Back to Wallets & Transactions

How do I see charge key authorizations in Hub?

Where to find charge key authorizations in Hub — per key, per charge point, and across your account — what each attempt means, who can see what, and how to filter and export.

Help Center / Monta Hub / Payments & Transactions / Wallets & Transactions / How do I see charge key authorizations in Hub?

Where to find charge key authorizations in Hub — per key, per charge point, and across your account — what each attempt means, who can see what, and how to filter and export.

How do I see charge key authorizations in Monta Hub?

For: Charge point operators and operator admins using Monta Hub.

Every time a driver taps a charge key, Monta has to decide whether that key is allowed to charge. Authorizations is the record of those decisions — every attempt, successful or not, with the reason behind it. It answers the question that used to require a support ticket: why did this key (not) charge?

An authorization is recorded whether the attempt succeeded or failed, whether the key is yours or a visiting driver's, and whether the tap happened on your own charge points or on a roaming partner's network.

A charge key is also known as a radio-frequency identification (RFID) card, RFID tag, charge card, key fob, or token — they all refer to the same thing.

Where do I find authorizations?

There are four places to look. Two show the whole picture across your account; two zoom in on a single key or a single charge point.

Across all your keys — every attempt made with the keys you issue, on your own hardware and while roaming out:

  1. Open Charge keys (EMP / Fleet).
  2. Open the Authorizations tab, beside Keys.
Charge keys → Authorizations — every attempt by the keys you issue

Across all your stations — every attempt on your charge points, including keys you don't manage:

  1. Open Network.
  2. Open the Charge key authorizations tab.
Network → Charge key authorizations — every attempt on your stations

One charge key — everything a single key has tried:

  1. Open Accounts → [account] → Charge keys.
  2. Select the charge key.
  3. Open the Authorizations tab, beside Sessions.
A single charge key's Authorizations tab

One charge point — everything tried at a single station, by any key:

  1. Open EVSE → [charge point].
  2. Open the Integration tab.
  3. Select the Authorizations sub-tab.
A single charge point's Authorizations sub-tab

The two account-wide tabs are for operator admins (see What can I see, and what is hidden?). The single-key and single-charge-point views are available to standard roles too.

What does each row show?

Every view shares the same first three and last columns. The middle columns vary by view — each view drops the column for the thing you are already looking at (a single key's view has no Charge key column; a single charge point's has no Where column):

Column Shown on What it means
When All When the key was presented.
Result All Allowed, Denied, or Error.
Reason All A plain-language explanation. Hover it for the longer description.
Where All except One charge point The charge point the key was presented at, or Roaming — [partner] for an attempt on a partner network.
EVSE network Key views The operator that owns that charge point, or the roaming partner it was reached through.
Charge key All except One charge key The key that was presented — its name if you manage it, otherwise the key identifier.
Charge key network Station views Where the key came from: the issuing operator, the roaming partner, or Unknown if the card can't be attributed.
Charge session All The charge that started, on a successful attempt. Declined and errored attempts have none.

Result tells you what happened; Reason tells you why:

  • Allowed — the key was approved to charge. This does not always mean a charge started, and it does not always mean Monta made the decision. See What does an approved authorization tell me? below.
  • Denied — the key was recognised but not permitted to charge. This is the normal, expected outcome for a blocked key, an empty wallet, a private station, and so on.
  • Error — something failed on our side before a decision could be reached. Error is deliberately shown in a different colour from Denied, so you can tell a genuine "no" from a system fault at a glance.

How do I filter, search, and export?

The toolbar above every table gives you:

  • Search — search by charge session, token, key, EVSE, or location.
  • Filter — filter by Result, whether it resulted in a charge, Reason, Channel, Source, Authorized by, Network, and a date range. The key views add a Direction filter. The same filters are available on every view, from a single key or charge point up to the account-wide tabs.
  • Columns — show or hide columns.
  • Refresh — reload the list.
  • Export — the download icon saves the rows currently shown as a comma-separated values (CSV) file, using the friendly reason label you see on screen rather than the internal code. It captures the current page, so for a complete extract of all your authorization data use Data exports (see Export the data below).

The table shows 50 rows per page by default. A filter selection is saved in the page address, so you can bookmark a view or paste the link into a ticket.

See it at a glance — Studio dashboards

If you'd rather not read the raw list, two curated Studio dashboards summarise the same data. Find them under Studio → Dashboards (they carry an Early access badge):

  • Charge key authorizations — My keys: total attempts, allowed share, the allowed-vs-denied trend, your top denial reasons, the split between your own hardware and roaming out, and the networks your keys charge on.
  • Charge key authorizations — My network: attempts on your EVSEs, the denial-reason mix, known vs unknown keys, your busiest charge points, and the networks charging on your infrastructure.

The dashboards are read-only. Clone one into a personal copy if you want to customise its widgets or filters.

Studio dashboard — My keys Studio dashboard — My network

Export the data

Beyond the CSV download on each table, the same authorization data is available as two datasets in Data exports (Analytics → Data exports):

  • Charge Key Authorizations (My Keys) — attempts made with the keys you issued, wherever they were used.
  • Charge Key Authorizations (My Network) — every attempt on your EVSEs, including keys you don't manage.

Choose your columns, add filters, preview the result, and download it as CSV. Exporting is an admin-level action (see What can I see, and what is hidden?).

Building a charge-key authorization export in Data exports

How do I open a single attempt?

Select any row to open its own authorization page. The page is a normal link — you can copy it from the address bar and share it with a colleague or paste it into a support ticket.

The page is grouped into four sections:

  • Outcome — Result, Reason, When, and Recorded. Recorded is when Monta captured the record. It is normally within a second or two of When, including for attempts the charge point decided locally. Roaming attempts reconciled from a partner's session records are the exception and can be recorded hours later. An Attempts field appears only when more than one identical failed tap was collapsed into the row.
  • Charge key — the key that was presented (linked to its detail page when you manage it), the Presented key identifier, and the Charge key network it came from.
  • EVSE — the charge point, its Location, the EVSE network, and the resulting Charge session.
  • Technical detailsChannel, Direction, Source, Authorized by, Raw reason code, Request ID, Session reference, Partner country, and Partner party ID. A Message field appears when the system recorded one. Every field has an information icon that explains what it is. Use these when raising a case with Monta support or with a roaming partner.

Fields that don't apply to an attempt show a dash. A plain charge on your own hardware has no partner country or party ID, for example.

A single authorization's detail page

What does an approved authorization tell me?

An Allowed result means the key passed the checks and was approved to charge. It does not, by itself, mean a charge ran — and it does not always mean Monta made the decision.

Who decided?

The Authorized by field under Technical details names the part of the system that resolved the attempt. Despite the name, it covers declines as well as approvals — some values only ever appear on a decline. It is worth checking, because not every decision is made by Monta.

Authorized by What it means
auth_token The key was recognised as a Monta charge key and checked against the platform. This is the standard path, and the only one that regularly both approves and declines.
(blank) Nothing recognised the key. Always paired with Key not found.
ocpi The attempt was resolved by the roaming partner that issued the key, over OCPI.
hubject The attempt was resolved by the roaming partner that issued the key, through Hubject.
private_ocpi The attempt was resolved by a roaming partner over a private OCPI connection (a direct peering, rather than the open roaming hub).
local_auth_list The charge point approved the key from the local authorization list it holds, without asking Monta.
authorization_cache The charge point approved the key from its own cache of recently accepted keys, without asking Monta.
edge_cache The charge point approved the key from a cached decision held on the device.
local_terminal A payment terminal at the site approved the session.
vehicle_vid The vehicle identified itself instead of a card being presented. Approves and declines.
plug_and_charge The vehicle authorised itself with Plug & Charge (ISO 15118) — no card was presented.
auth_token_scan The tap was a key-pairing scan, not a charge attempt.
trust_level An anti-fraud trust-level check resolved the attempt.
active_cp Declined because the charge point is not active.
maintenance Declined because the charge point is in maintenance.
peak_hour Declined by a peak-hour restriction.
internal_error The attempt failed inside Monta before any decision could be made.

These values are shown exactly as written above.

A blank Authorized by is not a fault. It means no part of the system recognised the key at all, which is why the attempt was declined as Key not found. On a public charge point this is normal and usually means an unknown visitor's card.

The three local routes matter for control. When local_auth_list, authorization_cache, or edge_cache resolved the attempt, the charge point decided on its own and did not check with Monta at that moment. A block you had just applied, or a usage limit the key had already reached, may not have been in force for that specific tap — even though the charge point reports the decision to us straight afterwards. If you have just blocked a key, treat locally-approved charges in the period that follows as expected behaviour rather than as the block failing.

Why does an approved attempt sometimes have no charge session?

An Allowed row with a dash in the Charge session column is common and usually not a fault. The most likely explanations, in order:

  • The driver never started charging. The key was approved at the reader, but the cable was never plugged in, or the driver walked away. The approval is genuine; there was simply nothing to charge.
  • The charger never started the session. The key was approved but the charge point failed to begin the transaction — a cable, connector, or station fault.
  • The link is still being made. Monta attaches the charge to its approval just after the charge is created, retrying for about a minute and a half. Refresh the page.
  • The charge is on a roaming network. For attempts where your key charged on a partner's network, the session is attached only when the partner sends us its record. That typically takes an hour or two, and can take considerably longer. These rows are the main reason Recorded can sit well after When.
  • The approval could not be matched to the charge. Monta links a charge to its approval by matching the same key, at the same charge point, in the hour before the charge started. When two approvals from the same key at the same station fall close together, the newest one is linked and the earlier one keeps its dash — even though a charge did run.

To tell a genuine no-show from a linking gap, open the charge point's Charge sessions tab for the same period. If a session exists there but the authorization shows a dash, it is a linking gap and the charge is unaffected. If no session exists, the charge really never started.

A run of Allowed attempts with no charge session at one charge point is worth investigating. It usually means drivers are tapping successfully and then failing to get power — a station problem that costs you utilisation and shows up nowhere else.

What can I see, and what is hidden?

Two things decide what appears for you: your role on the operator (which views you can open), and ownership (how much detail each row shows).

Who can open which view

What you want to see Standard role (manager, bookkeeper, supporter) Operator admin
One charge key's authorizations Yes Yes
One charge point's authorizations Yes — foreign keys masked (see below) Yes — all keys shown in full
Across all keys (account-wide tab) Yes
Across all stations (account-wide tab) Yes
Export a view to CSV Yes

Access is a permission, not a fixed role — an operator admin can grant the account-wide view or export to another role, or withhold the authorization data from a role that otherwise sees the account. The account-wide tabs cover the accounts your current view includes: your main account and, if you are a holding account, its sub-accounts.

How much detail each row shows

Authorizations sit between two parties: the operator who issued the key and the operator who owns the charge point. A single attempt is often visible to both, and each sees a different amount of detail. Monta decides this when it serves the data — you never have to configure it.

  • You issued the key. You see the key's name, the full identifier, and the exact reason — including private ones such as Not enough funds.
  • You own the charge point but not the key. You see that an attempt happened, when, at which charge point, the result, and the key's network of origin. The identifier is masked to its last four characters (for example, ••••7C3A), and reasons that belong to the driver's own account or home network are generalised to Declined without the underlying detail.
  • You own both the key and the charge point. You see everything.

This is why, on your charge point view, your own keys appear by name (Fleet key — Bay crew) while a visiting driver's key appears as ••••51A9 from IONITY (DE\ION) with the reason Declined*. The driver's wallet balance and account limits are their home operator's business, not yours. If a visiting driver reports a problem, point them at the operator that issued their key.

What do the reasons mean?

Reason What it means Typical fix
Allowed The key was authorized and a charge started.
Key not found The charge key wasn't recognised. Depends on the view — see below.
Key blocked The key has been blocked and can't start charges. Find out why it was blocked before unblocking it. See Before you raise a limit below.
Roaming disabled Roaming is turned off for this key. Roaming is often turned off deliberately to limit cost and exposure. If the key should roam, enable Roaming network on it.
Not authorized The key isn't authorized to charge here. Check the key's wallet payment restrictions and the station's access settings. Confirm the key should have access before widening them.
Not enough funds The wallet doesn't have enough funds. Ask the driver to top up, or top up the account wallet.
No payment method The key has no valid payment method. Add a payment method to the wallet the key is connected to.
Payment not allowed Payment isn't permitted for this key at this charge point. Check the key's wallet payment restrictions (allowed countries and operators). A decline in an unexpected country is worth investigating before you widen them.
Daily limit reached The key hit its rolling 24-hour charge count limit. Check the recent attempts before raising the limit. See Before you raise a limit below.
Spend limit reached The key hit its rolling 30-day spend limit. Check the recent attempts before raising the limit. See Before you raise a limit below.
Too many active charges The key hit its concurrent-charges limit. Check where the overlapping sessions are before raising the limit. See Before you raise a limit below.
Charge key limit reached The key hit one of its usage limits. Review the key's Usage limits, and the recent attempts, before changing anything.
Limit check failed A usage-limit check couldn't be completed. Retry. Contact support if it repeats.
Station not recognised The charge point couldn't be identified. Contact support — the station may not be correctly registered.
Station inactive The charge point isn't active. Activate the charge point.
Station is private The charge point isn't available to this key. Adjust the station's access settings, or use a key that has access.
Station unavailable The charge point isn't in a state that allows charging right now. Check the charge point's status — it may be offline, faulted, or occupied.
Station reserved The charge point is reserved. Wait for the reservation to end.
Station not ready for roaming The charge point isn't set up for roaming charges. Enable roaming on the charge point.
Location mismatch The charge point didn't match the expected location. Contact support.
Peak-hour restriction Charging is restricted at this charge point during peak hours. Expected — charging is allowed outside the restricted window.
Smart queue restriction Charging is being managed by the smart queue. Expected — the session starts when the queue allows it.
Roaming operator missing The roaming operator couldn't be resolved. Contact support.
Couldn't start charge The key was authorized but the charge couldn't be created. Retry. Contact support if it repeats.
Internal error Something went wrong on our side. Retry, then contact support with the Request id.
Couldn't handle request We couldn't process the authorization request. Retry, then contact support with the Request id.
Declined Declined on the driver or home-network side. The driver should contact the operator that issued their key.
Unknown The reason couldn't be classified. Contact support with the Request id.

A note on "Key not found"

Key not found is by far the most common decline, and it belongs almost entirely to the charge point view.

On the charge point view, it means an unrecognised card was presented at your station: a visitor whose key Monta doesn't know, a card from a network you don't have roaming with, or a hotel or office card that isn't a charge key at all. These attempts are expected on any publicly accessible charge point and there is usually nothing to fix.

Because no key was identified, Monta cannot tell which network the card belongs to either — so Charge key network reads Unknown on these rows. That is the expected result, not missing information.

On the charge key view, Key not found is rare. An attempt has to be matched to one of your keys before it can appear under that key at all, and by definition these attempts matched nothing. When one does appear, there are two explanations:

  • The key is known to Monta, but was not found at the moment the decision was made.
  • The attempt was made on a roaming network, and the partner did not recognise your key. This is usually propagation rather than a fault: Monta shares new keys with roaming partners immediately, but each partner updates its own systems on its own schedule — often within a day, and with some networks up to a month.

There is one pattern worth a second look: a burst of Key not found attempts at a single charge point in a short window, especially outside normal hours. One driver tapping the wrong card a few times looks nothing like a run of different unrecognised cards at one station.

Before you raise a limit

Usage limits, wallet payment restrictions, the roaming toggle, and the blocked status are deliberate controls over spending and access. When one of them declines a key, the system is doing exactly what you set it up to do. Raising the limit makes the decline go away — it does not tell you whether the attempt was legitimate.

A key that suddenly starts hitting its limits can mean the limit is simply too tight for how the driver works. It can also mean the key has been lost, copied, or shared. Use the Authorizations list to tell the two apart before you change anything:

  • Where were the attempts? Charge points far from where this driver normally charges — or in another country — deserve a second look.
  • When did they happen? A run of attempts overnight, or outside working hours for a fleet key, is worth questioning.
  • How many, and how quickly? A burst of declines within minutes reads very differently from one decline a week.
  • Do the sessions overlap? Too many active charges means the key tried to run sessions at the same time. If those sessions are at different sites, one physical card cannot be in both places — that points to a copied or shared key.

If the pattern looks wrong, block the key instead of raising the limit. Select Block charge key on the key's page, then speak to the driver. You can unblock it afterwards.

The same care applies in reverse: if a key is already blocked, find out why before you unblock it. Someone blocked it for a reason, and the authorization history usually shows what that reason was.

Common questions

Why do I see attempts at a charge point I don't own?

On the key views, you see everywhere your key was used — including roaming partner networks. Those rows show Roaming — [partner] under Where.

Why do I see keys I don't manage?

On the station views, you see every key presented at your station, including visiting drivers' keys. That is the point of the view: it shows demand and failures on your infrastructure, not just your own drivers.

Who can see the account-wide tabs?

The Across all keys and Across all stations tabs, and CSV export, are admin-level. Standard roles can still open a single key's or a single charge point's authorizations. See What can I see, and what is hidden?

Why is the same failure only one row?

Repeated identical failed taps are grouped into a single record. The Attempts field on the detail page shows how many taps it represents.

Why is an approved attempt missing its charge session?

Most often because the driver was approved but never actually started charging. See What does an approved authorization tell me? for the full list of causes and how to tell them apart.

Does an approved authorization mean the charge point checked with Monta?

Not always. Check Authorized by on the detail page — charge points can approve a key from a local list or cache without contacting us.

A key is hitting its limits constantly — should I just raise them?

Not before you look at the attempts. Repeated limit declines are as likely to be a lost, copied, or shared key as a limit set too tight. See Before you raise a limit.

Why did an attempt appear late?

Offline authorizations, roaming attempts, and attempts reconciled from a partner's session records are learned about after they happen. Compare When with Recorded on the detail page.

Related: How do I add and edit charge keys in Monta Hub? · How do I fix issues with charge keys?