Prevent duplicate payment charges
Mallow blocks duplicate payment charges automatically. If you or your client accidentally submit the same payment attempt twice, the second submission is rejected instead of creating a second charge. This applies to invoice payments, vault charges, and subscription billing.
When duplicate prevention applies
The safeguard is active in three places:
Public invoice payments — when a client pays through the invoice link
Vault charges — when you charge a stored payment method from the Vault or a client profile
Subscription billing — when Mallow automatically charges a subscription for the first time or on renewal
What happens when the same attempt is submitted twice
Each time someone clicks Pay Invoice or Charge this payment method, the system generates a fresh attempt ID. If the exact same attempt is resubmitted, the system rejects it.
On the public invoice pay page
If a client resubmits the same payment attempt, they see one of the following:
If the payment already succeeded: a success message with Payment already processed and the original receipt details.
If the payment is still processing: an error message such as Payment is already processing for this invoice or Payment is already processing for this request.
If the invoice is already paid or ACH settlement is pending: the page says the invoice is already paid or that the payment is still settling.
The Pay Invoice button is disabled while a payment is processing, which also reduces accidental double-clicks.
On vault charges
When you charge a stored payment method, the same guard applies. If you or another team member submits the same charge attempt twice, the second request is blocked and no duplicate charge is created.
On subscription billing
Subscription billing runs in the background. If a scheduler run overlaps with another, the duplicate run does not create a second charge. The subscriber receives only one billing email and one receipt.
The difference between a duplicate resubmit and a genuine retry
This is the most important distinction to understand:
Duplicate resubmit — clicking Pay Invoice or Charge again before the first attempt finishes, or refreshing the page and resubmitting the same form data. The system recognizes this as the same attempt and blocks it.
Genuine retry after failure — the first payment truly failed, and you or your client start a new payment with fresh details or a different card. Because the failed payment is no longer active, the system allows a new charge attempt.
Failed and refunded payments do not block new attempts. Only payments that are currently pending or already completed are protected.
What to do if a payment is blocked as a duplicate
If you see a duplicate-prevention message, check the payment status first before trying again.
Go to Merchant Hub > Payments and filter by the invoice.
If the status is Completed, the payment already went through. No further action is needed.
If the status is Pending or ACH Pending, wait for it to finish. Do not resubmit.
If the status is Failed, you can start a new payment attempt with fresh details. This is a genuine retry, not a duplicate.
Bank transfers can show ACH Pending for 2–5 business days. That is normal processing, not a failure. See ACH bank transfer payments for the full timeline.
Related articles
Recover failed or incomplete payments — how to check failure codes and retry safely.
Access stored payment methods — how to charge a saved card or bank account.
Invoice types — how subscription auto-pay works.
Create an invoice — sending the public payment link to clients.