Fleet Card Processing at the Pump: How Authorization Really Works
11 p.m. at a travel plaza. A diesel truck pulls up, a WEX fleet card goes into the reader, and the driver types an ID and odometer reading. Fuel starts flowing in under 3 seconds.
What happened in those 3 seconds? Most fleet card content comes from card issuers or payment processors, and none of it explains what happens at the forecourt controller level.
This article follows the full authorization chain for fleet card processing at the pump, from card reader to controller to fleet network and back to the dispenser, covering Level III data capture, product code restrictions, driver ID verification, and network routing.
TL;DR
- Fleet cards use closed-loop networks, not Visa or Mastercard interchange.
- The forecourt controller handles routing, driver prompts, product restrictions, and dispenser activation.
- Level III data adds gallons, fuel grade, price per gallon, odometer, and driver identification to every transaction.
- EMV fleet card certification differs from consumer card EMV and requires controller-level support.
- Controller speed and accuracy affect fleet transaction throughput, compliance, and account retention.
Table of Contents
- What Makes Fleet Card Transactions Different from Consumer Cards at the Pump?
- How Does a Fleet Card Authorize at the Pump?
- What Is Level III Data and Why Do Fleet Cards Require It?
- How Does the Controller Enforce Product Code Restrictions?
- How Does Driver ID Verification Work at the Pump?
- How Do Fleet Card Networks Differ from Standard Payment Networks?
- What Is the Status of EMV for Fleet Cards at the Pump?
- Why Does Fleet Card Processing Matter for Travel Plaza Operators?
- Frequently Asked Questions About Fleet Card Processing at the Pump
What Makes Fleet Card Transactions Different from Consumer Cards at the Pump?
Fleet cards run on closed-loop networks separate from Visa and Mastercard, require driver ID verification, capture Level III line-item data, and enforce product restrictions at the controller level.
A consumer credit card transaction at the pump is straightforward: the card network validates the number, checks available credit, and approves or declines. Fleet cards add several layers on top of that. The forecourt controller must prompt for a driver ID or PIN, collect an odometer reading, check which fuel grades the card is authorized to purchase, and capture detailed line-item data about the transaction.
Fleet card purchases in the United States totaled $93.5 billion in 2023, equal to 10% of all B2B card spending. The forecourt controller sits between the outdoor card reader and the fleet card network, orchestrating the entire authorization. For a broader primer on what the controller does, see What Is a Forecourt Controller.
The major closed-loop fleet card programs include WEX, CFN (Commercial Fueling Network), Comdata, Fuelman, Pacific Pride, and EFS. These are not branded Visa or Mastercard products. They operate on their own proprietary networks with their own authorization protocols. OatFi's overview of open vs. closed-loop fleet card programs explains that distinction in detail.
How Does a Fleet Card Authorize at the Pump?
The forecourt controller receives card data from the outdoor reader, prompts for driver ID and odometer, packages the authorization request, routes it to the fleet network, and activates the correct dispenser grade upon approval.
Here is the step-by-step sequence that runs every time a fleet card is swiped or inserted at an outdoor card reader:
- The driver inserts or swipes the fleet card at the outdoor card reader.
- The card reader sends the card data to the forecourt controller.
- The controller identifies the card as a fleet program card (WEX, CFN, Comdata, etc.) and sends a prompt back to the card reader display asking for the driver's ID or PIN.
- The driver enters the assigned ID/PIN and current odometer reading on the card reader keypad.
- The controller packages the authorization request: card data, driver ID, odometer, product code restrictions, and site identification.
- The controller routes the request to the appropriate fleet card network, not to Visa or Mastercard.
- The fleet network validates the driver ID, checks account status, applies product restrictions (diesel only, no premium gasoline, gallon limits), and returns an authorization response.
- The authorization response arrives back at the controller with approved product codes and spending limits.
- The controller activates only the permitted dispenser grades based on the authorization.
- Fueling begins while the controller captures Level III data in real time: gallons dispensed, fuel grade, price per gallon, and taxes.
- The driver hangs up the nozzle or hits the preset limit. The controller sends the final transaction data to the fleet network.
On a well-configured site, that entire sequence completes in under 3 seconds. The controller is the system making every step happen, from the initial card read through the network call and back to the dispenser. A fleet-ready controller such as NeXGen PRIME is built to handle the reader, the network, and the dispenser without slowing the lane.
What Is Level III Data and Why Do Fleet Cards Require It?
Level III data is line-item transaction detail (fuel grade, gallons, price per gallon, odometer, taxes) that the forecourt controller captures and transmits with every fleet card transaction.
A consumer card transaction typically carries three data points: merchant category, transaction amount, and timestamp. Fleet card transactions capture all of that plus fuel grade, gallons dispensed, price per gallon, odometer reading, driver ID, vehicle number, site ID, tax breakdown, and product code. The controller reads the dispenser's pulse output for gallons, knows the programmed price per gallon, calculates taxes, and packages everything into the completion message.
Fleet managers rely on that data for four things:
- Expense allocation by vehicle, driver, and route
- IFTA fuel tax reporting, which requires gallons purchased by jurisdiction
- Fraud detection through odometer irregularities and unusual fueling patterns
- Driver accountability, tying every gallon to a specific person and vehicle
WEX's closed-loop network captures driver ID, job number, and odometer reading alongside the transaction record. The controller is doing the fieldwork here, not the card issuer. Without accurate Level III data from the controller, the fleet manager's reporting falls apart.
How Does the Controller Enforce Product Code Restrictions?
The forecourt controller reads the approved product codes from the fleet network's authorization response and activates only the permitted dispenser grades, blocking unauthorized fuel types at the hardware level.
Fleet card networks assign product code restrictions at the card or driver level. Common restrictions include:
- Diesel only (the most common for over-the-road fleets)
- Regular unleaded only (no premium gasoline)
- Fuel only (no car wash, no convenience store purchases at the pump)
- Gallon or dollar limits per transaction
When the authorization response comes back from the fleet network, it includes which product codes are permitted. The controller reads those codes and enables only the corresponding grades on the dispenser. If a driver authorized for diesel only tries to select premium gasoline, the controller blocks that grade. The pump will not activate it. This is hardware-level enforcement, not an honor system.
The card issuer or fleet manager sets the restriction policy. The controller enforces it. This is the sharpest line between what card issuers explain (the policy) and what only the controller manufacturer can explain (the enforcement mechanism at the pump).
How Does Driver ID Verification Work at the Pump?
The forecourt controller sends a driver ID prompt to the outdoor card reader display, collects the entered ID or PIN, and includes it in the authorization request sent to the fleet network for validation.
After the fleet card is read, the controller sends a message to the card reader's small screen: "Enter Driver ID" or "Enter PIN." The driver keys in the assigned number on the card reader keypad. At the same prompt, the controller also requests the current odometer reading. Both fields are packaged with the card data and sent to the fleet network.
The fleet network, not the controller, validates the driver ID against the account. If the ID does not match, the authorization is declined and fueling never starts. Even if someone steals a physical fleet card, they cannot fuel without the correct driver ID. This matters because fraud on magnetic stripe fleet cards climbed from $21.8 billion in 2015 to $31 billion in 2020, driven largely by card skimming and cloning.
Some fleet card programs are adding additional security layers. WEX, for example, supports two-factor authentication that sends a verification code when the driver is physically at the fuel station. The controller's role in all of this is managing the prompt sequence, collecting the input, and forwarding it to the network for validation.
How Do Fleet Card Networks Differ from Standard Payment Networks?
Fleet cards like WEX and Voyager operate on independent closed-loop networks that bypass Visa and Mastercard entirely, requiring separate merchant enrollment and dedicated network connections from the forecourt controller.
WEX, Voyager, CFN, and other fleet card brands run on proprietary network rails. A travel plaza enrolled to accept Visa and Mastercard is not automatically enrolled for WEX or CFN. Each fleet card network requires its own merchant enrollment, its own MCC (merchant category code) configuration, and its own network connection.
The forecourt controller maintains simultaneous connections to multiple fleet card networks. When a fleet card is swiped, the controller identifies which network the card belongs to based on the card's BIN (Bank Identification Number) and routes the authorization request to the correct destination. A single controller at a busy travel plaza might route transactions to WEX, CFN, Comdata, EFS, and Fuelman within the same hour.
WEX's proprietary network reaches roughly 95% of fuel stations and more than 45,000 service locations nationwide. For a controller platform designed to manage several of those fleet network connections simultaneously, see AEGIS. Revolution Payments' discussion of fleet card processing for WEX and Voyager merchants covers the enrollment and configuration requirements from the merchant side.
Incorrect MCC coding is one of the most common causes of fleet card authorization failures. If the merchant category code on the controller doesn't match what the fleet network expects, transactions will not route correctly and the card will be declined.
What Is the Status of EMV for Fleet Cards at the Pump?
Fleet card EMV adoption is underway but presents unique certification challenges; controllers must support both chip and magnetic stripe during the transition while maintaining fleet-specific data capture requirements.
The EMV liability shift for outdoor automated fueling dispensers took effect in April 2021 for Visa, Mastercard, Discover, and American Express. That date established the timeline for merchants to deploy EMV-capable outdoor payment terminals. However, fleet cards present complications that consumer cards do not.
Standard EMV chip configurations handle card authentication and transaction authorization. Fleet cards require additional data fields (driver ID, odometer, product code restrictions) that standard EMV kernels do not natively support. This means fleet EMV implementations need custom extensions beyond what consumer card EMV requires.
Merchants accepting EMV fleet cards must undergo Level 3 (L3) certification, which verifies that the POS and controller handle fleet-specific transaction data accurately and securely. Paragon Edge's explanation of EMV fleet card testing requirements covers the certification process in detail.
During the transition, controllers need to support both chip insertion and magnetic stripe swipe. Many fleet cards still rely on magnetic stripe, particularly in the over-the-road trucking segment. Contactless (tap-to-pay) fleet card authorization is starting to appear at outdoor terminals but is not yet standard. For controller EMV capability details, see Forecourt Control.
Why Does Fleet Card Processing Matter for Travel Plaza Operators?
Fleet fueling is the primary revenue stream for truck stops, and controller capability directly determines authorization speed, Level III data accuracy, and product restriction enforcement for every fleet transaction.
Fleet card transactions represent the majority of fuel volume at travel plazas and truck stops. A controller that cannot process fleet cards efficiently loses trucks to the next exit. At high-volume sites with 20 or more diesel lanes, even a 2-second delay per authorization compounds across hundreds of daily transactions.
The under-3-second authorization benchmark matters because drivers notice the difference. Slow fleet card authorizations stack up during peak hours, creating visible bottlenecks at the fuel island. Level III data errors create different problems downstream: reconciliation failures, incorrect IFTA filings, and fleet manager complaints that can cost a site its fleet accounts.
Allied Electronics' NeXGen PRIME and AEGIS forecourt controllers handle fleet card authorization at virtually every truck stop and travel plaza in North America. Both support WEX, CFN, Comdata, and other major fleet card networks, with EMV certification across major dispenser brands and card processors. For a broader look at how these controllers fit into travel plaza operations, see Travel Plaza Fuel Management.
Frequently Asked Questions About Fleet Card Processing at the Pump
Fleet card processing at the pump raises practical questions for operators, fleet managers, and IT staff. These are the most common.
Ready to Talk Fleet Card Processing?
Allied's controllers handle fleet card authorization at virtually every truck stop in North America. Talk to a specialist about your site.
Talk to a Specialist →