On this page
No Headings
Last updated: July 8, 2026
The Attempts and Declines report provides insights into payment transactions that were attempted and those that were declined. It covers transactions that were made using payment methods such as debit cards, credit cards, Apple Pay, and Google Pay, and it includes both successful attempts and reasons for declines.
If you opt in to PayPal's fraud protection tools, the report also includes data about fraud risk scores and the filters that triggered authorization declines.
Use this report to understand the factors behind transaction outcomes on a daily basis and to improve authorization success rates, increase sales conversions, and manage risk.
Before using this report, review these important requirements and considerations:
/ppreports/outgoing directory. For help with SFTP access, see Access SFTP reports.To see what's available in this report, download a sample in CSV format. This sample may vary from your actual report, depending on your configuration.
To maintain backward compatibility, read the report data by column header name instead of column index.
Attempts and Declines report files follow this naming convention:
{encryptedSubscriptionId}-{NodeIdentifier}-AADR-ATTEMPTS_AND_DECLINE_REPORT-{startDate}-{fileNumber}-{totalFiles}-{genDateTime}.CSVFor example:
0003EPN-XWSFEXVAAJLVN-AADR-ATTEMPTS_AND_DECLINE_REPORT-20240701-1-1-20240701000000.CSV
For more details about the file naming convention, see the Terminology.
Each row of the report consists of a 2-letter row type, followed by the details for that row type. The following table lists the valid row types and the sections that describe the data for that row type.
| Code | Section | Description |
|---|---|---|
RH | Report header | Contains report metadata including name, status, generation date, account hierarchy, and timezone. |
RD | Report details | Contains payment attempt and transaction decline details. |
RF | Report footer | Contains the file number, total record count, and total file count. |
The report header contains metadata about the report, including its name, generation status, date, account hierarchy, and time zone.
| Position | Column name | Required | Data type | Description |
|---|---|---|---|---|
| 1 | RH | Required | Static, 2 characters | The row type (report header, RH) |
| 2 | Report Name | Required | Varchar(256) | The report name: ATTEMPTS_AND_DECLINE_REPORT |
| 3 | Report Status | Required | Varchar | The report generation status: Success or Error |
| 4 | Report Generated | Required | Date-time | The generation date of the file, in this format: YYYY-MM-DD |
| 5 | Hierarchy | Required | Varchar(256) | The encrypted PayPal account number for the account |
| 6 | Time Zone | Required | Varchar(256) | The time zone of the report |
The report details section contains 1 row per authorization attempt, including decline reasons, fraud signals, and PayPal product flags where applicable.
| Position | Column name | Required | Data type | Description |
|---|---|---|---|---|
| 1 | RD | Required | Static, 2 characters | The row type (report details, RD) |
| 2 | Partner Identifier | Optional | Varchar(256) | The partner identifier that is associated with the transaction |
| 3 | Merchant Account ID | Required | Varchar(256) | The encrypted account number of the merchant |
| 4 | Authorization ID | Optional | Varchar(256) | The encrypted authorization ID |
| 5 | Order ID | Optional | Varchar(256) | The order ID that was created at the time of the transaction |
| 6 | Invoice ID | Optional | Varchar(256) | The invoice ID that was passed at the time of the transaction |
| 7 | Custom Field | Optional | Varchar(256) | A field for custom data |
| 8 | Authorization Status | Required | Varchar(256) | The authorization outcome: Authorized or Declined |
| 9 | Authorization Date | Required | Date-time | The date and time the authorization was initiated, in this format: YYYY-MM-DD HH:MM:SS offset. offset is the 5-character signed offset from GMT, for example +0800. |
| 10 | Authorization Amount | Required | Numeric(23,2) | The authorized amount |
| 11 | Currency | Required | 3-character currency code | The currency of the transaction |
| 12 | Payment Instrument Type | Optional | Varchar(256) | The method of payment that was used to process the transaction |
| 13 | Payment Instrument Subtype | Optional | Varchar(256) | The specific tender that was used to process the transaction |
| 14 | BIN | Optional | 6-8 digits | The Bank Identification Number of the card that was used |
| 15 | Card Number | Optional | Varchar(256) | The masked credit card number (for example, **********4545) |
| 16 | Card Issuing Bank | Optional | Varchar(256) | The name of the bank that issued the card. Not available for virtual credit cards. |
| 17 | Card Issuing Country | Optional | Varchar(256) | The country where the card-issuing bank is based |
| 18 | Decline Reason | Required | Varchar(256) | The category of the decline reason: - Platform Decline: Declined due to risk, policy, platform issues, or instrument decline - Processor Decline: Declined by the processor or due to a processor error - Fraud Protection Decline: Declined by PayPal's fraud protection tool after applying fraud filters Note: Fraud decline details are available only to merchants subscribed to PayPal's fraud protection tool. |
| 19 | Decline Reason Details | Optional | Varchar(256) | Additional details about the decline reason |
| 20 | Risk Filter Applied | Optional | Varchar(256) (JSON) | A list of risk filters that were applied and contributed to the decline. Note: Available only to merchants subscribed to PayPal's fraud protection tool. |
| 21 | Risk Score | Optional | Numeric | The transaction risk score. Note: Available only to merchants subscribed to PayPal's fraud protection tool. |
| 22 | Risk Score Details | Optional | Varchar(256) (JSON) | Detailed breakdown of the transaction risk score. Note: Available only to merchants subscribed to PayPal's fraud protection tool. |
| 23 | Account Updater | Optional | Varchar(256) | Indicates whether the Account Updater product was applied during the authorization attempt. The value is Applied if the product was used. |
| 24 | Tokenization | Optional | Varchar(256) | Indicates whether tokenization was used during the authorization attempt. The value is Applied if tokenization is used. |
| 25 | 3DS | Optional | Varchar(256) | Indicates whether a 3D Secure check was performed during the authorization attempt. The value is Applied if a 3D Secure check was performed. |
| 26 | Fraud Screening | Optional | Varchar(256) | The fraud protection screening status: Standard (Fraud Protection Standard was applied), Advanced (Fraud Protection Advanced was applied), or blank (not subscribed to a fraud protection product) |
| 27 | Email ID | Optional | Varchar(256) | The email address of the buyer |
| 28 | Billing Zip Code | Optional | Varchar(256) | The buyer's billing zip code |
| 29 | Payment Channel | Optional | Varchar(256) | Indicates if the transaction is Online, PoS or MOTO. |
| 30 | Offline Payment | Optional | Boolean | Indicates whether the transaction was processed offline. An offline transaction is approved without internet connectivity and later approved or declined by the network. |
| 31 | Offline Approval Time | Optional | Date-time | The date and time the offline authorization was initiated, in this format: YYYY-MM-DD HH:MM:SS offset. offset is the 5-character signed offset from GMT, for example +0800. |
| 32 | Store ID | Optional | Varchar(256) | The ID of the store where the transaction was initiated. |
| 33 | Reader ID | Optional | Varchar(256) | The terminal ID of the store where the transaction was initiated. |
| 34 | Risk Status | Optional | Varchar(256) | The risk status based on the fraud protection filters configured by the merchant: Approved (risk approved the transaction), Declined (risk declined the transaction), or In Review (transaction flagged for review — action required). |
| 35 | Related Authorization ID | Optional | Varchar(256) | The immediate parent authorization ID. For example, for an incremental authorization ID, the parent is the estimated authorization ID. |
The report footer indicates the file number, total record count, and total number of files that were generated for the report.
| Position | Column name | Required | Data type | Description |
|---|---|---|---|---|
| 1 | RF | Required | Static, 2 characters | The row type (report footer, RF) |
| 2 | File Number | Required | Numeric(23,2) | The current file number. This corresponds to the file number in the file naming convention. |
| 3 | Total Records | Required | Numeric(23,2) | The total number of transactions in the report details section for this file. This field appears only when transactional details are present. |
| 4 | Total Files | Required | Numeric(23,2) | The total number of files that were generated for the report |