Decline codes

Stripe decline codes and what to do about each

When a card payment fails, Stripe says why with a decline code. Each guide covers what Stripe says the code means, whether a retry can work, and what Dunity does with it.

  • $29/month, flat
  • Cancel anytime
  • Restricted Stripe key only

The guides

9 codes, grouped by what each one needs. Stripe defines many more, and its full list is in its own decline codes docs.

Soft and hard declines

Stripe calls a decline hard when the card issuer has rejected the payment and it can’t succeed on a retry without a new payment method. Stripe’s automatic retries skip these. Anything else can still succeed on a later attempt, which is why Stripe spaces its retries out and recommends no more than eight.

Stripe’s list of hard decline codes for subscription payments:

  • incorrect_number
  • lost_card
  • pickup_card
  • stolen_card
  • revocation_of_authorization
  • revocation_of_all_authorizations
  • authentication_required
  • highest_risk_level
  • transaction_not_allowed

From Stripe’s Smart Retries docs. 3 of the 9 guides here are on it: authentication_required, lost_card, stolen_card.

What Dunity does after any decline

  1. Stripe tells Dunity about the failed payment, and Dunity records the invoice, the amount and the decline code.
  2. Dunity emails your customer once, with a link to update their card. The email doesn’t say why the payment failed.
  3. The first retry comes 24 hours later, or 72 hours after an insufficient_funds decline. It tries up to 5 times, and you can change the delays and the limit.
  4. If a retry comes back as a hard decline, Dunity stops there and marks the payment Failed. The link in the email still works for the customer.

The whole flow, including the payment wall and the win-back offer, is on how Dunity works, and what to set up in Stripe first is on the Stripe setup guide.

Decline code questions

What people ask about failed payments and Stripe’s codes.

What is a Stripe decline code?

It is the reason the card issuer gave for declining a payment, passed on by Stripe. You can see it in your Stripe Dashboard and through the API. Issuers report most declines as generic, so many payments come back with generic_decline and no more detail.

What is the difference between a soft and a hard decline?

Stripe calls a decline hard when the card issuer has rejected the payment and it can’t succeed on a retry without a new payment method. Stripe’s own automatic retries skip those. Other declines can still succeed on a later attempt.

Should I tell my customer why their payment was declined?

Not for every code. Stripe says not to report the specific reason when a card is reported lost or stolen, or when Stripe suspects fraud, and to show a generic message instead. Dunity’s default email never states a reason.

How many times will Dunity retry a declined payment?

Up to 5 attempts by default. The first retry comes 24 hours after the failure, or 72 hours after an insufficient_funds decline, and you can change the delays and the limit in Settings. Stripe recommends no more than eight retries on a charge.

Does Dunity stop retrying when a decline is a hard one?

Yes. When a retry comes back with one of Stripe’s hard declines, or needs the customer to authenticate, Dunity marks the payment Failed and makes no more attempts. The first retry still runs, because that is how Dunity finds out the card still declines this way.