defined alternative routes according to merchant-configured priority rules.
This dynamic rerouting happens in milliseconds, making the process imperceptible to the end customer.
Furthermore, failover routing helps merchants manage practical constraints like monthly volume caps and individual MID limits. When a primary acquirer is approaching its pre-set volume threshold, traffic can be intelligently shifted to an alternative provider, or specific MIDs can be activated or deactivated to ensure continuous processing without exceeding limits and incurring penalties.
How failover routing works
Configure health checks
Merchants define parameters for active and passive health checks for each integrated acquirer and gateway endpoint. These checks can include synthetic transactions, API response time monitoring, and assessment of error rates. Thresholds are set for each parameter to determine what constitutes a 'healthy' versus 'degraded' status.
Monitor for degradation
The Cardflo engine continuously monitors the configured endpoints based on the established health checks. Any deviation from the defined thresholds, such as increased latency, higher error rates, or a complete lack of response, triggers an alert within the system. This identifies potential or actual service impairments.
Trigger failover
Upon detecting a degraded or failed endpoint, the system automatically initiates a failover event. Transactions are immediately redirected to a pre-configured alternative acquirer or gateway, following a prioritised list defined by the merchant. This redirection occurs without manual intervention and is invisible to the customer.
Restore service and alert
Once the original acquirer or gateway restores its service and its health checks return positive, the system will, if configured, automatically restore traffic to that endpoint. Detailed notifications are sent to merchant operations teams, confirming both the failover and the subsequent restoration of service.
Why failover routing matters
Maintain uninterrupted revenue streams
Outages or performance slumps from a single acquirer can directly translate into lost sales and customer dissatisfaction. Failover routing automatically diverts payments to operational pathways, ensuring transactions continue to be processed successfully, thus protecting against revenue loss and maintaining a consistent income flow even during external disruptions to payment infrastructure. Automated failover prevents manual intervention during critical moments, reducing the operational burden on internal teams.
Meet compliance and risk thresholds
Many acquiring agreements include clauses regarding maximum transaction volumes or chargeback thresholds per MID, exceeding which can lead to higher fees or outright suspension. Failover routing allows for proactive management of these limits by intelligently distributing transaction volume across multiple MIDs or acquirers, preventing breaches and associated penalties. This proactive management is critical for sustaining long-term, cost-effective acquirer relationships and avoiding unexpected service interruptions due to non-compliance.
Failover routing use cases
Flash sale timeout recovery
Limited-release product drops can produce abrupt checkout bursts, causing gateway requests to exceed latency thresholds while stock remains reserved for only minutes. Cardflo monitors endpoint response times, stops retries that risk duplicate authorisations and cascades timed-out transactions to an available acquirer partner before basket reservations expire.
Soft decline rescue rules
Card-not-present checkouts may return temporary decline responses such as issuer unavailable or processing error, although the shopper’s card remains valid. Cardflo classifies eligible response codes, applies controlled retry triggers through another acquirer partner and records whether the failover attempt recovered the sale without creating duplicate transactions.
Maintenance window continuity
Planned gateway or acquirer maintenance can interrupt overnight orders when technical teams have limited capacity to intervene. Cardflo uses health checks and configurable latency timeouts to identify an unavailable endpoint, divert new authorisation requests through the acquirer partner network and restore the standard route only after service has stabilised.
Peak checkout outage bypass
Major product launches can coincide with an acquirer endpoint failure, leaving otherwise valid card payments pending or declined during the busiest trading period. Cardflo detects elevated timeout and connection-error rates, activates secondary acquirer cascading for affected authorisations and provides failover success analytics so technical teams can assess recovered sales and residual failures.
Failover routing by the numbers
Typical availability achieved by merchants using multi-acquirer redundancy to bypass individual provider outages, based on industry-standard infrastructure reliability.
The estimated volume of transactions usually lost to technical declines and service timeouts. It can be recovered through automated path redirection.
The standard duration required for a modern orchestration engine to identify a gateway timeout. The engine then initiates an alternative routing path.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with Failover routing
- Configure health check frequencies for each acquirer endpoint to detect service degradation promptly.
- Define primary, secondary, and tertiary routing preferences for different transaction categories.
- Implement circuit breakers to prevent cascading failures during severe payment processor outages.
- Monitor real-time transaction throughput and response latency for all connected payment services.
- Receive alerts via PagerDuty or email when a failover event is triggered or resolved.
- Set volume thresholds for individual MIDs to automatically initiate traffic redistribution.
- Drain existing connections from a primary acquirer before routing new transactions to an alternative.
- Restore traffic automatically to a primary endpoint once its health checks return positive.
- Review detailed logs of all failover events, including timestamp, reason, and new route.
- Simulate failover scenarios in a sandbox environment to validate routing configurations.
A short scoping call, then a written plan for your MIDs.
Questions about Failover routing
What is the difference between failover routing and load balancing in payments?
Load balancing distributes transaction volume across multiple providers simultaneously to optimise performance or costs. Failover routing is a reactive mechanism that only redirects traffic when a primary provider fails.
While load balancing is a standard operational state, failover is a recovery event triggered by specific error thresholds or downtime. In a sophisticated payments stack, both are used together to ensure both efficiency and resilience.
Load balancing manages the daily flow, while failover provides the safety net.
Which outage signals activate payment failover routing between acquirer partners?
Payment failover routing can react to connection failures, unavailable endpoints, repeated HTTP errors and authorisation responses that indicate a temporary service problem. Cardflo’s gateway orchestration applies configured health checks and response rules before directing an eligible transaction through the acquirer partner network.
A failover is not triggered merely by slower-than-usual processing unless the defined latency timeout is reached.
How are latency timeouts configured for failover routing during acquirer downtime?
Technical teams can set timeout rules that define how long the orchestration layer waits for an acquirer partner response before treating the attempt as unavailable. Thresholds should reflect normal endpoint latency, checkout tolerance and the risk of an authorisation arriving after the timeout.
Cardflo applies these rules to eligible transactions and records the timeout event, route used and eventual outcome for analysis.
Which metrics show whether acquirer cascading recovers failed payment attempts?
Failover reporting can separate the original attempt from the subsequent acquirer partner attempt while linking both to the same payment journey. Finance and technical teams can analyse recovery rate, response time, decline reason, timeout frequency, route sequence and final authorisation outcome.
These metrics show whether cascading is rescuing eligible payments or merely extending checkout time without producing additional approvals.
What happens to 3D Secure authentication during a failover event?
If 3DS authentication has already been successfully completed, the authentication payload must be compatible with the secondary acquirer for the failover to succeed. If the interruption occurs before 3DS is finalised, the system may need to restart the authentication flow with the new provider.
Advanced orchestration platforms manage these handovers to ensure that the SCA requirements of PSD2 are still met during the redirection.
How quickly can the system detect a failure and switch to a new acquirer?
Detection usually happens within milliseconds or after a defined number of consecutive failures. Merchants can set thresholds, such as three consecutive 5xx errors or a timeout exceeding five seconds.
Once the threshold is met, the switch is instantaneous for all subsequent transactions. This rapid response is critical for maintaining high-volume checkout flows where even a few minutes of downtime can result in significant revenue loss.
Related guides.
See how Cardflo compares.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.