Last updated August 7, 2026
A card authorization is the client giving you permission to use their card to pay a supplier. The form encrypts the card details and stores them as a token, which you can reveal to run through your supplier (cruise line, hotel, tour operator, etc.) when you submit the booking. JourneyFuse does not run the actual card charge — the supplier does that on their end.
All card authorizations across your trips live under Invoices & Cards → Card Authorizations in the sidebar. The list is grouped by status:
Use the search bar to find an authorization by client, trip, or the card's last four digits.
There are three ways to start a new authorization:
For an event or a room block where you do not know yet who is coming, use a shared link instead (below). If you are sending several authorizations on the same trip, set the trip up once first (below) so each one opens already filled in.
You do not need a booking, an invoice, or even a trip. A card authorization is tied to a client, so you can send one the moment a client wants to pay, before anything else is loaded into JourneyFuse. If the client already has trips, you can optionally attach one under Link to Trip so the authorization files itself alongside that trip's money.
Either way, specify:
This generates a unique, shareable link.
If you run hosted events or hold a room block, you are charging the same price and the same handling fee to everyone on that trip. Set it once on the trip rather than retyping it for each traveler.
Open the trip, go to Payments, and find How this trip collects cards. Click Set up and fill in your price, your handling fee and your terms. From then on:
Edit changes the setup for everything you send from then on. It never rewrites an authorization somebody has already signed, and it will not let you drop your total available below the number of seats already taken.
A trip holds one setup. If you want two different prices on one trip, they are two trips.
A normal authorization is for one client you have already added. That does not fit an event or a room block, where you publish the details first and find out afterwards who is coming. A shared link is one link you post anywhere, and everyone who opens it authorizes their own card for their own seats.
Publish one from the trip (above), or for an event with no trip behind it, go to the Card Authorizations page, click New shared link and set:
Your payer sees the event and the price, enters their name and email, then lands on the normal card page to choose how many and enter their card. Each one becomes an ordinary card authorization in the list below, so you charge, reveal and receipt them exactly as you always have. Anyone who is not already a client is added as one, assigned to you.
The link shows how much of your block is gone. A payer who starts but does not finish still holds their seats, which is what stops the block being oversold while several people are checking out at once. Revoking their authorization gives those seats straight back.
Close stops the link taking anything new without touching what it has already collected. Reopen it any time.
The amount you enter is not just for your own records. Your client sees it in the request email and again on the authorization page, so it is worth a second look before it goes out.
After the link is created, click Preview email next to the Send to field. You will see the exact subject line, the greeting, the description, and the amount your client will read. If the amount looks wrong (for example a booking total that did not import the way you expected), close the dialog, correct the figure, and create the authorization again.
Share the card authorization link with your traveler. They'll see a secure form asking for:
All card data is encrypted by Evervault before it leaves the browser — your agency never sees or stores raw card numbers.
Once the traveler submits:
At this point the card is ready to use. To actually run the card, open the authorization and click Reveal Card to see the full number, expiry, and CVV — then enter those into your supplier's booking system. The client's card will only be charged when the supplier processes it.
You don't need to do anything for the happy path — the authorization stays valid for the access duration you set and the card details remain available to reveal whenever you submit the booking.
| Status | What it means |
|---|---|
| Pending | Created but the traveler hasn't submitted yet |
| Authorized | Card details collected and ready to use with your supplier |
| Charged | You have marked the authorization as processed by the supplier |
| Declined | The supplier declined the card when you ran it |
| Expired | Authorization window has passed |
| Revoked | You manually cancelled the authorization |
When the client submits the form, the authorization moves to Authorized. JourneyFuse also creates a payment record on the invoice for tracking, so the invoice reflects that the client has provided payment. The card itself has not been charged at this point.
When you run the card through your supplier's booking system and the charge goes through, click Mark as Charged to update the status. If the supplier declines the card, click Mark as Declined so the invoice can be re-collected.
The system will not double-create payment records on the invoice when you mark as charged, so it's safe to click after the supplier has processed the card.
You can revoke any pending or authorized card auth at any time. This immediately destroys the encrypted card data and prevents future charges.
When a client opens their authorization link, here is the exact flow they go through:
The card is never transmitted in plaintext. Neither JourneyFuse nor your agency ever sees or stores the raw card number.
The authorization agreement your client signs covers two things:
When you have a Terms & Conditions URL configured (see below), a direct link to your agency's terms appears inside the agreement text, right where the client reads it before signing. This is critical for chargeback defense: card networks specifically look for evidence that the cardholder agreed to the cancellation and refund policy at the time of booking.
Go to Settings → Agency → Terms & Conditions and paste the URL to your agency's terms and conditions page.
Once set, your T&C link appears directly in the authorization agreement text. Clients see it, click through to read it, and agree to it as part of authorizing their card. This single step materially strengthens your position if a chargeback is ever filed — the signed authorization becomes evidence that the cardholder agreed to your cancellation and refund policy before any payment was processed.
If you don't have a Terms & Conditions page yet, consider creating a simple one on your agency website covering your booking terms, deposit conditions, and cancellation/refund policy. Even a one-page PDF hosted publicly works.
Your terms appear on the authorization page as an expandable Terms & Conditions section, directly above the agreement checkbox, so the client reads and accepts them on the same page where they enter the card. The acceptance is timestamped and stored with the authorization.
When you create a request, Include Terms & Conditions is checked by default whenever you have terms on file. Uncheck it for a one-off request that shouldn't carry them. If you don't have any terms set, the checkbox doesn't appear and the request goes out without a terms section.
Which terms get attached follows the same rule as your proposals and invoices: your personal advisor terms if you've set any, otherwise your agency's default. See Advisor & Agency Terms & Conditions for how to set either one.
Lite advisors: set your terms under My Profile → My Terms & Conditions in the advisor portal. They apply to the card authorizations you send, whether or not the request is attached to a trip.
Every card authorization captures a permanent audit trail at the moment the client submits:
| Evidence | What is recorded |
|---|---|
| Signer name | The full name the client typed as their electronic signature |
| Date and time | The exact timestamp of submission |
| IP address | The IP address the authorization was submitted from |
| Authorization statement | The exact text of the agreement the client agreed to, preserved as it appeared at submission |
This audit trail is immutable — it cannot be altered after the fact.
To access the evidence for a specific authorization:
When a chargeback is filed, you present this receipt as evidence that the cardholder explicitly authorized the charge, agreed to your cancellation and refund policy, and signed electronically with their name, date, and IP address recorded.
Create invoices from trips, track payment status, and manage overdue balances across your client bookings.
Attach agency and supplier terms to invoices, override per invoice, and control what clients see on the public invoice page.
Record payments on invoices, assign them to travelers, and track payment history with status updates.