Skip to main content
TL;DR: A decline is a normal failed session, not an error — confirm with a GET, then start a new session with a new order_reference if the shopper wants to try again.
A declined card is a normal outcome, not an error — the gateway still responds successfully, it just reports that the issuer didn’t approve the charge. On hosted checkout, a decline looks identical to a shopper simply abandoning checkout at the redirect layer, which is exactly why you confirm server-side instead of trusting the return URL.

When this happens

  • The issuer declines the card (insufficient funds, risk block, expired card, and so on).

What you see

Don’t treat every cancel_url return as “the shopper cancelled.” A decline and a genuine abandon both land here with no params — the only way to tell them apart is a GET on the session.

What to do

1

Confirm the outcome with a GET

Since the redirect carries nothing to distinguish a decline from an abandoned checkout, check the session directly (API reference):
A status of failed confirms a decline (or another failure) rather than an abandon (which stays pending until it expires).
2

Show the shopper a generic decline message

Avoid echoing the issuer’s specific reason back to the shopper — see Decline codes for how to interpret the code internally without exposing it.
3

Start a new session for another attempt

The failed session can’t be retried in place. Create a new checkout session, with a new order_reference so it doesn’t collide with the terminal one (API reference):
Reusing the same order_reference as the failed session returns that same terminal session again — it doesn’t create a new attempt. Use a new reference for a genuine retry. See Prevent duplicate payments for the full guidance on choosing and reusing order_reference.

Decline codes

Interpret the issuer’s response code.

Verify the payment result

The full decision table for every result signal.

Session lifecycle

Why a failed session can’t be replayed with the same order reference.

Handle failures

All ten failure scenarios, symptom → page.
Last modified on September 15, 2026