Card Authorizations

Last updated September 18, 2026

A card authorization is the client giving you permission to use their card to pay a supplier. The form encrypts the card details and stores them as a token, which you can reveal to run through your supplier (cruise line, hotel, tour operator, etc.) when you submit the booking. JourneyFuse does not run the actual card charge — the supplier does that on their end.

Finding Your Card Authorizations

All card authorizations across your trips live under Invoices & Cards → Card Authorizations in the sidebar. The list is grouped by status:

  • Active — collected and ready to use
  • Pending — sent but the traveler hasn't submitted yet
  • Expired & Revoked — collapsed by default; click to expand

Use the search bar to find an authorization by client, trip, or the card's last four digits.

Creating a Card Authorization

There are three ways to start a new authorization:

  • From the Card Authorizations page — click Request Card Authorization and pick the client.
  • From a client — open the client, then More → Request card authorization.
  • From a trip — open the trip, go to Payments, and click Request from a client.

For an event or a room block where you do not know yet who is coming, use a shared link instead (below). If you are sending several authorizations on the same trip, set the trip up once first (below) so each one opens already filled in.

You do not need a booking, an invoice, or even a trip. A card authorization is tied to a client, so you can send one the moment a client wants to pay, before anything else is loaded into JourneyFuse. If the client already has trips, you can optionally attach one under Link to Trip so the authorization files itself alongside that trip's money.

Either way, specify:

  • Traveler — which traveler this card auth is for
  • Amount and currency — the authorization amount
  • Access duration — how long the authorization is valid (default: 30 days)

This generates a unique, shareable link.

Set Up a Trip Once, Instead of Every Time

If you run hosted events or hold a room block, you are charging the same price and the same handling fee to everyone on that trip. Set it once on the trip rather than retyping it for each traveler.

Open the trip, go to Payments, and find How this trip collects cards. Click Set up and fill in your price, your handling fee and your terms. From then on:

  • Every card you request on that trip opens already filled in. The dialog says Using this trip's setup so you can tell the trip's numbers from anything you typed. Change a figure for one client and it says so, with Reset to the trip to put it back.
  • Publish a link turns the same setup into a sign-up link for people who are not in your client list yet.

Edit changes the setup for everything you send from then on. It never rewrites an authorization somebody has already signed, and it will not let you drop your total available below the number of seats already taken.

A trip holds one setup. If you want two different prices on one trip, they are two trips.

The trip's handling fee also reaches the cards your clients enter on their own: when they accept a proposal, pay from an invoice link, book a group seat, or answer a payment reminder. The fee is added on top of what they owe. It never reduces their deposit or their remaining balance.

Your Agency's Default Handling Fee

If you charge the same fee on every trip, owners and admins can save it once under Settings → Payments → Default handling fee. Pick a percentage or a flat amount, choose what clients see it called, and click Save.

On its own, the default fills in the fee when you set up card collection on a trip, and you confirm it there. To have it apply without setting up each trip, tick Apply to trips that have no card setup of their own. From then on:

  • Cards your clients enter from an accepted proposal, an invoice link, group checkout or a payment reminder carry your default fee on any trip you have not set up.
  • A trip's own setup always wins, including a trip where you chose No fee.
  • Payment plans are not affected, and anything already sent keeps the amount it went out with.

Your Agency's Default Terms

If you put the same paragraph on every authorization ("deposits are non-refundable once confirmed with the supplier"), save it once as your agency default instead of typing it into each trip.

Go to Settings → Payments → Default card authorization terms, type your terms and click Save. From then on:

  • Every new card request opens with your terms already filled in. You can still edit them for one client before you send.
  • Authorizations a proposal or an invoice creates carry them too, so a client who books online and enters a card sees the same terms as one you emailed directly.
  • A trip's own terms win. Anything you type under Terms for this trip replaces the agency default on that trip. Leave it blank to use the agency default.
  • The signed record matches. The chargeback evidence captured when the client signs includes the terms that were actually on their page.

Changing the default only affects authorizations created afterwards. Anything already sent keeps the terms it went out with.

Faster from where you are typing: owners and admins see Save as agency default under the terms box on a trip's setup or on a card request. It appears when you have typed something that is not already the default, and saves it with one click.

A normal authorization is for one client you have already added. That does not fit an event or a room block, where you publish the details first and find out afterwards who is coming. A shared link is one link you post anywhere, and everyone who opens it authorizes their own card for their own seats.

Publish one from the trip (above), or for an event with no trip behind it, go to the Card Authorizations page, click New shared link and set:

  • What are they authorizing — the heading on the page and on every authorization it creates
  • How it is priced — Per ticket with a price each and your own word for it (ticket, seat, guest, room), a Price list of several items with their own prices, or a Fixed amount everyone authorizes
  • Total available — your whole block. The link closes itself when the last one goes
  • Most one payer can take — so one family cannot claim the whole block (on a price list, this counts every item they pick)
  • Handling fee — a flat amount or a percentage, and a flat one can be charged per ticket or once per payer
  • Terms for this link — wording for this one event, shown above the standard authorization statement
  • Closes on — an optional last day

Your payer sees the event and the price, enters their name and email, then lands on the normal card page to choose how many and enter their card. Each one becomes an ordinary card authorization in the list below, so you charge, reveal and receipt them exactly as you always have. Anyone who is not already a client is added as one, assigned to you.

Some extras come in more than one kind at more than one price, such as checked bags and seat assignments on a group flight. Choose Price list and add one row per item:

  • Item — what the traveler is choosing, such as "Checked bag (roundtrip)" or "Aisle seat"
  • Price each — what one of that item costs
  • Most each — optional, for items that are limited, such as exit row seats

Your traveler sees every item with a plus and minus button, starting at zero. The total adds up as they choose, and they must pick at least one item before they can authorize. The total is recalculated when they submit, so what they approve is always exactly what they chose.

When you open the authorization, What they chose lists each item, how many, and the approved total, so you can enter it with the supplier in one go.

A shared link always asks for a card. For a client who already has a card on file with you, open the trip's Cards tab and use Request more on this card instead, so they approve the new amount without typing their card again.

Keeping track of the block

The link shows how much of your block is gone. A payer who starts but does not finish still holds their seats, which is what stops the block being oversold while several people are checking out at once. Revoking their authorization gives those seats straight back.

Close stops the link taking anything new without touching what it has already collected. Reopen it any time.

Previewing the Email Before You Send

The amount you enter is not just for your own records. Your client sees it in the request email and again on the authorization page, so it is worth a second look before it goes out.

After the link is created, click Preview email next to the Send to field. You will see the exact subject line, the greeting, the description, and the amount your client will read. If the amount looks wrong (for example a booking total that did not import the way you expected), close the dialog, correct the figure, and create the authorization again.

Sending the Request in Your Own Wording

The Email wording dropdown under the link lists your saved emails. To add one, go to Automations, open the Emails tab, click New email, then Write a new email, and choose Automation Template. You do not need to put it in an automation.

Decide where the secure link goes with {{card_auth_link}}:

  • On its own line, it becomes the Submit Card Details button, the same one our default wording uses.
  • Inside a sentence or a link you made, it becomes the plain web address.
  • Left out, the button is added at the end for you.

Click Preview email to see exactly what your client will receive. Resending a pending link from the list still uses our default wording.

Share the card authorization link with your traveler. They'll see a secure form asking for:

  • Cardholder name
  • Billing address
  • Card details (number, expiration, CVC)
  • An authorization agreement checkbox

All card data is encrypted by Evervault before it leaves the browser — your agency never sees or stores raw card numbers.

Once the traveler submits:

  1. The card details are encrypted and stored as a token tied to the authorization
  2. The authorization is linked to a pending payment record where the flow includes an invoice or trip payment
  3. The authorization alone does not count as collected money or mark the invoice paid
  4. You receive an email confirming the authorization with the amount, cardholder name, and last 4 digits

At this point the card is ready to use. To actually run the card, open the authorization and click Reveal Card to see the full number, expiry, and CVV — then enter those into your supplier's booking system. The client's card will only be charged when the supplier processes it.

Check the expiry shown on the authorization before using it. After the supplier processes the charge, record that result in JourneyFuse.

Card Authorization Statuses

StatusWhat it means
PendingCreated but the traveler hasn't submitted yet
AuthorizedCard details collected and ready to use with your supplier
ChargedYou have marked the authorization as processed by the supplier
DeclinedThe supplier declined the card when you ran it
ExpiredAuthorization window has passed
RevokedYou manually cancelled the authorization

Processing the Card

When the client submits the form, the authorization moves to Authorized. A linked payment remains pending until the supplier charge is confirmed; authorization is not a collected payment. The card itself has not been charged at this point.

When you run the card through your supplier's booking system and the charge goes through, click Mark as Charged to update the status. If the supplier declines the card, click Mark as Declined so the invoice can be re-collected.

The system will not double-create payment records on the invoice when you mark as charged, so it's safe to click after the supplier has processed the card.

Sending the Supplier's Receipt With the Charge

When the supplier gives you a receipt for the charge (a PDF from the cruise line, the airline confirmation with the amount paid), you can send it to your client in the same step.

  1. In the Confirm Card Charge window, click Attach supplier receipt and pick the file. Add more than one if the charge has several receipts.
  2. Leave Email a receipt to the client ticked and click Confirm Charge.

Your client gets one email: the payment receipt, with the supplier's receipt attached. The file is also saved to the trip's Documents as Client can see, so it stays in their portal and in your records.

A few things worth knowing:

  • The file goes on this trip only. On a group, each family's charge sits on their own trip, so their supplier receipt is never sent to another family.
  • No second "New Document" email. A file added here does not also send the usual new-document notice, because the receipt already carries it.
  • When no payment receipt goes out, for example the charge is not on an invoice, the client gets the usual "New Document" email instead, so they still hear about the file once. The message after you confirm tells you which happened.
  • Unticking "Email a receipt to the client" saves the file to Documents without emailing anyone.
  • Several charges at once: the files go with the first charge's receipt, so your client receives them once rather than once per charge.
  • Files up to 10MB each.

Final Payment on a Card Kept on File

Ticking Keep card on file until I remove it on a request keeps the encrypted card available for the whole trip instead of destroying it a week after the trip ends. It does not authorize any future charge on its own: every payment you plan to run still gets its own signed authorization, so each one carries its own receipt, timestamp and IP address for chargeback defense.

You do not have to chase the client for that second authorization yourself. Set the trip's invoice up with a payment schedule (a deposit row and a final payment row), open the schedule and turn on Auto-send card authorization requests, choosing how many days before the due date the request should go out (3 to 14). JourneyFuse creates the final payment authorization for you, emails the client a link on that day, and the client signs from the email or from the pending authorization card in their portal.

The request always states what is owed on the day it is sent. Deposits and installments you record before then shrink the final payment row, and the emailed amount and the authorization form follow it.

Clients cannot start a new authorization from the portal on their own. If a link has expired they can ask for a fresh one from the expired page, which notifies you rather than minting a link.

Pair this with automated payment reminders at, say, 10 and 3 days for a final payment flow that runs itself: reminder, authorization request, client signs, you run the card at the supplier and click Mark as Charged.

The setting sends one authorization per payment, that many days before that payment's own due date, so pick a single number here and let your reminder emails cover the other dates. Final Payment Workflow walks the whole deposit-to-balance setup in order, including the automation step that looks like it does this and does not.

Partial payments rarely need a second authorization. The amount a client signs is a ceiling rather than a single charge, so you can charge against it more than once until it is used up. Send a new request only when the total would go above what they already authorized.

Revoking an Authorization

You can revoke any pending or authorized card auth at any time. This immediately destroys the encrypted card data and prevents future charges.

If your client authorized the card themselves from an invoice, for an amount they typed in, revoking before you charge it also removes the pending payment that authorization created, so the client stops seeing it as something to pay. A payment you scheduled yourself stays on the trip, because that money is still owed. Money already recorded as paid is never touched by a revoke.

Security & Compliance

  • Card data is encrypted client-side by Evervault (PCI DSS Level 1 compliant)
  • Encrypted data is automatically destroyed after the authorization expires
  • Your agency never has access to plaintext card numbers
  • All actions (authorization, charging, destruction) are logged for audit

The Client's Authorization Experience

When a client opens their authorization link, here is the exact flow they go through:

  1. They land on a secure authorization page hosted by JourneyFuse
  2. They enter their card details (cardholder name, email address, billing address, card number, expiration, CVC) — all data is encrypted in the browser by Evervault before it ever leaves their device
  3. They read the authorization agreement (displayed just above the submit button) and check the agreement checkbox
  4. They type their full name as an electronic signature
  5. They click Authorize to submit

The card is never transmitted in plaintext. Neither JourneyFuse nor your agency ever sees or stores the raw card number.

Who Gets the Receipt

The authorization receipt goes to the person who typed the card, at the email address they enter on that page. It does not go to the client on the trip record unless they are the same person.

This matters on any trip where more than one person pays. If Tonya pays her own share of a trip booked under Lateisha's name, Tonya gets her receipt and Lateisha does not get one for a card she did not use.

The email field is required for that reason. It is the payer's only proof that they authorized a charge, so there is nowhere else for it to go.

Two cases still fall back to the client on the record:

  • Cards authorized before this change, which carry no payer email
  • Cards you key in yourself, over the phone or in person

Traveler share links need no email field at all. A share link is issued to one named traveler, so their receipt goes to the address already on their record.

You still get your own notification for every authorization, whoever the receipt went to.

When a Client Says They Cannot Pay

Sometimes a client tells you the payment page is not working and you cannot reproduce it on your own screen. JourneyFuse now tells you what happened rather than leaving you to take their word for it.

Two different things can go wrong, and they need different responses.

Their card was refused. They filled the form in, pressed Authorize, and were turned away. You get a red "A card payment did not go through" strip at the top of the trip's Payments tab, quoting the exact sentence your client was shown, plus a notification. Nothing was charged and nothing is owed differently. The quoted sentence is usually enough to fix it in one message, for example an amount below the minimum you set.

They could not get a card in at all. They opened the page and never reached the point of submitting. You get an amber "A client could not finish paying by card" strip and notification saying why:

What you seeWhat it meansWhat to do
The secure card form never loaded in their browserAn ad blocker, browser extension, or their network blocked the service that encrypts card details, so there were no fields to fill inAsk them to try a different browser, or the same link with blockers turned off
They started filling in the card page and left without submitting, with fields still outstandingThe form was still waiting on something. The named fields are exactly the ones their screen was showing under the buttonPhone or message them and walk through the named fields

Both strips are advisory. They move no money, change no total, and count toward nothing. Dismiss one with the × once you have dealt with it; the record is kept, not deleted.

If a client pays after you were told they were stuck, the amber strip clears itself. You will not be left chasing a payment that has already landed.

A note on repeat reports: one client wrestling with one dead form is one strip per day, not one per reload.

Authorization Language and What Clients Agree To

The authorization agreement your client signs covers two things:

  1. Payment authority — the client authorizes your agency to use their card to make payments with travel suppliers on their behalf
  2. Terms and conditions — the client acknowledges they have read and agree to your agency's terms and conditions of booking, as well as the principal suppliers' terms, cancellation policies, and refund policies

When you have a Terms & Conditions URL configured (see below), a direct link to your agency's terms appears inside the agreement text, right where the client reads it before signing. This is critical for chargeback defense: card networks specifically look for evidence that the cardholder agreed to the cancellation and refund policy at the time of booking.

Setting Your Terms & Conditions URL

Go to Settings → Agency & Branding → Defaults → Terms & Conditions (Settings → My Business → Terms & Conditions if you are a solo advisor) and paste the URL to your agency's terms and conditions page.

Once set, your T&C link appears directly in the authorization agreement text. Clients see it, click through to read it, and agree to it as part of authorizing their card. This single step materially strengthens your position if a chargeback is ever filed — the signed authorization becomes evidence that the cardholder agreed to your cancellation and refund policy before any payment was processed.

If you don't have a Terms & Conditions page yet, consider creating a simple one on your agency website covering your booking terms, deposit conditions, and cancellation/refund policy. Even a one-page PDF hosted publicly works.

Attaching Your Terms to an Individual Request

Your terms appear on the authorization page as an expandable Terms & Conditions section, directly above the agreement checkbox, so the client reads and accepts them on the same page where they enter the card. The acceptance is timestamped and stored with the authorization.

When you create a request, Include Terms & Conditions is checked by default whenever you have terms on file. Uncheck it for a one-off request that shouldn't carry them. If you don't have any terms set, the checkbox doesn't appear and the request goes out without a terms section.

Which terms get attached follows the same rule as your proposals and invoices: your personal advisor terms if you've set any, otherwise your agency's default. See Advisor & Agency Terms & Conditions for how to set either one.

Lite advisors: set your terms under My Profile → My Terms & Conditions in the advisor portal. They apply to the card authorizations you send, whether or not the request is attached to a trip.

Chargeback Evidence: What Is Captured and Where to Find It

Every card authorization captures a permanent audit trail at the moment the client submits:

EvidenceWhat is recorded
Signer nameThe full name the client typed as their electronic signature
Date and timeThe exact timestamp of submission
IP addressThe IP address the authorization was submitted from
Authorization statementThe exact text of the agreement the client agreed to, preserved as it appeared at submission

This audit trail is immutable — it cannot be altered after the fact.

To access the evidence for a specific authorization:

  1. Go to Invoices & Cards → Card Authorizations
  2. Find the authorization and open it
  3. The authorization detail shows the signer name, date/time, IP, and the agreed statement
  4. You can download or print a receipt showing the full audit trail — this is what you submit to your card processor when responding to a chargeback

When a chargeback is filed, you present this receipt as evidence that the cardholder explicitly authorized the charge, agreed to your cancellation and refund policy, and signed electronically with their name, date, and IP address recorded.