Authorize.Net

Mastercard Transaction Link ID Rule Reaches Recurring Charges October 23, Not December 1

Stripe, Checkout.com, and Worldpay documentation puts Mastercard's requirement that recurring and other merchant-initiated charges carry the original Transaction Link Identifier on October 23, 2026. The December 1, 2026 and January 31, 2027 dates now circulating match Worldpay's schedule for lifecycle linking, and Authorize.Net and NMI have not published TLID guidance.

Illustration of a mother and her teenage son checking a laptop at the kitchen table on an October night, a red-circled date on the calendar behind them and a stack of shipping boxes waiting nearby.

Mastercard’s rule that recurring and other merchant-initiated card charges carry a Transaction Link Identifier (TLID) takes effect on October 23, 2026, according to developer documentation from Stripe, Checkout.com, and Worldpay. That is 13 days away. A later pair of dates, December 1, 2026 and January 31, 2027, has been reported as the comply-by date and start of fines for recurring billing, but Worldpay’s published schedule ties those two dates to an earlier, narrower phase of the same mandate.

The difference matters for subscription merchants, including supplement autoship programs, telehealth memberships, and CBD clubs, whose cards sit in a gateway vault or a separate billing engine. Each renewal charged to a Mastercard after October 23 is supposed to carry the TLID from the checkout where the customer first agreed to be billed. Whether that happens automatically depends on where the card is stored and which system sends the charge.

What the TLID is

The TLID is a 22-character code that Mastercard generates for a transaction and returns in the authorization response. Stripe’s TLID documentation describes it as alphanumeric and case sensitive, with hyphens and underscores allowed, and gives e7R9d3L2-Q9vS6pP1_WzEh as an example. Mastercard’s own Mastercard Send release notes 26.1 say the identifier travels in a new Data Element 105, subelement 001, announced in bulletin GLB 7102.7, and is used “identically across the network message platforms.”

Two kinds of linking are involved. Lifecycle linking ties an authorization to its own clearing record, refund, or chargeback. Economic linking, the part aimed at subscriptions, ties every merchant-initiated transaction (MIT), such as a monthly renewal, back to the cardholder-initiated transaction (CIT) where the customer saved the card. The TLID does not replace the existing Mastercard Trace ID. Worldpay’s TLID guide says the two “will run in parallel (both required) until future notice.”

Two phases on two schedules

Worldpay’s guide lays out the mandate as two phases, and it is the clearest public timeline EC4IM found. Mastercard rarely posts its bulletins publicly, and EC4IM did not review the underlying Mastercard announcements.

  • Phase I, lifecycle transactions. Effective October 17, 2025, acquirers and merchants must pass the TLID from the original authorization into later messages in the same transaction. Worldpay lists Mastercard’s monitoring schedule for this phase as June 2, 2026 (monitoring begins), July 1, 2026 (notifications begin), December 1, 2026 (“Worldpay expected to comply”), and January 31, 2027 (“Assessments begin (fines)”).
  • Phase II, economically related transactions. Effective October 23, 2026, Mastercard requires acquirers and merchants globally “to send the TLID provided by Mastercard on the original cardholder-initiated transaction response, in all merchant-initiated authorisation requests,” according to Worldpay. Recurring and subscription payments are listed among the affected transactions.

Stripe gives the same Phase II dates in its own terms. Starting June 2, 2026, processors had to retain TLIDs from CITs that set up future card use, and starting October 23, 2026, they must send the retained TLID “with all subsequent merchant-initiated-transactions.” Checkout.com’s support article, dated July 7, 2026, says that on October 23 Mastercard “will require the TLID” for recurring payments and instalments, and that the mandate applies in all regions.

Where the December 1 date comes from

Merchant Cost Consulting’s October 2 roundup of network changes calls December 1, 2026 “the comply-by-date for Mastercard’s new TLID on recurring billing transactions” and says assessments for non-compliance begin January 31, 2027. Rivero, a dispute software company, wrote in April that formal compliance with the October 23 phase “is required by 1 December 2026, with assessments beginning 31 January 2027.”

Other sources point the December date at clearing records rather than renewals. J.P. Morgan’s payment brand changes page for its Online Payments API says that “starting December 1, 2026, deposit transactions will be considered non-compliant if the TLID is missing or incorrect.” Melissa Shields, head of payments strategy at Very Good Security (VGS), wrote in an August 26 post that the January 31, 2027 assessments “only apply to the Lifecycle Linking (authorization and clearing)” and not yet to CIT and MIT linking. She described the fees as “reportedly ranging from $2,500 to $5,000 per month, capped at $25,000,” under Mastercard’s Data Integrity Monitoring Program. EC4IM could not confirm those amounts in a Mastercard or acquirer document.

Read together, the processor documents put the recurring requirement on October 23. The December 1 and January 31 dates appear in Worldpay’s schedule for lifecycle linking, and whether Mastercard will assess fees on missing recurring TLIDs from January 31 is not settled in the public material EC4IM reviewed.

What happens to a renewal without a TLID

The sources disagree on the near-term risk. Checkout.com says that where another provider processed the original CIT, MITs missing the required TLID “may be subject to scheme fines from Mastercard or could experience higher decline rates from issuers.” VGS expects merchants to start seeing related declines around October 23. Spreedly, a payments orchestration company, says in its TLID guide that “Mastercard has confirmed there is no network logic that declines or fails a transaction due to a missing or incorrect TLID.”

None of those statements says a renewal will be blocked at the network. The exposure described is softer: issuer decisions, possible fees passed down by acquirers, and weaker evidence when a cardholder later disputes a recurring charge.

Subscriptions that started before June 2

Mastercard only began returning TLIDs to processors on June 2, 2026, so older subscriptions have no original value to send. Stripe says that in this case it sends the TLID “from the earliest authorized merchant-initiated-transaction after June 2, 2026, as Mastercard recommends.” Checkout.com tells merchants to use the TLID from the most recent successful, undisputed recurring payment within the last three months, then keep using it for the rest of the series.

A card change starts a new chain. Checkout.com says any new customer-authenticated card setup, such as adding a card or re-verifying one, is a new CIT that generates a new TLID, which must then be used for later MITs on that card. VGS adds a zero-dollar Account Status Inquiry as another way to obtain a fresh value when a stored record is unreliable.

Which providers handle it automatically

The large processors that have published guidance handle the TLID for cards stored with them:

  • Stripe stores and returns TLIDs at payment_method_details.card.transaction_link_id and sends them on MITs “if a customer originally saved their card on Stripe.”
  • Checkout.com resolves the TLID itself when both the CIT and the MIT ran through Checkout.com and the merchant sends previous_payment_id. Merchants whose first charge ran elsewhere “must capture, store, and send the TLID” in processing.scheme_transaction_link_id.
  • J.P. Morgan returns transactionLinkId and asks merchants to store it and send it back as originalTransactionLinkId on linked transactions.
  • Worldpay says users of its Integrated Payment Server (IPS) who charge stored tokens must upgrade their IPS software and store both the TLID and Trace ID from the zero-dollar verification that created the token.

The common gap is portability. A subscription that was signed up on one processor and renews on another, or a card migrated during a processor switch, needs the original TLID carried across by the merchant or its billing platform. Gr4vy’s connector guide, updated October 5, notes that importing cards from another provider does not set a TLID.

Authorize.Net and NMI have not published TLID guidance

For stores that bill through Authorize.Net’s Customer Information Manager (CIM) or NMI’s Customer Vault, the picture is less clear. Neither gateway has published TLID guidance that EC4IM could find as of October 10.

Authorize.Net’s card-on-file documentation explains how merchants link MITs using networkTransId and originalNetworkTransId, and says customer profiles “automatically send the original network transaction ID from the first transaction submitted for the payment profile.” The page does not mention the TLID. Gr4vy’s connector table lists Authorize.net as not yet supported, with the note “The Authorize.net API has no TLID field.” That is Gr4vy’s description of its own integration, not a statement from Authorize.Net about what the gateway does internally for profiles it stores.

NMI’s transaction processing reference includes stored credential fields such as initial_transaction_id but no TLID field that EC4IM found. Third-party tables differ on NMI. Gr4vy lists NMI under connectors where the provider handles the TLID, meaning cards stored with NMI have their TLID kept and replayed by NMI, while Spreedly’s table, last checked July 21, lists NMI as not yet supported for passing through a TLID supplied by the merchant. EC4IM’s comparison of NMI and Authorize.Net for high-risk stores covers how the two vaults differ more broadly. Merchants on either gateway should get an answer from the gateway itself, in writing, before October 23.

Analysis: what a subscription stack should confirm

Analysis. The points below are EC4IM’s reading of the processor documentation above, not requirements published by Mastercard.

  • Who sends the renewal. When the gateway’s own recurring module bills a card in its own vault, the gateway is in a position to keep the TLID. When a plugin or billing engine stores the token and calls the gateway for each renewal, as in a typical plugin-based subscription setup, the TLID may have to pass through that code. EC4IM’s piece on WooCommerce Subscriptions and high-risk recurring billing pitfalls describes how those layers split responsibility.
  • Whether the field exists. Merchants storing credentials themselves need a column that holds 22 case-sensitive characters, as Checkout.com advises, and a record of which TLID belongs to which subscription. Spreedly warns that a card paying for two subscriptions can get the wrong TLID if the agreements are not told apart.
  • Cards that moved. Any subscriptions migrated between processors, or routed to a backup processor for renewals, are the likeliest to be missing an original TLID.
  • Decline data after October 23. Because the sources disagree on whether missing TLIDs raise declines, Mastercard renewal approval rates in the weeks after the deadline are the practical test. EC4IM’s guide to account updater and network tokenization covers the other levers that affect those rates.

The recurring date is October 23

Processor documentation from Stripe, Checkout.com, and Worldpay places Mastercard’s requirement to carry the original TLID on recurring and other merchant-initiated charges on October 23, 2026, after a retention phase that began June 2. The December 1, 2026 and January 31, 2027 dates now circulating line up, in Worldpay’s schedule, with monitoring of lifecycle linking, and VGS says the first fees target that phase rather than renewals. Stripe and Checkout.com handle the identifier for cards they store, J.P. Morgan and Worldpay expect merchants to store and return it, and Authorize.Net and NMI have not said publicly how their vaults treat it. For subscription sellers, the open questions are which system sends each renewal, whether that system holds the TLID, and what the gateway confirms before the deadline arrives.

Sources