On This Page
Recent Revisions to This Document
26.09.01
- PrestaShop
- Updated the PrestaShop plugin. See PrestaShop.
- OpenCart
- Updated the OpenCart plugin. See OpenCart.
- Oracle NetSuite
- Updated the Oracle NetSuite SuiteApp. See Oracle NetSuite.
26.07.01
- Adobe Commerce
- Updated the Adobe Commerce plugin. See Adobe Commerce REST API.
- PrestaShop
- Updated the PrestaShop plugin. See PrestaShop.
- OpenCart
- Updated the OpenCart plugin. See OpenCart.
- Oracle NetSuite
- Added a module for Oracle NetSuite to this guide. See Oracle NetSuite.
- Salesforce B2C Commerce REST
- Updated the Salesforce B2C Commerce REST plugin. See Salesforce B2C Commerce.
- WooCommerce
- Updated the WooCommerce plugin. See WooCommerce.
26.02.02
- New Adobe Commerce Open Source Plugin
- A new Adobe Commerce Open Source plugin was added to augment the existing Adobe Commerce Cloud plugin. See Adobe Commerce REST API.
- GitHub link
- Added a link to ISV Toolkits available at GitHub. See About the Integrated Solutions.
- Adobe Commerce Cloud
- Updated the section on configuring web services to refer to a change in the procedure where SOAP p12 certificates are uploaded to a section now called Simple Order P12 Key File. See Configure WebService.
- Updated the section on creating a SOAP security key to refer to the SOAP P12 certificate. See Configure Security Credentials.
- PrestaShop
- Revised the PrestaShop section. See PrestaShop.
- Shopify
- Added note to the configuring section to ensure that the Test mode is used when testing. See Configure the Shopify Extension.
- The testing section was revised to describe how to install and use a new test app. For more information, see Reference Information.
- WooCommerce
- Updated the WooCommerce plugin. For more information, see WooCommerce.
25.12.01
- Oracle NetSuite
- Removed Oracle NetSuite module from guide.
25.10.01
- Shopify
- Added note that when using the test server, ensure that the Test Mode option is enabled. See Configuring Shopify.
- WooCommerce
- Added note to the troubleshooting section to check with support services for configuration guidance when your account is managed by a merchant services provider. See Support and Troubleshooting.
25.09.02
- PrestaShop
- This revision contains only editorial changes and no technical updates.
- Shopify
- The app now supports Shopify subscriptions.
- Clarified that during installation, you use the transacting merchant ID as your credentials. See Installing the Live App.
25.09.01
This revision contains only editorial changes and no technical updates.
25.08.01
- WooCommerce
- Updated all information in this section. See WooCommerce.
Visa Platform Connect: Specifications and Conditions for
Resellers/Partners
The following are specifications and conditions that apply to a Reseller/Partner enabling
its merchants through
Cybersource for
. Failure to meet any of the specifications and conditions below is
subject to the liability provisions and indemnification obligations under
Reseller/Partner’s contract with Visa/Cybersource.Visa Platform Connect
(“VPC”)
processing- Before boarding merchants for payment processing on a VPC acquirer’s connection, Reseller/Partner and the VPC acquirer must have a contract or other legal agreement that permits Reseller/Partner to enable its merchants to process payments with the acquirer through the dedicated VPC connection and/or traditional connection with such VPC acquirer.
- Reseller/Partner is responsible for boarding and enabling its merchants in accordance with the terms of the contract or other legal agreement with the relevant VPC acquirer.
- Reseller/Partner acknowledges and agrees that all considerations and fees associated with chargebacks, interchange downgrades, settlement issues, funding delays, and other processing related activities are strictly between Reseller and the relevant VPC acquirer.
- Reseller/Partner acknowledges and agrees that the relevant VPC acquirer is responsible for payment processing issues, including but not limited to, transaction declines by network/issuer, decline rates, and interchange qualification, as may be agreed to or outlined in the contract or other legal agreement between Reseller/Partner and such VPC acquirer.
DISCLAIMER: NEITHER VISA NOR CYBERSOURCE WILL BE RESPONSIBLE OR LIABLE FOR ANY ERRORS OR
OMISSIONS BY THE
Visa Platform Connect
ACQUIRER IN PROCESSING TRANSACTIONS. NEITHER VISA
NOR CYBERSOURCE WILL BE RESPONSIBLE OR LIABLE FOR RESELLER/PARTNER BOARDING MERCHANTS OR
ENABLING MERCHANT PROCESSING IN VIOLATION OF THE TERMS AND CONDITIONS IMPOSED BY THE
RELEVANT Visa Platform Connect
ACQUIRER. About the Integrated Solutions
Overview of the integrated solutions available for connecting third-party e-commerce platforms to the
Cybersource
platform.Cybersource
offers integrated solutions to enhance payment acceptance,
fraud management, recurring billing, reconciliation, and reporting processes. Our
integrated solutions provide use cases for product managers, developers, and business
professionals. Reduce your operational costs through streamlined
payment integrations and improve customer satisfaction through flexible and secure
payment options. Our solutions can easily scale to your growing business needs, help
increase sales and conversion rates, and provide a clear value proposition to
distinguish your business from competitors.The solutions detailed in this document are:
For information on how to become a partner, see the
Partner Getting Started
guide. See
these additional resources for more information about the ISV Plugins documented in this
guide:
Toolkits for integrating our ISV plug-ins are available at our
repositories on GitHub.
Built by Us
Welcome to our suite of integrated solutions. These solutions improve
operational efficiency, enhance security, and provide comprehensive reporting and
invoicing. Reduce the risk of errors, protect against fraudulent transactions, and
ensure accurate financial records through streamlined reconciliation processes. Our
solutions are ideal for various industries including financial services, healthcare,
manufacturing, and distribution. For example, in healthcare, our solutions can manage
payment operations efficiently, ensuring secure and accurate processing of payments for
services rendered, and support timely invoicing actions.
These guides are created by
Cybersource
:Adobe Commerce REST API
The Visa Acceptance Solutions extension for
Adobe Commerce
/Magento
Open Source enables merchants to connect their Adobe Commerce
/Magento Open Source store to the Visa Acceptance Platform to directly take credit and
debit cards, Apple Pay, Google Pay, and Click to Pay payments.For simplicity in this document, any reference to
Adobe Commerce
will
apply for Magento Open Source also, unless otherwise stated.Supported Features
The Visa Acceptance Solutions extension supports various payment methods and security features.
Payment Methods
- Credit/debit cards
- Apple Pay
- Google Pay
- Click to Pay
Security Features
- Payer Authentication/3-D Secure
- Tokenization
Supported Versions
The
Adobe Commerce
extension has these system requirements:- Adobe Commerce2.4.5+
- PHP 8.1+
Unsupported Adobe Commerce Features
Adobe Commerce
FeaturesThese features are not supported by this extension:
- Order void
- Multi-shipping
- Multiple node implementation
- Google reCAPTCHA
Visa Acceptance Solutions Prerequisites
Mandatory Prerequisites
This Visa Acceptance Solutions product must be configured for your Merchant ID:
- Unified Checkout
You also must have a REST Shared Secret Key. See the Getting Started with REST Developer guide
for information on how to get a REST Shared Secret Key.
Optional Prerequisites
These Visa Acceptance Solutions products are optional. If you want these products you
must enable and configure your Merchant ID with them.
- Payer Authenticationfor3-D Secure
- Tokenization
- Apple Pay
- Google Pay
- Click to Pay
You can also enable Message-Level Encryption (MLE) for additional security. A REST Certificate is required for MLE.
Release Notes
Version history and changes for the Visa Acceptance Solutions extension for
Adobe Commerce
.Version 25.2.0 January 2026
These enhancements were added with this release:
- Request Message Level Encryption
- API endpoint updates
- Support for Jaywan card
- Implemented Sub Resource Integrity (SRI)
- UpdatedUnified Checkoutto version 0.33
These bugs were addressed in this release:
- Corrected the country field source in theUnified Checkoutcapture context.
- CSP violation
This release is compatible with:
- Adobe Commerce2.4.5+
- PHP 8.1+
Version 25.1.0 May 2025
Initial release that supports:
- Unified Checkout
- Apple Pay
- Google Pay
- Click to Pay
- TMS
- Payer Authentication
This release is compatible with:
- Adobe Commerce2.4.5+
- PHP 8.1+
Installation
Follow these steps to install the Visa Acceptance Solutions extension for
Adobe Commerce
. Before starting the installation, ensure you have
Adobe Commerce
authentication keys and that they are set
correctly in your environment. See Authentication Keys for details.Go to the
Adobe Commerce
Marketplace and get the free extension.Choose the appropriate installation method based on your environment:
- Adobe Commerce Cloud: For cloud-based installations, go to the Adobe Commerce Cloud.
- Adobe CommerceOn-Premise / Magento Open Source: For self-hosted installations, go to Adobe Commerce On-Premise.
Adobe Commerce Cloud
Adobe Commerce Cloud
Follow these steps to install in
Adobe Commerce Cloud
environments.- Run this command in your local Cloud project directory:composer require Cybersource/module-payment:25.2.0
- After Composer finishes, commit the updated files using these commands:git add composer.json composer.lock git commit -m "Add Cybersource Payment module" git push
- Enable the module with this command:php bin/magento app:config:dump
- After enabling the module, commit the updated configuration file with these commands:git add app/etc/config.php git commit -m "Enable Cybersource> Payment module" git push
Adobe Commerce On-Premise / Magento Open Source
Adobe Commerce
On-Premise / Magento Open SourceTo install the module using Composer, run these commands in your
Adobe Commerce
On-Premise and Magento Open Source environments.php bin/magento module:enable Cybersource_Payment php bin/magento setup:di:compile php bin/magento indexer:reindex php bin/magento setup:upgrade php bin/magento setup:static-content:deploy -f php bin/magento cache:clean php bin/magento cache:flush php bin/magento module:status
Configuration
To configure the Visa Acceptance Solutions extension, go to . Configure these fields:
Configure General settings
: - Environment:
- Test: Choose for testing of yourCybersourcetest account.
- Production: Choose for live transactions.
- Merchant ID: Enter the transacting Merchant ID (MID) assigned to you by Visa Acceptance Solutions.
- API Key: Enter the Key from your REST API Shared Secret Key.
- API Shared Secret Key: Enter the Shared Secret from your REST API Shared Secret Key.
- Accepted Card Types: Choose the card brands you want to accept.
Configure Debug Mode
: - Yes: Compiles detailed logs for every transaction. This option is only recommended for the Test Environment or when troubleshooting issues in Production.
- No: Only basic logging occurs.
Configure Message Level Encryption
:
Enabled
- Yes: Encrypts the full request message using JSON Web Tokens before being transmitted to the Visa Acceptance Platform.
- No: Uses the HTTP Signature.
JSON Web Tokens use a digital certificate to prove who you are, while HTTP
Signature uses a shared secret key to confirm the message is genuine. Both methods
are PCI compliant.
- Certificate File: Upload the p12 certificate for yourCybersourceMerchant ID.
- Key Password: Enter the password that was used when you created your p12 certificate.
Configure Secure Payment Methods
: - Enable: ChooseYesto enable the extension.
- Title: Enter the label your customers see on the checkout page.
- Payment Action: Choose one of these options:
- Authorize and Capture: Captures the transaction automatically when the authorization is approved.
- Authorize only: Sends an authorization request and if approved, you must manually request a capture.
- Payment Card Types: Choose the card brands you want to offer to your customers.
- Allowed Payment Methods: Choose the payment methods you want to offer to your customers. These payment card types must be enabled for your MID in theBusiness Center. See here for details.
- Select Layout:
- Embedded: The payment widget appears inline on the checkout page.
- Sidebar: The payment widget appears on the right side on the checkout page.
- Payment from Applicable Countries:
- All Allowed: Uses theAdobe Commerceglobal settings to determine which countries are available.
- Specific Countries: Specify which countries you want to accept payments from.
- : ChoosePayer Authentication/3-D SecureYesto enable3-D Secure.
- Tokenization: ChooseYesto enable your customers to save their payment cards for future purchases.
- Tokenization Title: Enter the label you want your customers to see when they pay with a saved card.
- Saved Card Verification: ChooseYesto request that your customer enter their card security code when paying with a saved card.
- Enforce Strong Customer Authentication: ChooseYesto enforce a3-D Securechallenge when a customer saves their card for the first time.
Order Management
The Visa Acceptance Solutions extension provides comprehensive order management
capabilities for handling transactions after they are processed. This includes capturing
authorized payments and processing refunds when necessary.
The order management features enable you to:
- Capture authorized transactions to collect funds.
- Process full or partial refunds for completed transactions.
- Manage the payment lifecycle from authorization to settlement.
Capture
When you have the
Payment Action
set to
Authorization
, you must capture the transaction to collect the
funds.- Enter an order from the list of orders.
- ClickInvoice.
- Check the item(s) that require capturing.
- Ensure the drop-down capture option is set toCapture Online.
- ClickSubmit Invoice.
Refund
To refund an order:
- From the list of orders, choose the order you want.
- Click onInvoices.
- Select the appropriate invoice.
- Click theCredit Memobutton.
- Check the item(s) to be refunded.
- Verify and if necessary update theRefund Totals.
- ClickRefund.
Support & Troubleshooting
Get support for the Visa Acceptance Solutions extension by providing detailed information about your issue.
If you require support with this extension, sign into the Support Center to raise a case,
providing these details:
- Summary of the issue
- Steps needed to reproduce the issue
- Platform version
- Extension version
- CybersourceMerchant ID
- Configuration screenshots
- List of themes/additional extensions installed
- Log file and any other data or screenshots related to the issue
Upgrade
To upgrade from an earlier version of our
Adobe Commerce
extension, run these composer commands- Update the extension to the latest version:composer requireCybersource/module-payment:25.2.0
- Run the setup upgrade command:bin/magento setup:upgrade --keep-generated
- Deploy static content:bin/magento setup:static-content:deploy
- Clean the cache:bin/magento cache:clean
Adobe Commerce
Adobe Commerce
You can integrate
Cybersource
with the Adobe Commerce
platform to process payments using Magento checkout. The Adobe Commerce
extension supports popular payment methods, safeguards
payment data, minimizes fraud, and mitigates risks. This section describes the payment
management capabilities offered by Cybersource
through the Adobe Commerce
integration.This guide also applies to installing this extension in a Magento Open Source
environment.
Fraud Management
Fraud Management prevents fraud losses and gives you the flexibility to control
business practices and policies in real time. Fraud Management can help you
accurately identify and review potentially risky transactions while minimizing the
rejection of valid orders. Fraud Management comprises these capabilities:
- Real-time fraud screening performed only during authorization
- Device fingerprinting
- On-demand Conversion Detail Report for changes in order status
Account Takeover Protection
Account Takeover Protection defends customers and merchants from fraudulent use of
online accounts. It monitors suspicious account changes and helps identify high risk
users at account creation and login. These capabilities comprise Account Takeover
Protection:
- Real-time event screening of account creation, login, and changes
- Device fingerprinting
Payer Authentication
Payer Authentication enables you to add support to your web store for card
authentication services offered by Visa
, Mastercard,
and other card brands. These
programs verify the cardholder’s identity directly with the card-issuing bank in
real time to increase payment security and reduce the risk of fraud. However, Payer
Authentication is not a fraud management service, and Cybersource
recommends that you configure a comprehensive fraud management program such as
Decision Manager
in addition to Payer Authentication services. These services
comprise Payer Authentication:- Verified by Visa
- Mastercard Identity Check
- American Express SafeKey
- Discover ProtectBuy
- JCB
- Diners
- Maestro International
To comply with the recent mandates for French local processors that support Payer
Authentication, CMCIC, Atos and BNP processors no longer support these
combinations.
PayPal
The
Adobe Commerce Cloud
integration includes the PayPal payment
method. Processing your PayPal transactions through Cybersource
enables you to consolidate all payment types under a single gateway account,
simplify integration efforts, screen PayPal transactions for fraud with Decision
Manager, and streamline reporting. These services comprise PayPal:- Sessions
- Check Status
- Order
- Authorization
- Authorization Reversal
- Capture
- Sale
- Refund
- PayPal Credit
- Billing Agreements
PayPal Credit
PayPal Credit is a payment method that allows merchants to accept a PayPal
transaction when the customer chooses to finance their purchase through PayPal.
Electronic Check (eCheck Service)
eCheck
Service)The
eCheck
Service is a form of digital payment that serves the same
function as a physical check. When a merchant accepts an electronic check payment,
the funds are pulled directly from the customer’s checking or savings account. The
eCheck
service includes both debit and credit services.eCheck
Service process refunds with the credit payment
service.Online Bank Transfers
Online banking services enable customers to pay for goods by sending money from their
bank account to the merchant.
The
Adobe Commerce Cloud
extension supports the following payment
methods and corresponding online bank transfer services:- Bancontact
- Sale
- Check Status
- Refund
- Country: Belgium
- iDEAL
- Options
- Sale
- Check Status
- Refund
- Country: Netherlands
Tax Calculation
The Tax Calculation service provides real-time tax calculation during order checkout
for orders placed worldwide with your business.
Delivery Address Verification
The Delivery Address Verification service verifies the entered address and suggests
the recommended address for city, state, and zip code combinations in real time.
If this feature is enabled in the
Adobe Commerce Cloud
console, the
Adobe Commerce Cloud
extension verifies the delivery address on
shipping information updated by the user.Klarna
Klarna credit provides a seamless user experience for online customer financing to
merchants of all sizes, which helps in increasing customer choice, loyalty and
growth in sales.
Google Pay
Google Pay is a digital wallet that enables customers to pay with any payment method
saved to their Google account.
Release Notes
This section provides information about functionality, bug fixes, and enhancements for
the
Adobe Commerce Cloud
Cybersource
integration.January 2026
- Adobe Commerce CloudCybersourceVersion 3.5.11 is compatible withAdobe Commerce Cloud: 2.4.8-p3, 2.4.8-p2, 2.4.8-p1, 2.4.8, 2.4.7-p8, 2.4.6-p13 and PHP 8.4, 8.3, 8.2
- Implemented Request Message Level Encryption
- Implemented Google Pay Payer Authentication
- Fixed Anonymous Script Load Error (Integrity and Cross Origin)
- UpdatedauthenticationStatusflag for Payer Authentication in Google Pay
August 2025
- Adobe Commerce CloudCybersourceVersion 3.5.10 is compatible withAdobe Commerce Cloud: 2.4.8-p1, 2.4.8, 2.4.7-p6, 2.4.6-p11,2.4.5-p13 and PHP 8.4, 8.3, 8.2, 8.1
- Extended support forAdobe Commerce Cloudv2.4.8.
- Changed path for certificate folder from root to var directory.
- Updated the certificate folder name to certificates.
April 2025
- Adobe Commerce CloudCybersourceVersion 3.5.9 is compatible withAdobe Commerce Cloud: 2.4.7-p4, 2.4.7-p3, 2.4.7-p2, 2.4.7-p1, 2.4.7, 2.4.6-p9, 2.4.5-p11 and PHP 8.3, 8.2, 8.1
- Upgraded Microform to v2.
- Implemented SOAP p12 Authentication.
- Removed legacy Click to Pay payment module.
- Fixed issue of declined cases and SCA transactions on the Firefox browser.
June 2024
- Adobe Commerce CloudCybersourceVersion 3.5.8 is compatible withAdobe Commerce Cloud: 2.4.6 p3, 2.4.6 p2, 2.4.6 p1, 2.4.6, 2.4.5 p5, 2.4.4 p6 and PHP 8.2, 8.1
- Fixed Logger and CSP issue for Magento v2.4.7.
- PHP support added for v8.3.
- Removed unused class in Apple Pay.
- Added required field for Merchant ID in Back Store.
- Fixed issue for admin order redirecting to blank page.
- Made Payer Authentication common for both Secure Acceptance (Stored Card) and Soap Toolkit API.
- Fixed Visa Checkout error "No such cart entity id with cartid".
March 2024
- Adobe Commerce CloudCybersourceVersion 3.5.7 is compatible withAdobe Commerce Cloud: 2.4.6 p3, 2.4.6 p2, 2.4.6 p1, 2.4.6, 2.4.5 p5, 2.4.4 p6 and PHP 8.2, 8.1
- Removed zend dependency and replaced with laminas.
- Removed Payer Authentication Cardinal key dependency from Back Store Configuration.
- Google Pay and Apple Pay refund issue fixed for multiple websites.
- Apple Pay customer billing address fixes for downloadable and virtual products.
- The issue has been fixed for JSON error message in the 3-D Secure pop-up.
- Fixed invalid card type message that appeared in credit card Flex Microform.
- Added error message for Apple Pay session failure.
- Fixed Device Fingerprint raw parameter for Secure Acceptance.
- Fixed Payer Authentication failure scenario.
October 2023
- Adobe Commerce CloudCybersourceVersion 3.5.6 is compatible withAdobe Commerce Cloud: 2.4.6 p2, 2.4.6 p1, 2.4.6, 2.4.5 p4, 2.4.4 p5, and PHP 8.2, 8.1
- Implemented Direct Connection API Payer Authentication.
- Removed dependency onsales_order_gridtable for Google Pay and Secure Acceptance.
- Apple Pay order cancel fixes.
- PayPal billing address line 2 issue fixes.
- Removed parenthesis for http signature request-target in coreand.eCheckmodule
- Upgraded version for the lcobucci/jwt from 3.4.2 to 3.4.6.
May 2023
- Adobe Commerce CloudCybersource3.5.5 is compatible withAdobe Commerce Cloud: 2.4.6, 2.4.5 p2, 2.4.5p1, 2.4.4 and PHP 8.2, 8.1
- PHP support added for v 8.2.
- Compatibility withAdobe Commerce Cloudv2.4.6 – Changed few components of zend framework to laminas as per the latestAdobe Commerce Cloudchanges.
- Fixed bugs related to supported card types and sandbox/production issue in Apple Pay.
- Fixed jQuery deprecated functions.
February 2023
- Adobe Commerce CloudCybersource3.5.4 is compatible withAdobe Commerce Cloud: 2.4.5 p2, 2.4.5 p1, 2.4.x, 2.3.x
- New implementation foreCheckcron –EventStatus.
- Fixed bug related to Strong Customer Authentication.
- Removed required validation from reCAPTCHA fields.
- Updated Klarna library from credit to payments.
- AddedPaymentFlowModeas inline andPaymentMethodNameaspay_nowin Klarna app session request.
- Updated WSDL version to latest V1.206.
- Add new payment reject status asAUTHORIZED_RISK_DECLINEDfor Decision Manager reject.
Update Adobe Commerce
Adobe Commerce
Follow these steps to update the
Cybersource
bundle to the latest
version:- In your directory, navigate to theAdobe Commerceroot directory and find thecomposer.jsonfile.
- Open thecomposer.jsonfile and in theRequirefield, change the version to the latest version of the plugin.
- After you change the version in theRequirefield of thecomposer.jsonfile, run the composer update command.
Configure Adobe Commerce
Adobe Commerce
Customer payments can be managed through the
Adobe Commerce
or the
Visa Acceptance Solutions Business Center
. This section describes the settings
you must configure in the Business Center
as well as some general use cases that
are typical in the day-to-day management of your Adobe Commerce
store. Contact Visa Acceptance Solutions for information about product availability and
enablement.You must complete all of the configuration tasks in order to use the features offered in
the
Adobe Commerce
Cybersource
integration.Configure Security Credentials
The module uses connection methods to access services that require their own security
credentials for authentication.
You must create and configure the SOAP toolkit key and REST API key for the
Adobe Commerce
to function properly.If you do not have a
Business Center
account, go to the Business Center
Registration
website to create an account. To activate your merchant account, follow the instructions
that are emailed to you. Then log in to the Business Center
to complete the
registration process. Be sure to store your merchant key ID for later use.Create a SOAP P12 Certificate
The
Adobe Commerce
integration uses the SOAP Toolkit API to
access several services.Generate a SOAP P12 certificate from your
Business Center
account. For information on how
to create a SOAP P12 certificate, see Creating a SOAP p12 Certificate. Create a REST API Key
The
Adobe Commerce
integration requires REST API key
creation to use some services like Flex Microform and the Fraud Management
report.From your
Business Center
account, you also need your merchant key ID
and shared secret key to enable the integration with Adobe Commerce
. For information on how to generate a shared secret
key, see Creating a Shared Secret Key Pair. Be sure
to store your key ID and shared secret key for later use.Configure Additional Backend Settings
Some services supported on
Adobe Commerce
require additional backend
setup on your Business Center
account. Contact your Cybersource
account representative
to enable any of these services:- Payment Tokenization: Required by the module for credit card processing
- Decision Manager
- Payer Authentication
- PayPal Express Checkout
- eCheckService
- Online Bank Transfers
- Tax Calculation
- Klarna
- Click to Pay: Enabled in theBusiness Center
- Apple Pay: Enabled in theBusiness Center
Configure Backend Settings
Follow these steps to access the configuration settings in the administration section
of your
Adobe Commerce
console:- Go to theAdobe Commerceadministration console.
- On the left navigation panel, clickStores.
- Under Settings, clickConfiguration.
- On the Configuration page, clickSalesto expand the menu.
- ClickPayment Methods.
- ChooseOTHER PAYMENT METHODS >.Cybersource
ADDITIONAL INFORMATION
Complete all of the required fields in the sections and subsections of the settings to configure theCybersourcepayment module and other payment methods. Expand each section to complete the fields.
Configure General Settings
The settings under the General section apply to all payment methods. Follow these steps to complete this section:
- From theCybersourcesetting, click the arrow to expand the General section.
- From theDebug Modedrop-down list, chooseYesto troubleshoot using theAdobe Commercelogs (cybs.log). Diagnostic information is stored in log files on theAdobe Commerceweb server.
- From theSort Orderdrop-down list, change the default module sort order.
- In theShow Exact Rejection or Error Message to Usersoption set to:
- Noto display general error messages according toAdobe Commerce Cloudin all rejection and error cases.
- Yesto display a general error message according to the responses fromCybersourcein all rejection and error cases.
- In theOverride Payment Error Route Pathfield, enter the error page route path. When you leave the defaultUse system valuebox checked, the checkout or cart route is used if no path is entered.
Configure WebService
The WebService configuration includes the default
Adobe Commerce
merchant ID (applies to all the payment methods), the REST shared key, and the
SOAP key detail. Follow these steps to complete the configuration:- ClickWebService Configurationto expand the section.
- In theMerchant IDfield, enter yourCybersourcemerchant ID.
- From theTest Modedrop-down list, choose:
- Yesto use theBusiness Centertesting environment.
- Noto use the productionBusiness Center. Optionally, in theDeveloper IDfield, you can enter the developer ID. The ID cannot exceed eight characters. You can also request thatCybersourceassign you a developer ID.
- In the Simple Order P12 Key File section, upload the SOAP p12 certificate and then enter the Key Password. If you did not generate a key, see Creating a SOAP p12 Certificate for instructions.
- In theREST API Key Detailfield, enter the REST key you generated from theBusiness Center. If you do not have a REST Shared Secret Key Pair, see Creating a Shared Secret Key Pair for instructions.
ADDITIONAL INFORMATION
Proper configuration of the SOAP WebService is required for the functioning of other services includingTax Calculation, Secure Acceptance, PayPal, Account Takeover Protection, andApple Pay. If you experience issues with these modules, verify that the SOAP WebService options are configured correctly. The SOAP p12 Certificate must have the correct password and the Test Mode option must match the correct environment for theCybersourceBusiness Center(test). - In theREST API Shared Secret Keyfield, enter the Shared Secret key you generated from theBusiness Center. If you do not have a REST Shared Secret Key Pair, see Creating a Shared Secret Key Pair for instructions.
ADDITIONAL INFORMATION
Proper configuration of the REST Web Service is required for other services including Flex Microform,Google Pay, and the Account Updater. If you experience issues with these modules, verify that the REST Web Service options are configured properly. The API Key Detail and API Shared Secret Key must have the correct value, and theDecision Manager,Test Modeoption must match the environment for theCybersourceBusiness Center.
Configure Device Fingerprinting
Device Fingerprinting is used with
Decision Manager
for all relevant payment
methods. If you are not using Decision Manager
, you must disable this
module. Follow these steps to configure device fingerprinting:- ClickDevice Fingerprintto expand the section.
- In theActivefield, chooseYesto activate it orNoto deactivate it if you are not usingDecision Manager.
- In theOrg IDfield, enter the value provided to you. To obtain this value either for test or production, contact yourCybersourcerepresentative.
Configure the Delivery Address Verification Service
The Delivery Address Verification Service acts as an additional layer of address
verification and normalization on the shipping page. Follow these steps to configure
this section:
- ClickDelivery Address Verification Serviceto expand the section.
- From theAddress verificationdrop-down list, chooseYesto enable this service orNoto disable this service.
- From theAddress Force Normalizationdrop-down list, chooseYesto require the use of suggested address alternatives orNoto make suggested address alternatives optional.
Configure Credit Card Payments
Follow these steps to configure
Cybersource
credit card
payments:- From theEnableddrop-down list, chooseYesto activate orNoto deactivate the credit card payment method.
- In theTitlefield, enter the text you want to display as the name for credit card payment method.
- In thePayment APIdrop-down list, choosePayment APIto have an authorization performed and post card data toCybersource. ChooseSOAP Toolkit APIto have the card information tokenized. The SOAP service separately requests authorizations.
- In theCheckout Flow Typedrop-down list, choose a desired checkout type.
ADDITIONAL INFORMATION
Cybersourcerecommends that you chooseFlex Microform. Flex Microform is a REST-based Microform Integration to access new enhancements, easier configuration, and updated technology.You will use all of the benefits from the Hosted Checkout and Checkout API.The customer never leaves your checkout page and is a potential SAQ A qualification. For more information about Microform Integration, see Microform Integration. - In theCSRF Token Expiration Time (Seconds)field, enter the expiration time in seconds. This is the lifetime of the SOP security token used to prevent card testing attacks. For the default of 600 seconds, leave this field blank.
Configure Strong Customer Authentication
When payer authentication is enabled and a transaction is declined with reason code
478
(Strong Customer Authentication required), another request is sent
from the Adobe Commerce
module for the same order. The customer must
complete a 3-D Secure
challenge. To configure this setting, click
Strong Customer Authentication
to
expand the section. In the Enforce Strong Customer Authentication when saving a
card
drop-down list, choose Yes
to have the cardholder
complete a 3-D Secure
challenge while saving a card.Configure Credit Card Settings
Follow these steps to complete the Credit Card Settings section:
- ClickCredit Card Settingsto expand the section.
- From thePayment Actiondrop-down list, chooseAuthorize OnlyorAuthorize and Capture. Authorize Only reserves funds during checkout and captures when making an invoice. The Authorize and Capture payment action authorizes and captures funds during the customer checkout.
- From theAuth Indicatordrop-down list, choose the purpose of the authorization.
- From theNew Order Statusfield drop-down list, choose the order status assigned to the order when successfully paid, or leave the defaultUse system valuebox checked forProcessingorder status.
- From theIgnore AVSdrop-down list, chooseYesto have the results of AVS verification ignored.
- In theIgnore CVNfield, chooseYesto have the results of CVN verification ignored.
- In theSkip Fraud Management for Tokenizationfield, chooseNoto have theSkip Decision Managerfield set tofalsefor Secure Acceptance tokenization requests and set totrueotherwise.
- In theSkip Pre-Authorization Check for Tokenizationfield, choose toNoto have theskip preauthorizationfield set tofalsefor Secure Acceptance tokenization requests and set totrueotherwise.
- In thePass expiration date for tokenized card via SOAPfield, specify the card expiration date with SOAP Toolkit Authorization Calls for card tokenization.
- In theCredit Card Typesbox, choose which card types you want to accept. This applies only toCheckout API andFlex Microform configuration.This option is not used for Hosted Checkout.
- In thePayment from Applicable Countriesfield, leave the defaultUse system valuebox checked to accept credit card payments from the countries chosen, or clear theUse system valuebox to specify countries in the next field.
- Specify the countries from which to accept credit card payments in thePayment from Specific Countriesbox.
- From theOverride secure acceptance localedrop-down list, leave the defaultUse system valuebox checked to use the store locale language.
Configure Payer Authentication
The Payer Authentication (
3-D Secure
) protocol reduces fraud risk for online payments. 3-D Secure
adds frictionless authentication and improves the user
experience. You must have the SOAP Toolkit configured to use this service. Follow these steps to configure the Payer Authentication section:
- ClickPayer Authenticationto expand the section.
- From theEnableddrop-down list, chooseYesto activate the Payer Authentication Module orNoto deactivate it.
- From theCredit Card Typesfield box, choose the card types to be enabled for Payer Authentication.
Configure Save Card for Later Service
Follow these steps to configure Save Card for Later Service settings:
- ClickSave Card for Later Serviceto expand the section.
- From theEnableddrop-down list, chooseYesto enable the customer to save their credit card information securely for later use.
- In theSaved Card Section Titlefield, enter the name of the saved cards payment method.
- From theSave Card for Later for Admin ordersdrop-down list, chooseYesto enable storing card details for orders placed in the admin area.
- From theUse CVV for Saved Credit Cardsdrop-down list, chooseYesto enable the customer to enter the Card Security Code when paying with a stored card.
- From theUse CVV for Saved Credit Cards in Admindrop-down list, chooseYesto allow the merchant to enter the customer’s Card Security Code when the customer is paying with a stored card.
- ClickSave Config.
Configure reCAPTCHA
The
Adobe Commerce
SOAP Toolkit API provides an option to use
reCAPTCHA. This feature is essential in protecting the merchant's store from brute force
attacks. Most of the time, the reCAPTCHA is invisible to normal users, but it will
provide a visible challenge when necessary. The module providing reCAPTCHA is an
optional package.Install reCAPTCHA
To install reCAPTCHA, run this command for Composer
installation:
composer require
Cybersource
/module-recaptcha Generate reCAPTCHA Keys
Follow these steps to generate the
Google reCAPTCHA Site Key and Secret Key:/
- Visit the Google fraud defense website: Google Cloud Fraud Defense documentation
- Log in to the Google Fraud Defense Admin Console.
- Click theCreateicon.
- Fill in the required details.
- After you submit the details, the reCAPTCHA site key and secret key are generated.
ADDITIONAL INFORMATION
Use these keys to configure the module in Back Store.x
Configure reCAPTCHA in Adobe Commerce
Adobe Commerce
Follow these steps to
configure reCAPTCHA in Adobe Commerce.
- Go theAdobe Commerceconsole.
- On the Payment Methods page, under theCybersourcesettings, clickreCaptchato expand the section.
- From theEnableddrop-down list, chooseYesto activate, orNoto deactivate reCAPTCHA.
- In theWebsite API Keyfield, enter your site key obtained from reCAPTCHA Admin Console.
- In theSecret API Keyfield, enter your secret key obtained from reCAPTCHA Admin Console.
- From thereCAPTCHA typedrop-down list, choose the reCAPTCHA type that matches your API keys.
- In theBadge positionfield, choose the reCAPTCHA badge position.
- In thereCAPTCHA languagefield, choose a language code for reCAPTCHA or leave theAutooption selected.
- ClickSave Config.
- Clear theAdobe Commercecache.
Configure the eCheck Payment Module
eCheck
Payment ModuleThe
Cybersource
eCheck
module enables customers to make purchases using a routing
number and an account number. During checkout, an eCheck
transaction
request is sent to Cybersource
. If successful, the transaction is sent
to the Automated Clearing House (ACH).The
Adobe Commerce
queries Cybersource
periodically
to check on the status of each pending eCheck
transaction. In
response, Cybersource
provides an updated transaction status, known as a
Payment Event Type
. Various outcomes can occur during ACH processing. For
each pending transaction included in the Cybersource
response, the
Adobe Commerce
determines whether a transaction remains
pending, settles, or is rejected.You can configure these
eCheck
payment event types :- Pending Event Type: No change is made to the transaction or order status. The order remains in Payment Pending state.
- Reject Event Type: The order is cancelled.
- Accept Event Type: An invoice is prepared for that order, and the order status changes to processing.
Test eCheck Payment Settings
eCheck
Payment Settings You can test the
eCheck
Payment Event Types using two Adobe Commerce
settings that simulate possible event types during
the processing of the requested report. While the status request goes to Cybersource
, the Adobe Commerce
ignores the
returned Payment Event Type in the response and uses the Test Event Type
instead.Follow these steps to test the
eCheck
Payment Event
Types:- Clickto expand the section.eCheck
- From theEnableddrop-down list, chooseYesto enable theeCheckpayment method.
- In theTitlefield, enter the text that is displayed to customers as the name of this payment method.
- Configure the payment statuses for these event types:
ADDITIONAL INFORMATION
- In theAccept Event Typebox, choose which payment statuses will mean accept, and signify the receipt of funds and move the order status to processing.
- In thePending Event Typebox, choose which payment statuses will mean pending.
- In theReject Event Typebox, choose which payment statuses will mean reject because they were rejected after processing by ACH despite being initially accepted during checkout.
- Configure how to accept theeCheckpayment method:
ADDITIONAL INFORMATION
- To accept the default country configuration, in thePayment From Applicable Countriesfield, ensure theUse system valuebox is checked.
- To specify any other countries you will accept theeCheckpayment method from, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries.
- To require customers to enter a drivers license number, from theEnabled Drivers License Numberdrop-down list, chooseYes. ForTeleCheck, contact a representative to see if this field is required.
- To require the customer to enter the check number, from theEnabled Check Numberdrop-down list, chooseYes. These processors have specified whether check number is required or optional:
ADDITIONAL INFORMATION
- Chase Paymentech Solutions: Optional.
- CybersourceACH Service: Not used.
- Worldpay: Optional on debits, and required on credits.
- TeleCheck: Strongly recommended on debit requests, and optional on credits.
- To require an agreement at the checkout page, from theAgreement Requireddrop-down list, chooseYes.
- From theSEC codedrop-down menu, choose a code that specifies the authorization method for the transaction.
- In theSort Orderfield, enter the number of entries to be sorted on a page.
- ClickSave Config.
Configure Fraud Management
You must configure the
Adobe Commerce
to work with Fraud Management
to use all of the features. Follow these steps to configure Fraud Management in
Adobe Commerce
:- ClickFraud Managementto expand the section.
- From theEnable Fraud Management CRON Jobdrop-down list, chooseYes.
- In theFraud Management fail email senderoption, leave theUse system valuebox checked.
- In theFraud Management fail email templateoption, leave theUse system valuebox checked.
- From theSettle Fraud Management accepted order automaticallydrop-down list, chooseYes.
- Expand theOn-Demand Jobsection to see theReport Datefield.
- Enter a date to download an accepted or rejected transactions report, and clickRun.
- ClickSave Config.
Fraud Management Orders
The
Decision Manager
rule setting and the response received for
authorizations and sales service determine whether the Adobe Commerce Cloud
marks the orders as Pending Review. On the
Decision Manager
Case Management page, when you change an order from
REVIEW
to REJECT
or
ACCEPT
, the Adobe Commerce Cloud
updates
payment transaction states periodically (by cron every two minutes) by contacting
Cybersource
and querying for changes.In the settings, find the
Adobe Commerce Cloud
Cron settings and
configure them to trigger an Adobe Commerce Cloud
task. The task
looks for Decision Manager
changes in the Business Center
and
updates the Adobe Commerce Cloud
Orders accordingly.
If the module detects a change in state, it updates the order status in the
Adobe Commerce Cloud
from Pending Review to one of these states:- Processing
- Pending
- Closed
If an order is Pending Review in
Decision Manager
, you
cannot prepare an invoice in the Adobe Commerce Cloud
until
Decision Manager
accepts it.
Fraud Management Refunds
Decision Manager
must either accept or reject an order before issuing a
refund. If you reject an order in Decision Manager
, an Authorization
Reversal for the order automatically occurs as part of the Cron process that queries
for updates in Decision Manager
.Configure Custom Fields
Decision Manager
supports custom fields known as merchant-defined data
fields. You must configure the fields inside Decision Manager
in the
Business Center
to use them. The Module for the Adobe Commerce Cloud
sends 10 of these fields. Follow these steps to add custom fields provided by the
Adobe Commerce Cloud
:- Log in to theBusiness Centerand go toDecision Manager> Shared Configuration > Custom Fields.
- ChooseMerchant Custom Fields.
- To add a field, clickADD CUSTOM FIELD, enter a name, and choose anorder element.
ADDITIONAL INFORMATION
Use the list below to map the correct names and elements for each field:- Logged-in customer:Merchant_defined_data1
- Account creation date:Merchant_defined_data2
- Purchase History Count:Merchant_defined_data3
- Last Order Date:Merchant_defined_data4
- Member account age:Merchant_defined_data5
- Repeat customer:Merchant_defined_data6
- Coupon Code Used:Merchant_defined_data20
- Discount Amount:Merchant_defined_data21
- Gift Message:Merchant_defined_data22
- Order Source:Merchant_defined_data23
- Shipping Method Code:Merchant_defined_data31
- Shipping Method Description:Merchant_defined_data32
- ClickSave.
ADDITIONAL INFORMATION
For detailed instructions on how to add custom fields, see theDecision ManagerGuide. In theBusiness Center, go to the left navigation panel, and chooseDecision Manager > Documentation > Guides.
Configure Apple Pay
To use Apple Pay, you must meet these prerequisites:
- Have a valid Apple Developer Account.
- All pages that incorporate Apple Pay must be served over HTTPS.
- Your website must comply with the Apple Pay guidelines. For more information, see Apple Pay on the Web Acceptable Use Guidelines.
- Your website must have HTTPS mode enabled and used at checkout. For more information, see Setting Up Your Server.
- To configure Apple Pay with theAdobe Commercemodule, you must complete these tasks:
- Register an Apple Pay merchant ID. For more information, see Create Your Apple Pay Merchant ID.
- Create a Payment Processing certificate in theBusiness Center. For more information, see Part 2: Create an Apple Pay Payment Processing Certificate.
- Validate your store domain in Apple Pay. For more information, see Register a Merchant Domain.
- Create a Merchant Identity certificate. For more information, see Create a Merchant Identity Certificate.
Configure the Apple Pay Extension
Follow these steps to configure the Apple Pay extension:
- Go theAdobe Commerceconsole, and open the Payment Methods page.
- Under theCybersourcesettings, clickApple Payto expand the section.
- From theEnabledrop-down list, chooseYesto activate Apple Pay. (orNoto deactivate it.)
- InTitlebox, enter the text to display to customers on the checkout page.
- From thePayment Actiondrop-down list, chooseAuthorize Onlyto reserve funds during checkout and capture during invoice creation. ChooseAuthorize and Captureto authorize and capture during customer checkout.
- From theNew Order Statusdrop-down list, choose the order status assigned to an order that was successfully paid withCybersource.
- In theApple Merchant IDbox, enter your Apple Pay Merchant ID.
- In theApple Display Namebox, enter the business name that appears on a bank or credit card statement. For example, COMPANY, INC.
- In theCertified Domainbox, enter the validated site domain on which the service is meant to be used. Do not enter ahttps://prefix.
- In thePath to Certificatebox, enter the full path to the Merchant ID Certificate file.
- In thePath to Keybox, enter the full path to the Merchant ID Certificate Private key file.
- In theCredit Card Typesbox, choose the types of credit cards to accept for payment.
- In theSort Orderbox, enter a number for the sort order.
Configure Apple Pay
You must configure Apple Pay on your storefront that is displayed to the customer.
Follow these steps to configure Apple Pay on your storefront:
- On the Reviewing the order page, choose.Adobe CommerceApple Pay
- When the Apple Pay window appears, complete fingerprint (Touch ID) authentication, or choose a saved card.
- After authentication is complete, verify the transaction details inBusiness Center.
Configure Google Pay
To use Google Pay on the
Adobe Commerce
, your site must be running
through HTTPS. Follow these steps to configure Google Pay in the Adobe Commerce
:- ClickGoogle Payto expand the section.
- From theEnabledrop-down list, chooseYesto activate Google Pay orNoto deactivate Google Pay.
- In theTitlebox, enter text to display to customers on the checkout page.
- From thePayment Actiondrop-down list, chooseAuthorize Onlyto reserve funds during checkout and capture during invoice creation. ChooseAuthorize and Captureto authorize and capture funds during customer checkout.
- In theGoogle Pay Merchant IDbox, enter your Google Pay merchant ID.
- In theMerchant Display Namebox, define your business name that appears on a customer's bank or credit card statement. For example, “COMPANY, INC.”
- Configure which countries you will accept Google Pay from:
ADDITIONAL INFORMATION
- To accept payment from the default countries, in thePayment From Applicable Countriesfield, leave theUse system valuebox checked.
- To specify other countries, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries from where you want to accept Google Pay.
- In theCredit Card Typesfield box, choose which card types to accept.
- To show the Google Pay button on the product page, in theGoogle Pay button on Product Pagefield, chooseYes.
- To show the mini cart widget, in theGoogle Pay button in mini cartfield, chooseYes.
- In theSort Orderbox, enter a number to change the default module sort order.
- ClickSave Config.
Configure Alternate Payments
Adobe Commerce
has four types of alternate payments modules: - PayPal. For more information, see Configure PayPal.
- Klarna. For more information, see Configure Klarna.
- Bank Transfer. For more information, see Configure Bank Transfers.
- WeChat Pay. For more information, see Configure WeChat Pay.
Click
Alt Payments
to expand the section.Configure Klarna
Follow these steps to configure Klarna payments. You can use the default merchant ID
or you can manually configure a new merchant ID:
- ClickKlarnato expand the section.
- From theEnabledrop-down list, chooseYesorNoto activate or deactivate Klarna.
- FromTitlebox, enter the text to display to customers on the checkout page.
- From theUse Default Merchant IDdrop-down list, leaveYesselected to use the Merchant ID given in Web Service Configuration under General Settings. ChooseNoto enter another merchant ID and transaction key in the next two fields.
- If you choose not to use the default merchant ID, in theMerchant IDfield, enter a different merchant ID.
- In theTransaction Keyfield, enter the transaction key for the merchant ID you entered.
- From theNew Order Statusdrop-down list, choose the order status assigned to the order successfully paid withCybersource.
- Configure which countries you will accept Klarna from:
ADDITIONAL INFORMATION
- To accept payment from the default countries, in thePayment From Applicable Countriesfield, leave theUse system valuebox checked.
- To specify other countries, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries from where you want to accept Klarna.
Configure PayPal
Follow these steps to configure the PayPal Express Checkout, PayPal Credit, and
PayPal Billing Agreement:
- ClickPayPalto expand the section.
- From theEnabledrop-down list, chooseYesorNoto activate or deactivate PayPal.
- InTitlebox, enter the text to display to customers on the checkout page.
- From theNew Order Statusdrop-down list, choose the order status assigned to the order successfully paid withCybersource.
- In theMerchant IDfield, enter yourAdobe Commerce Cloudmerchant ID.
- From thePayPal Redirection Typedrop-down list, chooseTraditional Express Checkoutto redirect the customer PayPal Payment Page, or chooseIn-Context Express Checkout for a PayPalpop-up to appear for customers to complete payment.
- From thePayment Actiondrop-down list, chooseAuthorize Onlyto check the account for validity, but not charge until the order is approved and invoiced. ChooseAuthorize and Captureto charge the PayPal account at the time the order is submitted.
- Configure which countries you will accept PayPal from:
ADDITIONAL INFORMATION
- To accept payment from the default countries, in thePayment From Applicable Countriesfield, leave theUse system valuebox checked.
- To specify other countries, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries from where you want to accept PayPal.
- From theEnable PayPal Creditdrop-down list, chooseYesto enable financing through PayPal Credit.
- In thePayPal Credit Titlebox, enter the text customers will see as the title of PayPal Credit payment option.
- From theEnable PayPal Billing Agreementsdrop-down list, chooseYesto allow registered customers to create a billing agreement for faster purchases.
- In theSort Orderbox, enter a numeric value to place this payment method amongst all the otherAdobe Commercepayment methods.
Configure Bank Transfers
Online banking services enable customers to pay for goods using direct online bank
transfers from their bank account to your
Adobe Commerce
merchant
account.Click
Bank Transfer
to expand the section. In the
Store Name
field, enter the name you want customers to
see on their bank transfer invoices.Configuring iDEAL
Follow these steps to configure an iDEAL payment:
- ClickiDEALto expand the section.
- In theEnabledrop-down list, chooseYesto activate the iDEAL bank transfer orNoto deactivate iDEAL bank transfer.
- InTitlebox, enter the text to display to customers on the checkout page.
- In theUse Default Merchant IDfield, leaveYesselected to use the merchant ID given in the Web Service Configuration under General Settings page. ChooseNoto enter another merchant ID and transaction key in the next two fields.
- If you choose not to use the default merchant ID, enter yourCybersourceMerchant IDin theMerchant IDfield.
- In theTransaction Keyfield, enter the transaction key for the merchant ID you entered.
- In theAllowed Currenciesbox, choose which currencies you will accept payment.
- In theSort Orderbox, change the default module sort order.
- Configure which countries you will accept iDEAL from:
ADDITIONAL INFORMATION
- To accept payment from the default countries, in thePayment From Applicable Countriesfield, leave theUse system valuebox checked.
- To specify other countries, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries from where you want to accept iDEAL.
Configuring Bancontact
Follow these steps to configure Bancontact bank transfer payments:
- ClickBancontactto expand the section.
- In theEnabledrop-down list, chooseYesorNoto activate or deactivate Bancontact Bank Transfer.
- InTitlebox, enter the text to display to customers on the checkout page.
- In theUse Default Merchant IDfield, leaveYesselected to use the Merchant ID given in Web Service Configuration under General Settings. SelectNoto enter another merchant ID and transaction key in the next two fields.
- If you choose not to use the default merchant ID, enter yourCybersourcemerchant ID in theMerchant IDfield.
- In theTransaction Keyfield, enter the transaction key for the merchant ID you entered.
- In theAllowed Currenciesbox, choose the currencies with which to accept payment.
- In theSort Orderbox, change the default module sort order.
- Configure which countries you will accept Bancontact from:
ADDITIONAL INFORMATION
- To accept payment from the default countries, in thePayment From Applicable Countriesfield, leave theUse system valuebox checked.
- To specify other countries, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries from where you want to accept Bancontact.
Configure WeChat Pay
WeChat Pay is a digital wallet that enables customers to make mobile payments and
online transactions. Customers who have provided bank account information can use
the app to pay bills, order goods and services, transfer money to other users, and
pay in stores if the stores have a WeChat payment option.
Follow these steps to configure WeChat Pay:
- ClickWeChat Payto expand the section.
- From theEnabledrop-down list, chooseYesto activate WeChat Pay, orNoto deactivate it.
- In theSort Orderbox, change the default module sort order.
- InTitlebox, enter the text to display to customers on the checkout page.
- In theUse Default Merchant IDfield, leaveYesselected to use the merchant ID from the Web Service Configuration section under General Settings. ChooseNoto enter another merchant ID and transaction key in the next two fields.
- If you choose not to use the default merchant ID, enter yourCybersourcemerchant ID in theMerchant IDfield.
- In theTransaction Keyfield, enter the transaction key for the merchant ID you entered.
- In theQR Code Expiration Timefield, enter an expiration time in seconds for the WeChat pay QR code.
- In theCheck Status Frequencyfield, enter an interval in seconds between transaction status checks.
- In theMax Status Requestsfield, enter a limit for transaction status checks.
- Configure which countries you will accept WeChat Pay from:
ADDITIONAL INFORMATION
- To accept payment from the default countries, in thePayment From Applicable Countriesfield, leave theUse system valuebox checked.
- To specify other countries, clear theUse system valuebox and in thePayment From Specific Countriesbox, choose the countries from where you want to accept WeChat Pay.
- In theSuccess/Failure Message Delayfield, enter a delay in seconds between the transaction check and redirection to the result page.
- In theCheck Status query Simulated Responsefield, choose a simulated status check response code for testing.
- ClickSave Config.
Configure Taxes
Cybersource
offers a service that calculates taxes to be charged on
orders. You must configure your settings in order to receive accurate results.Contact your
Cybersource
representative to have this feature enabled.
This feature includes activation of sandbox capabilities as well.Before configuring the Tax Calculation service, you must have the SOAP Web Service
configured. For more information, see Configure Security Credentials.
To use the Tax Calculation Service, you must have the Product Tax Class codes and
Cybersource
Tax Services settings configured. For more
information, see Configure Product Tax Classes and Configure Cybersource Tax Services Settings.Configure Product Tax Classes
Each product in the
Adobe Commerce
has a setting for Tax Class.
This setting defines the product and how it should be taxed. Contact your Cybersource
representative for a list of available product tax class IDs
and your tax consultant for advice on which IDs you should use for products you
sell.Follow these steps to set the product tax class IDs in
Adobe Commerce
:- Go to theAdobe CommerceAdmin console.
- On the left panel, clickStores, and then clickTax Classes.
- On the Tax Classes page, clickAdd Newto create a new tax class entry for each tax class ID that your representative provides.
- In theTax Class Codefield, enter the code provided to you.
- From theTax Class Typedrop-down list, chooseProduct.
- ClickSave.
- Complete these steps for each tax class ID.
Configure Cybersource Tax Services Settings
Cybersource
Tax Services SettingsFollow these steps to configure
Cybersource
Tax Services in the
Adobe Commerce Cloud
:- Go to theAdobe Commerce Cloudadmin console, and in the left panel, clickStores, and then clickConfiguration.
- On the Configuration page, go toSales > Tax >.CybersourceTax Services
- From theTax Calculationdrop-down list, chooseYesto activate theCybersourceTax Services per your business requirements.
- In theNexus regionsbox, select the regions where your business has a physical presence in the U.S. or Canada.
- In theCustomer countries to calculate Tax forbox, choose the countries for which you will calculate tax.
- In theCustomer Tax classes to exclude from Tax calculationbox, choose the customer tax classes to exclude from tax calculation.
- In theShip Fromfields, enter the city, postcode, country, and region from which the orders are shipped.
- In theAcceptancefields, enter the city, postcode, country, and region in which you will accept or approve customers' orders.
- In theOriginfields, enter the city, postcode, country, and region of the point of origin from which the order is picked up.
- In theMerchant VATfields, enter the merchant VAT seller registration number.
- ClickSave Config.
Calculating Taxes for Shipping Rates
You might have taxes calculated for shipping rates if your site offers dynamic
shipping rates from a carrier that is presented to the customer at checkout.
However, if you offer a flat-rate shipping charge, you might want to add taxes
to that flat rate.
Follow these steps to add taxes to flat shipping rates:
- On the Configuration page, go toSales > Tax > Tax Classes.
- From theTax Class for Shippingdrop-down list, select the product tax code that references the taxes applied to shipping services.
- ClickCalculation Settings.
- In theShipping Pricesfield, chooseExcluding Taxwhen the shipping rates need to be taxed. SelectIncluding Taxwhen the shipping rates already include taxes , and no taxes are applied through theCybersourcetax service.
- ClickSave Config.
Configure Transactional Emails
When an order is flagged for
Decision Manager
review, the customer is not
informed that their transaction was not fully accepted. If a manual review leads to
a rejection of the transaction, the customer is then informed that their order is no
longer active. You can configure the email sent to the customer.Follow these steps to configure the transactional emails sent to the customers:
- Go to theAdobe Commerceconsole.
- On the left panel, chooseMarketing.
- ClickEmail Templates.
- In the table, find the Template column, and click theDM Fail Transactiontemplate row. The Template Information page opens.
- On the Template Information page, complete the required information in the template name, subject, and content text boxes.
- ClickSave Template.
Configure Cron Settings
Follow these steps to configure Cron settings for
Decision Manager
:- Open theAdobe Commerceconsole.
- On the left panel, clickStores.
- Go toConfiguration > Advanced > System > Cron (Scheduled Tasks).
- Scroll down and clickCron configuration options for group:dm.
- Complete the required fields.
- ClickSave Config. For further instructions on how to configure Cron settings, see Cron (scheduled tasks).
Configure Tokens
When a customer is logged in and is checking out, their card data can be stored in a
secured
Cybersource
data center. After the card data is saved, a token
is provided to you through this module. This token represents the customer record. When
a returning customer uses your checkout, they can opt to use a previously stored card so
they don't have to enter their card data again.When a token is used, the customer is still redirected to the
Cybersource
Hosted Payment page for payment confirmation. If a customer chooses to checkout as a
guest, the token system is not used.Save a Card for Later Use
To save the card, log in or register a new customer account. During the checkout
process, check the
Save for later use
box. After the order is
placed, the card information is securely saved with Cybersource
.Manage the Adobe Commerce Tokens
Adobe Commerce
TokensCustomers who are logged in can delete their tokens at any time. To do so, they must
visit the My Account section of the
Adobe Commerce
and choose
the Stored Payment Methods
menu item. Customers can use the
delete links beside any stored tokens to remove a stored token.Pay with Tokens
To pay the order with a stored card, the customer chooses it from the list at the top
of the Billing and review checkout page.
Multi-Shipping Feature
The plugin supports the multi-shipping feature only for the
Adobe Commerce
registered users when they place orders with stored credit
cards.Node Implementation
The plugin does not support multiple-node implementation.
Support and Troubleshooting
- Summary of the issue
- Steps to reproduce the issue
- Magento platform versionCybersourceplugin version
- Visa Acceptance Solutions merchant ID
- Configuration screenshots
- All the themes/additional extensions that are installed
- Log files
To retrieve log files, navigate to this path in the root directory of Magento:
Magento Folder Name\var\log
.These log files are needed:
- system.log
- debug.log
- cybs.log
- exception.log
OpenCart
The plugin for OpenCart provides a payment solution for
merchants using OpenCart to manage their orders. This section describes the payment
methods and services the Plugin provides.
Supported payment methods
These are the supported payment methods for OpenCart:
- Credit and debit cards
- eCheck
- Click to Pay
Supported payment services
These are the supported payment services available for OpenCart:
- Payment acceptance services
- Authorization only
- Sale (bundled authorization and capture)
- Electronic check debit (sale) foreCheckpayment method
- Order management services
- Capture an authorization(not foreCheck)
- Multiple partial captures (not foreCheck)
- Standard and partial refunds
- Standard and partial void captures(not foreCheck)
- Standard and partial void refunds
- Full authorization reversal(not foreCheck)
- :Token Management Service(TMS) for credit and debit cards payments
- Create payment token along with authorization
- Update an existing token along with authorization
- Update an existing token from My Account section
- Delete an existing token from My Account section
- Create payment token for new payment methods during checkout
- Make a payment with a stored token during checkout
- Reporting services that allow you to import theses:Business Centerreports into OpenCart
- Transaction Request Report
- Payment Batch Detail Report
- Conversion Detail Report
Release Information
This section provides information about the releases for the plugin.
Release Version | Release Date | Support End Date |
|---|---|---|
Version 22.1.0 | October 25, 2022 | October 14, 2025 |
Version 23.1.0 | December 8, 2023 | December 7, 2026 |
Version 23.1.0 includes the following enhancements:
- Updated authentication signature
- Added DAV enable/disable button for admin configuration
- Updated reCAPTCHA key generation tooltip URL
- Fix for target origin issue for different domain in the flex form capture context
- Compatible with OpenCart versions 3.0.3.7 and 3.0.3.8
Version 22.1.0
- Initial release.
Installation
Before you install the plugin, make sure that these requirements are met:
- You are usingOpenCartversion 23.1.0.
- You have aBusiness Centeraccount and have generatedBusiness CenterREST API keys:
- To create an account, go to theBusiness CenterRegistration website.
- To generate REST API keys, see restgs-intro.html.
Follow these steps to install the plugin:
- Download the plugin from theOpenCartwebsite to your local system.
- OpenOpenCartBack Office and from the Dashboard, chooseExtensions>Installer.
- ClickUploadand browse to the file you downloaded to your local system.The pane displays the status of the installation. After the Plugin is installed, the pane indicates that the module is installed. You can close it or clickConfigureto configure the Plugin.
Configuration Overview
This section describes how to set up the plugin.
The following table shows where to access the plugin configuration settings.
From the left navigation panel in
OpenCart
Back Office, select
Extensions
and follow the path indicated in the table for the configuration
settings you want to configure. Settings | Path |
|---|---|
| Extensions > Extensions > Modules > Cybersource
Configuration |
Unified Checkout
| Extensions > Extensions > Payments > Cybersource
Unified Checkout |
eCheck
| Extensions > Extensions > Payments > Cybersource
eCheck |
Enable Basic Configuration
This section describes the required and optional basic configuration settings for the
plugin.
To enable Basic Configuration, follow these steps:
- InOpenCartBack office, navigate toExtensions>Extensions>Modules>.CybersourceConfiguration
- Click theEditicon.
- In the General Configuration tab of the EditCybersourceConfiguration Module pane, from the drop down list or text box, select or enter a setting.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to enable.
Required Settings
These settings are required for using the plugin:
- Sandbox Mode
- Set toEnableto operate in Sandbox (T) mode. You can test new changes in this mode and no funds are affected.
- Set toDisableto operate in Production (Live) mode.
- Merchant ID
- Enter theBusiness CenterMerchant ID or Organization ID, which is a unique identifier for the merchant.
- Merchant Key ID
- Enter your REST Shared Secret Key generated from within theBusiness Center. This specific key authenticates and authorizes the merchant's integration with the gateway.
- Merchant Secret Key
- Enter the complimentary Secret key that is generated at the same time as the Merchant Key ID. It is used for secure communication between the merchant's online store and a payment gateway.
- reCAPTCHA Site key
- For each request, this key returns a score based on the user interactions with your site. Based on these scores, you can take appropriate actions for your site, such as allowing or blocking users.
- reCAPTCHA Secret key
- This key authorizes communication between the plugin's backend and the reCAPTCHA server to verify the user's response. The secret key should be kept safe for security purposes.
Optional Settings
These settings are optional for using the plugin.
- Fraud Management
- ClickEnableto enable merchants to identify and prevent fraudulent activities.
- Delivery Address Verification
- ClickEnableto enable merchants to verify the delivery address.
- Device Fingerprint
- ClickEnableto enable merchants to identify and track devices accessing an online store.
- Developer ID
- Identifier for the developer that helps integrate a partner solution withCybersource. This settings is only required forCybersourceSystem Integrators.
- Status
- ClickEnablefor theCybersourceintegration to be active and visible at checkout.
- Payment Action
- ClickEnableto enable card payments for Authorize Only or Sale (Authorization and Capture) for front office transactions.
- Enhanced Logs
- ClickEnableto generate logs that can be accessed by selectingConfigure>Advanced Parameters>Logs.
Cybersource
strongly recommends that you map your Order Status
responses to your preferred order status under the Order Status Configuration
section. Enable Unified Checkout
Unified Checkout
This section describes the required and optional configuration settings for
Unified Checkout
for the plugin. To enable Card Payment follow these steps:
- InOpenCartBack office, navigate toExtensions > Extensions > Payments >.CybersourceUnified Checkout
- Click theEditicon.
- In the EditCybersourceUnified Checkoutpane, from the drop down list or text box, select or enter the setting you want.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to set.
Required Settings
The following settings are required:
Unified Checkout
for the plugin:- Payment Option Label
- Enter the text you want displayed to the customer at checkout.
- Allow Card Types
- Select the card types that you want to accept.
Optional Settings
The following settings are optional for enabling
Unified Checkout
for
the plugin:- Status
- ClickEnablefor theCybersourceintegration to be active and visible at checkout.
- Sort Order
- Specify an order in which a payment method displays at checkout.
Enable Tokenization
This section describes the required and optional configuration settings for Tokenization
for the plugin.
To enable Tokenization follow these steps:
- In OpenCart Back office, navigate toExtensions > Extensions > Payments >.CybersourceUnified Checkout
- Click theEditicon.
- In the EditCybersourcepane, from the drop down list or text box, select or enter the setting you want.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to set.
Required Settings
The following settings are required:
- Tokenization
- Setting enables customers to save cards for future use while making a card payment.
Optional Settings
The following settings are optional for enabling Tokenization for the plugin:
- Network Token Updates
- Enable this setting to subscribe to Network Token life cycle updates.
- Limit Saved Card Rate
- With this setting enabled, a limit is set to save only a specified number of cards in the My Account section in Front Office. There are two settings:
- Saved Card Limit Count: Number of cards that can be saved in a certain period of time.
- Saved Card Limit Time Frame: Number of hours that saved card attempts are counted.
- Enforce SCA for Saving Card
- If enabled, card holders are3-D Securechallenged when saving a card.
Enable Fraud Management
This section describes the required and optional configuration settings for Fraud
Management for the plugin.
To enable Fraud Management follow these steps:
- InOpenCartBack office, navigate toExtensions > Extensions > Modules >.CybersourceConfiguration
- Click theEditicon.
- In the General Configuration tab of the EditCybersourceConfiguration Module pane, from the drop down list or text box, select or enter the setting you want.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to enable.
Required Settings
The following settings are required:
- Fraud Management
- Device Fingerprint (not technically required, but highly recommended)
Optional Settings
The following setting is optional for enabling Fraud Management for the plugin:
- Conversion Detailed Report
- This report (enabled in the Report Configuration tab) pulls Case Management changes fromCybersourceat regular intervals to ensure orders are kept updated withinOpenCart.
Enable 3-D Secure (Payer Auth)
3-D Secure
(Payer Auth)This section describes the required and optional configuration settings for
3-D Secure
(Payer Authentication) for the plugin.To enable
3-D Secure
follow these steps:- InOpenCartBack office, navigate toExtensions > Extensions > Payments >.CybersourceUnified Checkout
- Click theEditicon.
- In the EditCybersourcepane, select from the dropdown or specify in the text box the configuration setting option you want to set.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to enable.
Required Settings
The following settings are required:
3-D Secure
for the plugin:- Payer Authentication
- When this setting is enabled, an extra layer of security is added at checkout.
Optional Settings
The following setting is optional but recommended for regions enforcing
3-D Secure
for the plugin:- Enforce SCA for Saving Card
- When this setting is enabled, card holders are3-D Securechallenged when saving a card.
Enable eCheck
eCheck
This section describes the required and optional configuration settings for
eCheck
for
the plugin. To enable
eCheck
follow these steps: - InOpenCartBack office, navigate toExtensions > Extensions > Payments >.CybersourceeCheck
- Click theEditicon.
- In the EditeCheckpane, from the drop down list or text box, select or enter the setting you want.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to enable.
Required Settings
The following settings are required:
eCheck
for the plugin:- Status
- With this setting enabled,eCheckis active.
Optional Settings
The following setting is optional but recommended for enabling
eCheck
for the
plugin:- Sort Order
- Order in which a payment method displays at checkout.
Enable Reporting
This section describes the required and optional configuration settings for Reporting for
the plugin.
To enable Reporting follow these steps:
- InOpenCartBack office, navigate toExtensions > Extensions > Modules >.CybersourceConfiguration
- Click theEditicon.
- In the Report Configuration tab of the EditCybersourceConfiguration Module pane, from the drop down list or text box, select or enter the configuration setting you want.
- Click theSaveicon.
- Repeat for each required setting and each optional setting you want to enable.
Required Settings
The following settings are required:
- Payment Batch Detail Report
- This report includes transactions that are processed with the applications. This report is available shortly after captured transactions are batched.
- When set toEnable, this report is downloaded from theBusiness CentertoOpenCart. The report is downloaded by default to different locations, depending on the mode in whichOpenCartis operating:
- In Sandbox (Test) mode, the report downloads to{OpenCartModuleInstallationDirectory}/cybersourceofficial/Reports/Sandbox
- In Production (Live) mode, the report downloads to{OpenCartModuleInstallationDirectory}/cybersourceofficial/Reports/Production.
- Cybersourcestrongly recommends thatOpenCartand theBusiness Centeroperate in the same time zone so that the Transaction Request Report and Payment Batch Detail Report work properly.
- Transaction Request Report
- This report includes details for individual transactions that are processed each day.
- When set toEnable, this report is downloaded from theBusiness CentertoOpenCart. The report is downloaded to different locations, depending on the mode in whichOpenCartis operating:
- In Sandbox (Test) mode, the report downloads to{OpenCartShopModuleInstallationDirectory}/cybersourceofficial/Reports/Sandbox
- In Production (Live) mode, the report downloads to{OpenCartModuleInstallationDirectory}/cybersourceofficial/Reports/Production.
- Cybersourcestrongly recommends thatOpenCartand theBusiness Centeroperate in the same time zone so that the Transaction Request Report and Payment Batch Detail Report work properly.
Optional Settings
The following settings are optional but recommended for enabling Reporting for the
plugin:
- Download path
- If you want to download the report to a path other than the default, specify that path here.
- Conversion Detail Report
- When set toEnable, this report pulls Case Management changes from theBusiness Centerat regular intervals to ensure orders are updated inOpenCart.
Enforcing Strong Customer Authentication
Select the
Enforce Strong Customer Authentication
setting to prompt a
3-D Secure
challenge when a customer saves their credit card
information. The customer is 3-D Secure
challenged when a transaction
is declined as reported by response code 478
(Strong Customer
Authentication required). After the transaction is declined, another request is sent
for the same order. The Enforce Strong Customer Authentication setting is only
available when the Payer Authentication/
3-D Secure
(General Plugin
setting) and Tokenization (Fraud Management Plugin setting) are enabled. See
Enable 3-D Secure (Payer Auth) and Enable Tokenization for information about enabling these
settings.Follow these steps to enable Enforce Strong Customer Authentication:
- OpenOpenCartBack Office and selectExtensions>Extensions>Payments>.CybersourceUnified Checkout
- Select theEditicon.
- From the drop down menu next to Enforce SCA for Saving Card, selectEnable.
- Click theSaveicon.
Scheduling Report Generation
Schedulers on a Linux, Mac, or Windows system are used to set up how often a specified
report is generated. Schedulers for Linux and Mac systems are set up using a Cron Tab.
The scheduler for a Windows system is set up using the Windows Task Scheduler app.
When setting up a schedule for generating a specific report, use this format:
- Format:<shop domain name>/module/cybersourceofficial/paymentReport
- Example:http://www.opencart_1.7.8.6.com/module/cybersourceofficial/paymentReport
Cron Tab Syntax for Mac and Linux Systems
When setting up the reporting schedule on a Linux or Mac system, you use
crontab
commands that determine how often and when the report
is generated. The syntax is:
* * * * * [command]
The asterisk (*) represents each of these timing parameters:
- Minute (0-59)
- Hour (0-23)
- Day of Month (1-31)
- Month (1-12)
- Day of week (0-6), (0-Sunday)
For example, these timing parameters indicate how often a specified report is
generated:
- * * * * * [command]: Runs every minute of every day of every week of every month.
- 0 * * * * [command]: Runs every hour of every day of every week of every month.
- 30 2 * * * [command]: Runs at 2:30 a.m. every day of every week of every month.
- 0 0 2 * * [command]: Runs once a month every month on the second day of the month.
- 0 * * * 1 [command]: Runs every Monday at every hour.
- 0,10,20 * * * * [command]: Runs on 0, 10, 20 minute of every hour of every day of every week of every month.
- 0 5-10 * * * *[command]: Runs every hour between 5 a.m. and 10 a.m.
- @reboot [command]: Runs every time after the server reboots.
- */5 * * * * [command]: Runs every five minutes of every day.
Setting Up Cron Scheduler for Linux
- Open a Linux terminal.
- Entercrontab-eto enter editor mode. For example:root@OpencartQA4:/etc# crontab -e
- Enter the command to set the timing for the cron job. For example, this command sets the cron job to run every 15th minute of every hour, every day, every week, and every month:15 * * * * curl https://www.dev.opencart.cybsplugin.com/mps1760/module/mybank/paymentReport
- EnterCtrl + Xto close the editor.
- Enter thecrontab -lcommand to check the scheduled cron job. For example:
The scheduled cron job should appear on the screen. For example:root@OpencartQA4:/etc# crontab -l15 * * * * curl https://www.dev.opencart.cybsplugin.com/mps1760/module/mybank/paymentReport
Setting Up Cron Scheduler for Mac
- Open a Mac terminal.
- Entercrontab-eto enter editor mode.C02X63PRJG5J:~ $crontab -e
- Enter the command to set the timing for the cron job. For example, this command sets the cron job to run every 45th minute of every hour, every day, every week, and every month:45 * * * * curl https://www.qa.opencart.cybsplugin.com/mps1786/module/cybersourceofficial/paymentReport
- EnterEsc + : + w + qto close the editor. The editor closes and displays this message:crontab: installing new crontab
- Enter thecrontab -lcommand to check the scheduled cron job.C02X63PRJG5J:~ $crontab -lThe scheduled cron job should display on the screen. For example:45 * * * * curl https://www.qa.opencart.cybsplugin.com/mps1786/module/cybersourceofficial/paymentReport
Setting Up Task Scheduler for Windows
- Open the Task Scheduler app and clickCreate Task. The Create Task pane displays.
- Select the General tab and enter a name for the task in theNamefield.
- Select the Triggers tab and clickNew. The New Trigger pane displays.
- Make the desired timing selections for the task in the New Trigger pane and clickOK.
- Select the Actions tab in the Create Task pane and clickNew. The New Action pane displays.
- Select and enter this information in the New Action pane and clickOK.
- Action drop-down menu:chooseStart a program.
- Program/script field:enter thecurlcommand.
- Add arguments (optional):enter the reporting URL.
- ClickOKin the Create Task pane to create the task. The new task displays in the Task Scheduler Summary.
Using the Plugin
The plugin provides merchants a frictionless way to process
payments, prevent fraud, and generate
reports within the
Business Center
while making it easy for customers to place and cancel orders, and save or update stored credit or
debit card information.Order Management
This section describes the order management process that occurs after a customer places
an order.
The order management process is handled using these
OpenCart
office
interfaces: - : Customers use this interface to place and cancel orders, and save or update stored credit or debit card information.
- : Merchants use this interface to configure the Plugin and manage orders, which includes these tasks:
- Capture an authorization(multiple partial captures are also supported).
- Reverse an authorization (full authorization is supported).
- Void a capture (standard and partial voids are supported).
- Refund a capture (standard and partial refunds are supported).
- Void a refund (standard and partial voids are supported).
Order Status
Order status is triggered and updated when transactions are processed. The plugin supports custom and default status states for
orders.
Custom order status states:
- Cancel error
- Canceled
- Canceled Reversal
- Chargeback
- Complete
- Denied
- Expired
- Failed
- Order cancelled by merchant
- Partial Refunded
- Partial Voided
- Payment error
- Payment pending for review
- Pending
- Processed
- Processing
- Refund Error
- Refunded
- Reversal
- Shipped
- Void Error
- Voided
Default order status states:
- Processed
- Canceled
- Shipped
- Delivered
- Refunded
Only the shipped and delivered status states can be manually updated.
Order Management Workflows
This section describes the order of events that the merchant completes after a customer
submits an order.
After-Authorization Workflow
This workflow comprises the sequence of events that occur after a customer places a new
order using
OpenCart
Front Office. The workflow shows how the order
status is updated when the authorized transaction is captured or reversed (full
authorization reversal). - The new order displays inOpenCartBack Office and the order status isPending.
- The merchant chooses one of these actions:
- Standard capture.
- Partial capture.
- Cancel products. For a full authorization reversal, the merchant must also cancel the order, which requires that they select all the quantities and all the items included in the order.A partial authorization reversal is not supported.
- When the merchant initiates a full authorization reversal, the authorization is cancelled and the order status is set toOrder cancelled by merchant.
- When the merchant initiates a multiple partial capture, they choose how many quantities to capture and whether to include the shipping costs.After multiple partial captures are processed, the order status is set toProcessing.
- When the merchant initiates a full capture, the entire authorization amount is captured and the order status is set toProcessed.
After-Capture Workflow
This workflow comprises the sequence of events that occur after an authorization is
captured. The workflow shows how the order status is updated when the captured
transaction is refunded or voided.
- The merchant selects one of these actions:
- Standard refund
- Partial refund
- Void capture
- If the merchant voids the capture, the captured transactions are voided.When all quantities of the transaction are captured, the entire order is voided and the order status is set toPayment cancelled.If only a few quantities are captured, only the captured quantities are voided and the order status is set toPartial payment accepted.
- If the merchant initiates a standard refundbeforeupdating the order status toshipped, the order status is set toPartial refunded (before shipped)until the refunded amount becomes equal to the captured amount. When the refunded amount becomes equal to the captured amount, the order status is set toRefunded.
- When the merchant selects a refundafterupdating the order status toshipped, the order status is set toPartial refunded (after shipped)until the refunded amount becomes equal to the captured amount. When the refunded amount becomes equal to the captured amount, the order status is set toRefunded.To refund the amount of an order, merchants can either generate a voucher or a credit slip for the refund. Depending on the type of refund they select and whether they issue a voucher or a credit slip, one of these actions occurs:
- When the merchant choosesGenerate a voucherfor a partial refund, the sum of the items is not refunded. Instead, a voucher is generated that can be used for future transactions.
- When the merchant choosesGenerate a voucherand enters the amount in the shipping costs field for a partial refund, then a voucher equal to the sum of the items and the shipping amount is generated.
- When the merchant choosesGenerate a credit slipfor a standard refund, the sum of the items is refunded.
- When the merchant chooses bothGenerate a credit slipandRepay shipping costsfor a standard refund, the sum of the items and the shipping amount are both refunded.
- When the merchant chooses bothGenerate a voucherandRepay shipping costsfor a standard refund, a voucher equal to the sum of the items and shipping amount is generated.
- When the merchant chooses bothGenerate a voucherandGenerate credit slipfor a standard refund, a voucher is generated and a refund for the sum of the items is not generated.
After-Refund Workflow
This workflow comprises the sequence of events that occur when the merchant voids a
refund under specific conditions:
- When the refund is processedbeforethe order is shipped, the refund is cancelled and the order status is set toVoidedorPartially Voided.
- When the refund is processedafterthe order is shipped, the refund is cancelled and the order status is set toVoidedorPartially Voided.
- When the voided refund amount is equal to the refund amount, the refund is cancelled and the order status is set toVoidedorPartially Voided.
OpenCart
does not provide an option to return
Gift Certificates. For orders associated with Gift Certificates, the services mentioned
below are not available: - Front Office Cancel
- Back Office Cancel
- Void a Capture
Customer Tasks
Customers can use the
My Account
option on the merchant's OpenCart
website to manage orders and their payment information. The
following sections contain the steps to complete these tasks.Saving Credit/Debit Card Information
Saving card information enables customers to use that information for future transactions. Using
OpenCart
Front Office, customers can save their card
information during the checkout process, or they can add their card's information to
their registered OpenCart
accounts using the Cybersource
My Cards feature.If a customer wants to save their card information during the checkout process, they can select
the
Save my card for future payment
option when entering
their credit/debit card payment during checkout.The card information can also be saved using the
Cybersource
My Cards page in
OpenCart
:- OpenOpenCartFront Office.
- ClickMy Account > Managed Stored Credit Cards >.CybersourceMy Cards > Add New Card
- If no current address is associated with the customer account, the customer is prompted to add an address. The customer can enter the required address information and clickSave.
- If an address is already associated with the customer account, the customer can select and use the address or add a new address.
- When the address information is complete and selected, the customer can update the card expiration information, if needed, or delete the existing card from the account.
- To update the expiration information (expiration month/year) for the card, underSaved Cardsthe customer clicks the blue arrow beneathMore, then clicks eitherUpdate, orDeleteto remove the card from the account.
ADDITIONAL INFORMATION
Customers can only add the number of cards that the merchant specified in the account configuration. The updated card information is tokenized and securely saved. The customer can use the saved card information for future transactions without having to enter that card information during the checkout process.
Selecting a Default Credit/Debit Card
When a customer has multiple cards associated with their account, they can designate the default
card. By default, the first card added to the account will be set as the default
card. In the
Cybersource
My Cards page, the default card is
identified using an asterisk (*) that appears to the right of the card number.To change the default card, the
customer follows these steps:
- OpenOpenCartFront Office.
- Open theCybersourceMy Cards page. The page displays the saved cards associated with the account.
- Choose the card to set as the default card and selectMore > SET AS DEFAULT. The card is set as the default card.
ADDITIONAL INFORMATION
The default card cannot be deleted unless all other saved cards from theCybersourceMy Cards section are deleted.
Cancelling an Order
This task describes the steps a customer takes to cancel an order. They cannot cancel
an order if the order is in review with the merchant. The Cancel option is also not
available in direct Settlement for Captured
and
orders.eCheck
- OpenOpenCartFront Office.
- SelectMy Account > Order History. The Order history page displays the customer's orders.
- Select the View icon for the order. The Order details page appears.
- Click theCancel Ordericon to cancel the order. A Cancel Order confirmation notice appears.
- ClickYeson the Cancel Order confirmation notice to cancel the order.
ADDITIONAL INFORMATION
Above the Order History, a notification appears statingSuccess: Entire order was successfully cancelled.The order is cancelled and the order status is set toCanceled.If the order was a sales transaction or was captured, the cancellation is sent to the merchant and the status is set toCanceled. After the customer cancels an order, the merchant can accept or reject the order cancellation (as instructed in Processing a Cancelled Order).If the merchant accepts the cancellation request, a refund for the order amount is initiated and the order status is set toRefunded. If the merchant rejects the cancellation request, the order status is set toDenied.
Merchant Tasks
Merchants use
OpenCart
Back Office to manage orders. This section
describes the steps to complete these tasks.Processing a Cancelled Order
When a customer cancels an order, a request is sent to the merchant and the order
status is set to
Cancelled
. Merchants can accept or reject an order that a
customer cancels.- OpenOpenCartBack Office and selectOrdersfrom the Dashboard.
- Click the box beside the order the customer cancelled.
- Click the View icon. Under Order Details, the information for that order displays.
- UnderAdd Order Status, choose the order status that describes your processing of the cancellation.
Processing a Merchandise Return
When a customer requests to return merchandise, the information appears on the
Merchandise Returns page in
OpenCart
Back Office. Follow these
steps to process the return.- OpenOpenCartBack Office and selectSales > Returns. The Product Returns page displays and identifies the order or orders for which customers have requested a return.
- Click the box beside the order that you want to process the return and then click the Edit icon. The Edit Product Return page displays.
- In the Product Information and Reason for Return pane, choose one of these options from theReturn Actiondrop-down menu:
- Credit issued
- Refunded
- Replacement Sent
The status is updated for the order on the Merchandise Returns page. Next, you can proceed with selecting a return or refund option for the order. - SelectOrdersfrom the Dashboard.
- Select the order for which you want to process a return, and select one of these options:
- Return products
- Partial refund
Fraud Management
The plugin provides fraud management functionality
for merchants who also use the
Business Center
. You can apply fraud management functionality to transactions
when:- Fraud management is enabled in the plugin.
- You have a fraud management profile in theBusiness Center.
Fraud screening includes these features:
- Fraud Management Essentials (FME):used to enforce the rules created byCybersourceMachine Learning System (MLS). Fraud management is used to define the merchant’s rules.
- Fraud Management Rules:
- When the decision status from theBusiness Centeris AUTHORIZED_PENDING_REVIEW or PENDING_REVIEW, the order is in review and the order status is set toPayment pending for review.
- When the decision status from theBusiness Centeris AUTHORIZED_RISK_DECLINED, the order is rejected and the order status is set toOrder cancelled by merchant.
The table below describes the possible decisions, outcomes, and timing Decision Manager
uses when an order is triggered for review.
When these transactions are in a Decision Manager review state,
certain settlement considerations apply:
- For authorizations:while accepting this transaction it is not recommended to settle it in theBusiness Center. When the transaction is settled in theBusiness Center, the follow-on services initiated from OpenCart Back Office are impacted.
- For sales:
- The entire authorized amount should be settled in theBusiness Centerwhen accepting the transaction. When the settlement is not performed in theBusiness Center, the follow-on services initiated from OpenCart Back Office fail.
- A follow-on void capture does not trigger from OpenCart Back Office. While accepting review transactions, merchants should not select the settle option.
Decision | Execution Timing | Outcome of Decision |
|---|---|---|
Monitor | Before authorization | Authorization will be successful and no
action from the Decision Manager is required. Use this decision to
understand the outcome of a rule. |
Accept | Before authorization | The order is processed normally and is
placed successfully. |
Review | Before authorization | The authorization is successful, and
follow-on services are put on hold until the merchant accepts or rejects
it. The order status will be set to Payment pending for review .
|
Reject | Before authorization | The order is rejected and the authorization
is not processed. The merchant is not able to view the order in OpenCart
Back Office. |
Monitor | After authorization | The authorization is successful and no
action from Decision Manager is required. Use this decision to
understand the outcome of a rule. |
Accept | After authorization | The order is processed normally and placed
successfully. |
Review | After authorization | The authorization is successful, and
follow-on services are put on hold until the merchant accepts or rejects
it. The order status is set to Payment pending for
review . |
Reject | After authorization | The original authorization is successful
and then is automatically reversed and the order status is set to
Order cancelled by merchant . |
Reporting
The plugin provides reporting functionality for merchants who also use the
Business Center
. You can import these reports from the Business Center
into OpenCart:- Transaction Request Report:includes details for individual transactions that are processed each day.
- Payment Batch Detail Report:includes transactions that are processed with the applications. This report is available shortly after captured transactions are batched.
- Conversion Detail Report:includes Case Management changes recorded in theBusiness Centerto ensure that updated orders are also included inOpenCart. This report is generated at regular intervals and includes the results of the converted orders for each reviewer. This information provides an overview of all orders that were not immediately accepted.
Scheduling
The Plugin reporting functionality works with a system scheduler to generate and
update reports for
OpenCart
. There are some Cron Job modules
available for OpenCart
, such as the Cron Tab, that support
reporting. Merchants can use any Cron Job module that OpenCart
supports, or any other online Cron service provider to generate reports. See Scheduling Report Generation for information about how to schedule
report generation.
Workflow
The reports are processed and orders are updated in
OpenCart
using this workflow: - Orders with anAUTHORIZED_PENDING_REVIEWorAUTHORIZED_RISK_DECLINEDstatus are included in theps_cybersourceofficial_ordertable in the OpenCart database.
- If a review is trigged for an order based on the profile rule in Decision Manager, aPayment pending for revieworder status displays for that order on theOpenCartBack Office Orders page.
- The merchant uses theBusiness Centerto accept the order that is in review, and, if not already enabled, enables the reports using the Report Settings on the Plugin Configuration page.
- The scheduler runs the report at regular intervals according to the intervals the merchant configured. The order is accepted or rejected by the merchant in theBusiness Center, is retrieved, and the new status is updated asAUTHORIZEDorDECLINED. The updated order status displays in theop_cybersourceofficial_ordertable in theOpenCartdatabase.
- The original decision and the new decision are updated and displayed in theop_cybersourceofficial_conversion_detail_reporttable in theOpenCartdatabase.
- The order is updated asAwaiting paymentstatus for the authorization and displayed on theOpenCartBack Office Orders page. The payment is accepted for the sale and any associated follow-on transactions (capture, void capture, refund, void refund, and full authorization reversal).
Testing
If you have not done so already, configure these settings using OpenCart Back
Office:
- General Settings:merchant ID, merchant key ID, and/or merchant secret key
- Payment Settings:applicable payment methods
After configuring the Plugin, complete this task to test the configuration using
OpenCart Front Office to place an order and OpenCart Back Office to manage the
order.
- Open OpenCart Front Office to place an order.
- At Checkout, enter any required personal information and select the payment method you want to use to place the order.
- Enter the card information you want to use to place the order and clickConfirm Order. If the order is successful, an order confirmation message displays.
- Open OpenCart Back Office to manage the order.
- SelectOrdersfrom the Dashboard. The Orders page displays and lists all active orders.
- Select the checkbox next to the order you processed in Step 1. Then click the View icon. The order status for the order should displayPending.
- ClickCaptureto capture the authorized amount, thenYes. The order status changes toProcessed.
- ClickPartial captureto capture part of the authorized amount. The order status changes toProcessing.
- ClickCancelto cancel the order. The order status changes toOrder Cancelled by Merchant.
ADDITIONAL INFORMATION
For more information about testing, including test cards, see testing-guide-v1.html
Upgrading
You can install a newer version of the plugin using
OpenCart
Back
Office.- To uninstallCybersourcePayment, navigate toExtensions > Extension Types > Paymentsand then uninstall all of theCybersourcepayment modules.
- To uninstallCybersourceTax, under the same Extension dropdown, selectOrder Totalsand uninstallCybersourceTax.
- To uninstall theCybersourcePayment extension, under the Extension dropdown, selectModules, and uninstall theCybersourcePayment extension.
- Navigate to the Extensions tab and clickInstaller, then clickDeleteto remove theCybersourceextension.
- Navigate back to the Extensions tab and clickModification, then clickRefresh.
- To install the newCybersourcePayment extension, follow the steps mentioned in Installation.
Troubleshooting Assistance
For help with troubleshooting, contact
GlobalPartnerSolutionsCS@visa.com
and
provide this information: - Summary of the issue
- Steps needed to reproduce the issue
- Platform version
- Plugin version
- Platform Merchant ID
- Configuration screenshots
- List of themes/additional extensions installed
- Log file and any other data or screenshots related to the issue
PrestaShop
The
Cybersource
extension for PrestaShop enables merchants to
accept various payment methods.The
Cybersource
extension for PrestaShop connects your PrestaShop store to the
Cybersource
Platform, enabling secure and flexible payment
acceptance.Supported Features
This is a list of payment methods and features supported by the
Cybersource
PrestaShop extension.Supported Payment Methods and Features
- Credit and debit cards
- Apple Pay
- Google Pay
- Click to Pay
- Paze
- ACH andeCheck
- PayPal
- Venmo
- 3-D SecurePayer Authentication
- Tokenization including Network Tokens
- CybersourceDecision ManagerandFraud Management Essentials
Supported Versions
This PrestaShop integration works with PrestaShop 8.1.6 to 9.1.5 and PHP 8.2+
Prerequisites
These required and optional products and configurations
must be in place for the PrestaShop extension.
Cybersource
Mandatory
This product must be enabled and configured for your
Merchant ID:
- Unified Checkout
You must also have a REST Shared Secret Key Pair and an Respone MLE Key
Optional
These products are optional. If you choose to use any of
these products, they must be enabled and configured for your Merchant ID:
- Decision Manager
- Fraud Management Essentials
- Network Tokens
As of version 8.0.0, accepted card brands, payment methods, Payer Authentication for
3-D Secure
, fraud screening, and payment action is configured and
enabled in the Business Center
. For more information,
see the
Unified Checkout Developer
Guide
.Mandatory Environment Prerequisite
The GMP PHP extension must be enabled on your MAMP or XAMPP server for JSON Web Token messaging.
Release Notes
Version history and release notes for the
Cybersource
PrestaShop extension.Version 8.0.0
Enhancements:
- Migrated to Unified Checkout v1.x including Unified Checkout becoming responsible for calling Payer Authentication, Tokenization, and fraud screening.
- Offer Sidebar and Embedded display for Unified Checkout widget
- Added webhook support for payment response and fraud management
- Support for Network Tokens
- Support for PayPal and Venmo
- ACH/eCheck reintroduced
- Full Message Level Encryption
- Configuration UI updated
Version 7.1.0
Enhancements:
- PrestaShop 9.0.3 support
- Unified Checkout v0.34
- Cybersource SDK v0.0.71
- Migrated authorization API calls for Unified Checkout (complete mandate)
- eCheck support temporarily removed
- Updated endpoints from cybersource.com to visaacceptance.com
- Support for Cardinal Commerce Data Center migration
- Card payments enabled by default
- Address form displayed before Unified Checkout is loaded for 'My Cards'
- Implemented Microform for securly capturing CVV for payments with saved card
- Back office UI updates
- Display of additional response fields
Version 7.0.0
Enhancements:
- PrestaShop 9 support
- Hummingbird Theme compatibility
- Replaced Microform with Unified Checkout
- Unified Checkout now includes Apple Pay, Click to Pay, Google Pay, ACH, and eCheck; individual components were removed.
- Removed Latin America processing logic.
Version 6.3.1
Enhancements:
- PrestaShop 8.2.3 support
Bug Fixes:
- Installation error
Version 6.3.0
Enhancements:
- Message Level Encryption
- Removed CVV capture for saved card transactions.
- PrestaShop 8.2.1 support
- Ended support for PrestaShop 1.7.x.
Version 6.2.1
Enhancements:
- Ability to override PrestaShop order status when authorization response is AVS FAILED
Version 6.2.0
Enhancements:
- Extended support to PrestaShop version 8.2.0
- Microform version 2 upgrade
- Compatible with PrestaShop versions 1.7.6.0–1.7.8.11 and versions 8.0.4–8.2.0
Version 6.1.0
Enhancements:
- Extended support to DMPA
- Extended support to PrestaShop version 8.1.7
- Added Payer Auth mandate fields
- PSID updated
Version 5.1.0
Enhancements:
- Extended support to PrestaShop versions 1.7.6.0–1.7.8.11 and up to 8.1.4
- Network tokens implemented
- 3DS Firefox browser cookie issue resolved
- PSID updated
Version 4.2.0
Enhancements:
- Cybersource authentication signature updated
- Compatible with PrestaShop versions 1.7.6.0–1.7.8.10
Version 4.1.0
Enhancements:
- Installment payment options for customers in Mexico, Brazil, Colombia, Chile, and Peru. This feature enables customers to conveniently split their payments into installments.
- Grace period payment options for customers in Mexico. This feature enables customers to delay a payment for a specified period after making a purchase.
- Expanded card payment services, which include credit and debit card options. This feature enables customers to securely make payments using their preferred card type.
Version 3.1.0
Enhancements:
- Added backward compatibility with Multiple PrestaShop versions(1.7.0.6 to 1.7.8.7).
- Implemented Strong Customer Authentication(SCA) in PrestaShop Versions.
- Line-Item details have been added for Refund service for all payment methods.
Version 2.1.0
Enhancements:
- Added eCheck support
- Fraud Management feature enhanced with "Rejected due to fraud check" new status is added
- In Fraud Management Post Auth Reject by profile scenario, automatic auth reversal will be triggered.
Version 1.1.3
Enhancements:
- Fraud management enhanced with Rate Limiter feature.
Version 1.1.2
Enhancements:
- 3DS production/test URL switch logic updated.
Version 1.1.1
Enhancements:
- Query conflict issue noticed in few themes is fixed
- Lines items added for authorization reversal service
- For capture service, tax amount for line item are passed separately.
Version 1.1.0
Enhancements:
- Integrated Apple Pay payment method
- Visa SRC is re-branded as Click to Pay.
Version 1.0.5
Enhancements:
- BO configuration features added:
- Hide/Show icon added for all the important keys
- Configurable Merchant Name and Merchant Id added for Google Pay
- Tokenization feature is enhanced with enable/disable option
- Supported countries URL added for Google Pay and Visa SRC tooltip
- Description added about reporting service
Version 1.0.4
Enhancements:
- SandBox/Production report save path configuration provided.
- Module display name is updated to Cybersource Official.
- .
Version 1.0.3
Enhancements:
- Back Office Add-on configurations enhanced with toggle feature
- Retry payment feature provided for failed transaction
- Latest jQuery(3.6.0) referenced instead of embedding for better integration
- Clickable tooltip added
Version 1.0.2
Enhancements:
- multiple changes made to the configuration screens in order to simplify the merchant onboarding journey.
Bug Fixes:
- Merchants could not switch to test system after release to 1.0.1 so this was required to be changed.
Version 1.0.1
Enhancements:
- Security Audit and internal review comments fixes
- Additional functionality like 3DS added
- Alternative solutions added for PrestaShop limitation/issues.
Version 1.0.0
Enhancements:
- Initial release.
Install PrestaShop
Install the extension for PrestaShop
from the marketplace.
Cybersource
OfficialFollow these steps to install the extension for PrestaShop.
Cybersource
Official Plugin- Go to the PrestaShop Marketplace and download the extension.
- Log in to your PrestaShop back office.
- Go to .
- Upload the module downloaded from the marketplace.
Configure PrestaShop
This is the complete configuration guide for the
Cybersource
PrestaShop extension.To configure the
Cybersource
extension for
PrestaShop, go to Modules > Module Manager
. Scroll down to
Cybersource
Official and click
Configure
.Click
Save
after you configure each tab.General Settings Tab
- Checkout Label: This text is displayed on your checkout page to your customers.
- Sandbox Mode:
- Yes: Choose for testing yourtest account.Cybersource
- No: Choose for live transactions.
- Merchant ID: The transacting Merchant ID (MID) thatassigned to you.Cybersource
- Merchant Key ID: The Key from your REST API Shared Secret Key.
- Merchant Secret Key: The Shared Secret from your REST API Shared Secret Key.
- Key File Path: Enter the path and filename for the Response MLE certificate created inBusiness Center
- Key Password: Enter the password for the Response MLE certificate
- Checkout Version: Optional field to force a version of Unified Checkout. Format 1.x. It is recommended to leave this blank to always take the latest version.
- Display Mode:
- Embedded: The payment widget loads within the browser page
- Sidebar: The payment widget appears to the side of the browser
- Tokenization:Set toYesto enable your customers to save their cards for future purposes.
- Network Tokens:If youraccount is enabled for Network Tokens, set toCybersourceYesto inform the module it needs to manage token lifecycle updates.
- Fraud Management:Set toYesto inform the module that yourCybersourceaccount is configured for fraud screening and needs to subscribe to the REVIEW webhook notification.
In Sale mode, if an authorization
returns an
AVS Failed
error, you will need to manually review
the transaction and decide whether to cancel or accept the transaction. If you
decide to accept the transaction, you will need to manually capture the
transaction.- Enhanced Logs: To generate logs that can be accessed from , set toYes. This feature is not recommended for Production (live) mode.
Report Settings Tab
- Transaction Request Report: When enabled, the extension downloads a report fromCybersourcecontaining details for transactions processed each day. Set toYesto enable.
- Payment Batch Detail Report: When enabled, the extension downloads a report fromCybersourcecontaining details of all captures and refunds that were submitted to your payment processor. Set toYesto enable.
For all reports, it is strongly recommended that your PrestaShop store and the
Cybersource
Business Center
user profile operate in the same time zone.Report download locations:
- In test mode:{PrestaShopModuleInstallationDirectory}/cybersourceofficial/Reports/Sandbox
- In production (live) mode:{PrestaShopModuleInstallationDirectory}/cybersourceofficial/Reports/Production
Registered Webhooks Tab
View information about subscribed webhooks. They can be deleted but this may affect
transaction response handling. Webhooks are automatically subscribed to based on
your configuration settings
Order Management
This topic explains how to manage orders including captures, refunds, and voids in
the PrestaShop extension.
Orders are marked differently depending on the
Unified Checkout
payment
processing choice.- For Authorize, orders are marked asAwaiting Payment.
- For Sale, orders are marked asPayment accepted.
Fraud Screening
When fraud screening is enabled, transactions are marked based on the
Unified Checkout
payment processing choice:- Approved orders are marked asAwaiting PaymentorPayment accepted(depending on your payment processing choice).
- Orders to review are marked asPayment pending for review.
- Rejected orders are marked asOrder cancelled by merchant.
Orders marked as extension will
receive webhook notifications advising of your decision. Rejected transactions are
marked as
Payment pending for review
must be reviewed in the Business Center
. The Cybersource
Order cancelled by merchant
.Accepted transactions are marked according to your payment processing choice.
Capture
Open the order from the order list and choose one of these options:
- Partial Capture: Select the items to capture and then clickPartial Capture. The order is marked asPartial payment accepted.
- Standard Capture: Captures the entire order and marks the order asPayment accepted.
Refund
Orders can be refunded only if they are marked as
Payment accepted
or
Partial payment
accepted.- To refund the entire order, clickStandard Refund.
- To refund part of the order, clickPartial Refund, choose the item(s) to refund, and then clickPartial Refund.
Void
- For an order that was not captured, clickCancel products, choose the item(s) to cancel, then clickCancel products. This action reverses the authorization.
- For an order that was captured, clickVoid capture.
- For an order that was refunded, clickVoid refund.
Support and Troubleshooting
Information about getting support and troubleshooting common issues with the PrestaShop extension.
Cybersource
Support
If you require support with this extension, visit support.visaacceptance.com to
raise a support case. For resold accounts, contact your reseller.
For the support case, provide this information:
- Summary of issue
- Steps to reproduce the issue
- PrestaShop version
- Extension versionCybersource
- merchant IDCybersource
- Configuration screenshots
- List of the additional themes and extensions installed
- Log file
- Any additional information related to the issue
FAQ
PrestaShop Language Pack Installation Error
When you get a
Cannot download language pack
error message while
installing the extension, follow these steps:- Go to/htdocs/PrestaShop root/Classesand opentools.php.
- Search forcurl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);.
- Changefalsetotrue.
- Save the file.
- Reload your browser and attempt installation again.
Upgrade
To upgrade to the latest version of the PrestaShop extension, go to
and click
Modules
> Module Manager
>
Cybersource
OfficialUpgrade
.Appendix
This is additional information about report scheduling for the
Cybersource Official Plugin
Prestashop extension.Report Scheduling
Schedulers for Linux and Mac systems are set up using a Cron Tab. The scheduler for a
Windows system is configured using the Windows Task Scheduler app.
When configuring a schedule for generating a specific report, use this format:
Format:
<shop domain
name>/module/cybersourceofficial/paymentReport
Example:
https://www.prestashop_8.2.2.com/module/cybersourceofficial/paymentReport
Cron Tab Syntax for Mac and Linux Systems
When setting up the reporting schedule on Linux or Mac, use crontab commands to
determine how often and when the report is generated.
The syntax is:
* * * * * [command]
Each asterisk (*) represents one of the timing parameters:
- Minute (0-59)
- Hour (0-23)
- Day of Month (1-31)
- Month (1-12)
- Day of week (0-6) 0 = Sunday
Cron Scheduler Setup
- Open a Linux or Mac terminal.
- Entercrontab-eto enter editor mode.
- Enter the command to set the timing for the cron job.
- For example, for 15-minute intervals:15 * * * * curlhttps://www.prestashop_8.2.2.com/module/cybersourceofficial/paymentReport
- Close the editor.
- Entercrontab -lto check the scheduled cron job.
Windows Task Scheduler
- Open Task Scheduler and clickCreate Task.
- Select the General tab and enter a name.
- Select the Triggers tab and clickNew.
- Enter the desired timings and clickOK.
- Select the Actions tab in the Create Task pane and clickNew.
- Enter this information into these fields and then clickOK.
- Action:Start a program
- Program/script:curl
- Add arguments (optional): Enter the reporting URL.
Salesforce B2C Commerce
Salesforce
B2C CommerceThe cartridge for
Salesforce
B2C
Commerce enables merchants to connect their Salesforce
B2C Commerce
store to the our platform
for payment processing.Supported Features
The cartridge for
Salesforce
B2C Commerce supports
multiple payment methods and features.Payment Methods
Through
Unified Checkout
, a single integration supports the following
payment methods- Credit/debit cards
- Apple Pay
- Google Pay
- Paze
- PayPal
- Venmo
- Click to Pay
- eCheck
Through the default Salesforce payment form calling API's directly,
the following payment methods are supported:
- Credit/debit cards
- Apple Pay
Security and Fraud Management
- Payer Authentication/3-D Secure
- Token Management Service
- Decision ManagerandFraud Management Essentials
Additional Services
- Delivery Address Verification
- Tax Calculation
- Meta-key
Methods are also exposed to process authorization reversal, capture, and refund.
Supported Versions
The cartridge is compatible with specific versions of
Salesforce
Storefront Reference Architecture (SFRA).Compatibility
The cartridge is compatible with
Salesforce
SFRA version 7.0 and earlier.Cybersource Prerequisites
Cybersource
PrerequisitesBefore implementing the cartridge, ensure that you have the required
and optional
Cybersource
products configured.Mandatory
This product must be enabled and configured for your Merchant ID:
- Unified Checkout
You must also have a REST Shared Secret Key Pair and an Respone MLE Key
Optional
These products are optional. If you choose to use any of these products, they must be
enabled and configured for your Merchant ID:
- Decision Manager
- Fraud Management Essentials
- Network Tokens
As of version 2.0.0, accepted card brands, payment methods, Payer Authentication for
3-D Secure
, fraud screening, and payment action is configured and
enabled in the Business Center
. For more information,
see the .
Unified Checkout
Configuration
GuideRelease Notes
Release history and updates for the Visa Acceptance
Salesforce
B2C Commerce cartridge.Version 2.0.0 (September 2026)
Versioning changed from Calendar Versionion to Semantic Versioning
Enhancements:
- Renamed integration from Cybersource to Visa Acceptance Solutions
- UpgradedUnified Checkoutto version 1.x, supporting multiple payment methods and services in a single integration
- Added Refund function
- Added webhook notifications for Fraud Screening andUnified Checkoutevents
- Added new Business Manager cartridgebm_cybs_sfra, including webhook manager page.
- Reorganised meta and site preference groupings
- Updated the authentication method to JSON web token
- Full support for Message Level Encryption
- Adjust Payer Authentication setup and Device Data Collection trigger (Direct API only)
Changes:
- Business Manager controls for Payer Authentication (including SCA), Decision Manager, and Transaction Type now only applies to the Salesforce default card form (direct API).
- Unified Checkoutpayment methods/services now configured inBusiness Center
- Google Pay now only supported throughUnified Checkout
- Replaced Network Token lifecycle notifications with API based updates
- Added webhook notifications for Fraud Screening and Unified Checkout events
- Replaced Network Token lifecycle notifications with API based updates
Security:
- Addressed security issues
Removed:
- Microform
Bug Fix:
- Added Device Data Collection timeout handling
Version 26.2.0 (March 2026)
Enhancements:
- Updated Payer Authentication flow to align with SFRA best practices
- Added fallback device data capture for Payer Authentication
- Updated Mastercard3-D SecureData Only transactions
- Updated Cardinal Commerce URLs for Data Center Migration
- Modified subscription creation during the authorization call in checkout
- Decision Manager support for Apple Pay Transactions
- Apple Pay address handling improvements
- Checkout page: collect address from checkout page
- Cart/Mini Cart page: collect address from Apple Pay
Bug Fixes:
- Corrected page routing for failed Apple Pay scenarios
- Fetch the total amount from the server side instead of capturing it on the frontend to avoid issues for different currencies across different locales
- Correct handling of AUTHORIZED_RISK_DECLINED response for post authorization scenarios
- CheckoutServices Error Fix: Resolved TypeError occurring when the cartridge is disabled
- Fixed issue where the Unified Checkout capture context did not refresh when the Delivery Address Verification is enabled
- Corrected page redirection issue for Decision Manager reject scenarios
- Fixed bug causing "setAddress1" of null when performing follow‑up transactions with a registered customer after updating shipping address.
- Fixed issue where the eCheck transient token exceeded the session.privacy 2000‑character limit
Version 26.1.0 (January 2026)
New Feature:
- Added support for3-D SecureData Only transactions.
Version 25.4.0 (December 2025)
New Feature:
- Added support forUnified Checkoutv0.32 (Card Payments, Apple Pay, Google Pay,Click to Pay, andeCheck).
Enhancement:
- End of support forClick to Paylegacy.
Version 25.3.0 (May 2025)
New Features:
- AddedPayer Authenticationsupport for Google Pay.
- Added multi-currency support for Google Pay.
Bug Fixes:
- Handled session variables in SCA flow.
- Removed encryption type from Microform v2 request.
Version 25.2.0 (March 2025)
New Feature:
- Message-Level Encryption (MLE).
Enhancement:
- Added support for Cartes Bancaires, Elo, China UnionPay, and JCB.
Version 25.1.0 (January 2025)
New Feature:
- Replaced Microform v0.11 with v2.
Bug Fixes:
- Added webhook subscription deletion if the subscription is deleted atCybersourceorSalesforcecustom object.
- Handled undefined exception scenario for3-D Securetransactions.
Version 24.4.0 (September 2024)
New Feature:
- DMPA support.
Enhancement:
- Upgraded to jQuery v3.7.0.
Version 24.3.0 (August 2024)
Enhancements:
- Upgraded the cartridge to support SFRA v7.0.
- Added MOTO Commerce Indicator.
Version 24.2.1 (May 2024)
Bug Fixes:
- Checkmarx issues fixed.
- Device fingerprint bug fixed.
Version 24.2.0 (April 2024)
New Features:
- Network token support
Enhancements:
- Implemented Direct API integration forPayer Authentication, adding Payer Authentication Setup and Device Data Collection.
- Enhanced Strong Consumer Authentication (SCA).
Version 24.1.0 (February 2024)
New Features:
- Added Strong Customer Authentication retries for card payments.
Enhancements:
- SFRA v6.3 support.
- SalesforceB2C Commerce Release 22.7 support.
- Renamed Visa SRC toClick to Pay.
- Implemented Sale functionality for Credit Card, Google Pay,Click to Payand Apple Pay.
- Updated flex script referring from v0.11.0 to v0.11.
- Updated API header in Http Signature Authentication.
Version 21.1.0 (June 2021)
Enhancements:
- ImprovedPayer Authenticationscreen (modal).
Bug Fixes:
- Added descriptive error messages on certain fail cases and invalid inputs.
- Reloading on the final confirmation page does not result in a failed authorization.
Version 20.2.0 (February 2021)
New Features:
- Google Pay
- Visa Secure Remote Commerce payment method
- Improved the security on the My Account page by adding Microform to tokenize payment cards.
Bug Fixes:
- Improved the security of keys by changing data type of password fields fromStringtopassword.
- Added more security to the exposed parameters of device fingerprint.
Version 20.1.1 (November 2020)
Bug Fixes:
- Improved the security on accessing and modifying sensitive fulfillment-related actions on an order (for example, order acceptance, canceling etc.).
Version 20.1.0 (August 2020)
Initial release supporting:
- Credit/debit cards
- Apple Pay
- Payer Authentication/3-D Secure
- Delivery Address Verification service
- Tax Calculation service
- Authorization, Capture, Authorization Reversal
Install Salesforce B2C Commerce
Salesforce
B2C CommerceDownload and install the cartridge for
Salesforce
B2C Commerce.Before beginning installation, ensure that you have:
- Access to yourSalesforceB2C Commerce instance.
- Node.js installed on your development machine.
- Appropriate IDE, such as VSCode with the Prophet Debugger extension.
- Download the cartridge forSalesforceB2C Commerce from the ISV Integration Toolkits section on GitHub.
- Set up your workspace by creating a folder namedin yourCybersourceSalesforceworkspace and copy the downloaded cartridges,int_cybs_sfra,int_cybs_sfra_base, andbm_cybs_sfrato the workspace.
ADDITIONAL INFORMATION
If the project's base path is different from the one available inpackage.json, open the file/package.jsonand modify thepaths.basevalue to point to yourapp_storefront_basecartridge. This path is used by the JS and SCSS build scripts. - Configure the IDE.
ADDITIONAL INFORMATION
If you use VSCode, install the Prophet Debugger extension and include these lines indw.json:ADDITIONAL INFORMATION
{ "hostname": "your-sandbox-hostname.demandware.net", "username": "yourlogin", "password": "yourpwd", "version": "version_to_upload_to", "cartridge": [ "int_cybs_sfra", "int_cybs_sfra_base", "bm_cybs_sfra", "app_storefront_base", "modules" ] }ADDITIONAL INFORMATION
If you are using a different IDE, refer to the respective guide to set up your workspace.
RESULT
Build and Upload Code
- Install the Node.js dependencies in theCybersourcefolder.
- Installsgmf-scriptsandcopy-webpack-pluginwith this command:npm install sgmf-scripts && npm install copy-webpack-plugin
- Compile JS and SCSS with this command:npm run compile:js && npm run compile:scss
- Upload the code to theSalesforceCommerce Cloud instance:npm run uploadCartridge
The cartridge is now installed and ready for configuration in your
Salesforce
B2C Commerce environment.Configure for Salesforce B2C Commerce
Configure the cartridge in the
Salesforce
B2C Commerce Business Manager.After installation, configure the cartridge through the
Salesforce
Business Manager to enable payment processing
capabilities.- Base Configuration
- Set up the cartridge path inSalesforceBusiness Manager by going to .
Step Result
For Cartridges, enterbm_cybs_sfra:int_cybs_sfra:int_cybs_sfra_base:app_storefront_baseand clickApply. - Upload Metadata
- Go to the folder.Cybersource/metadata/payments_metadata/sites/
- Rename the folderyourSiteIDwith your site ID fromSalesforceBusiness Manager.
ADDITIONAL INFORMATION
This can be found by going to . - Zip thepayments_metadatafolder.
- Go to and upload thepayments_metadata.zipfile.
- Import the uploaded zip file.
Step Result
Upon successful import, this metadata is created:- Site Preferences: VisaAcceptance_Core, VisaAcceptance_SecureIntegrationConfiguration, VisaAcceptance_SalesforceDefaultAcceptance_Configuration, VisaAcceptance_ApplePay, VisaAcceptance_Tokenization, VisaAcceptance_DeviceFingerprint, VisaAcceptance_DeliveryAddressVerification, VisaAcceptance_TaxConfiguration, VisaAcceptance_MLE
- Service: PaymentHttpService
- Payment Processor
- Payment Method
- Jobs: Payment : Decision Manager Order Update, Payment: Refresh Payment Status
- As of version 2.0.0, Payer Authentication (including SCA), Decision Manager, and Transaction Type are now grouped under Salesforce Default Acceptance Configuration, and apply to the Salesforce default card form (Direct API) only. Standalone Google Pay preferences have been removed.Minimum Configuration
- Configure the Visa Acceptance Core preferences by going to and setting these configuration parameters:
ADDITIONAL INFORMATION
- Enable Visa Acceptance Cartridge: Enable the cartridge.
- : The transacting Merchant ID assigned to you.CybersourceMerchant ID
- : The key from your REST API shared secret key.CybersourceREST KeyId
- : The shared secret from your REST API shared secret key.CybersourceREST Secret Key
- Commerce Indicator:
- For eCommerce transactions, useinternet.
- When you are using the store for call center transactions only, useMOTO.
- Enable Visa Acceptance Test Endpoints: Disabled by default. This enables the capture and authorization reversal endpoints (ServiceFrameworkTestcontroller). Use only in a sandbox environment.
- Enable Meta Key: Enable Meta Key for portfolio/account-level key management(optional).
- Meta Key Portfolio Merchant ID: TheCybersourceportfolio/account Merchant ID that owns the Meta Key(optional).
- ServicesThe target endpoints need to be set in yourSalesforceB2C Commerce environment.
- Configure the services by going to and enter the following URLs:
ADDITIONAL INFORMATION
- Environment: TestURL: https://apitest.visaacceptance.com
- Environment: ProductionURL: https://api.visaacceptance.com
- Payment Capture Method
- Go to , selectCREDIT_CARD, and verify that the payment processor isPAYMENTS_CREDIT.
- Go to .
ADDITIONAL INFORMATION
Choose fromADDITIONAL INFORMATION
- Unified Checkout
- Direct API (default Salesforce payment form)
ADDITIONAL INFORMATION
Unified Checkoutmight qualify you for PCI-DSS SAQ:A because the card number is collected in secure fields and never resides on your server.If you need access to the card number, selectDirect API. This option increases your PCI burden.If you select Unified Checkout, please see Unified Checkout Configuration
RESULT
The cartridge is now configured with basic settings.
Digital Payment Methods
Apple Pay and Google Pay can be standalone options, or they can be offered as payment
options with
Click to Pay
within Unified Checkout
.You can configure digital payment methods in two ways:
Unified Checkout
or as standalone options.- To configureUnified Checkout, go to .
- In theDigital Payment Methods infield, select Apple Pay, Google Pay, orUnified CheckoutClick to Pay. You can choose any or all of the options.
ADDITIONAL INFORMATION
If you are usingUnified Checkoutfor digital payment methods, the payment methods must be enabled for your Merchant ID inBusiness Center. For more information about enabling digital payments, see Enable Digital Payments. - EnableUnified Checkoutfor Cart and Mini Cart: Enable this option to display digital payment methods for quick checkout on the cart and mini cart pages.
- Go to and confirm that these options are enabled for the methods you accept:
ADDITIONAL INFORMATION
- DW_APPLE_PAY: Verify that the Payment Processor isPAYMENTS_APPLEPAY.
- DW_GOOGLE_PAY: Verify that the Payment Processor isPAYMENTS_CREDIT.
- CLICK_TO_PAY: Verify that the Payment Processor isPAYMENTS_CLICK_TO_PAY.
Apple Pay Standalone Configuration
To offer Apple Pay outside of
Unified Checkout
, follow these steps to enable Apple Pay in your Salesforce
B2C Commerce store.Follow the steps documented here first, before you follow this
procedure to enable Apple Pay in your
Salesforce
B2C Commerce
store.- SalesforceBusiness Manager Configuration
- Go to: .
- CheckApple Pay Enabled?
- Complete the "Onboarding" form:
ADDITIONAL INFORMATION
- Ensure the Apple Merchant ID and the Apple Merchant Name values you enter match the settings in your Apple account.
- Ensure all other fields match your supportedCybersourcesettings.
- Country Code: Enter the country code for the location of your site. The country code is a two letter ISO 3166 country code (for example,US).
- Merchant Capabilities: Check the box for 3-D Secure, leave the other fields unchecked.
- Supported Networks: Select the types of payment you support:Amex,Mastercard, andVisaare supported byCybersource.
- Required Shipping Address Fields: Select the fields that are required on the shipping form.CybersourcerecommendsEmail,Name,Phone, andPostal Address.
- Required Billing Address Fields: SelectNameandPostal Address.
- Fill in the Storefront Injection form:
ADDITIONAL INFORMATION
Select where to display Apple Pay buttons on your site. - Fill in the Payment Integration form:
ADDITIONAL INFORMATION
- Use Commerce Cloud Apple Pay Payment API?Checked
- Payment Provider URL:
- Test: https://apitest.cybersource.com/partner/demandware/payments/v1/authorizations
- Production: https://api.cybersource.com/partner/demandware/payments/v1/authorizations
- Payment Provider Merchant ID: Enter yourCybersourcemerchant ID.
- API Version: v1
- Use Basic Authorization?Unchecked
- Payment Provider User: Not Applicable
- Payment Provider Password: Not Applicable
- Use JWS?== Yes
- JWS Private Key Alias: Merchant.p12 Key Alias
Step Result
The private key alias is created when a merchant uploads their .p12 key file (fromCybersourceself-serve) to Commerce Cloud'sSalesforceBusiness Manager Module, Private Keys and Certificates () - ClickSubmit.
- Domain Registration inSalesforceBusiness Manager
- Go to .
- Under Domain Registration section
ADDITIONAL INFORMATION
- In the Apple Sandbox section, clickRegister Apple Sandboxto registerSalesforceB2C to the Apple Sandbox account.
- In the Apple Production section, click onRegister Apple Productionto registerSalesforceB2C to the Apple Production account.
- Transaction Type
ADDITIONAL INFORMATION
Go to and chooseAuthorizationorSale.
Google Pay Standalone Configuration
To offer Google Pay outside of
Unified Checkout
, follow these steps to enable Google Pay in your Salesforce
B2C Commerce store.- Go to .
- Configure Google Pay settings:
- Enable Google Pay: Enable.
- Enable Google Pay on Mini Cart: Enable to show Google Pay as a checkout option in the mini cart.
- Enable Google Pay on Cart: Enable to show Google Pay as a checkout option in the cart.
- Google Pay Merchant Id: Enter your Google Pay merchant ID (for live processing only).
- Google Pay Environment: ChooseTestfor testing andProductionfor live.
- Google Pay Transaction Type: ChooseAuthorizationorSale.
Alternative Payment Methods
Configure alternative payment methods such as
eCheck
for your
Salesforce
B2C Commerce store. Follow this procedure to enable
eCheck
as a payment option within Unified Checkout
.- Go to
- Set theEnableoption toeCheckYes.
- Go to and confirm that the payment processor is set toBANK_TRANSFER.
Payer Authentication and 3-D Secure
Payer Authentication
and 3-D Secure
Configure
Payer Authentication
and 3-D Secure
for enhanced
transaction security.- Go to .
- InMode, choose one of these options:Payer Authentication
ADDITIONAL INFORMATION
- Yes: All transactions will process with3-D Secure.
- No: No transactions will process with3-D Secure.
- Data Only + Yes: Data Only will be used for Visa and Mastercard/Maestro. All other card brands will process with3-D Secure.
- Data Only + No: Data Only will be used for Visa and Mastercard/Maestro. All other card brands will process without3-D Secure.
- IsSCAEnabled: Enable this option to enforce Strong Consumer Authentication (3-D SecureChallenge) when a customer is saving their payment card for future transactions.
Tokenization
Tokenization enables your customers to save their payment cards securely for future
payments.
- To enable tokenization, go to .
- Enable theEnable Tokenization Servicesoption to turn on Tokenization.
- Enable the option to set the limits associated to saving cards.
- In theSaved Cards Allowedoption, enter the number of cards a customer can save in the defined time limit.
- In theReset Intervaloption, specify the number of hours before the saved card limit resets.
- Enable theNetwork Token Updatesoption to prompt the cartridge to subscribe for Token Life Cycle Updates webhooks when yourCybersourceMID is configured for network tokens.
- Go to and verify that the custom object type Network Tokens Webhook exists.
Fraud Screening
Enabling Fraud Screening alerts the cartridge to look for fraud screening responses.
Fraud Screening profiles must be set up in the
Business Center
.- Go to and set these options:
- Enable theEnableoption.Decision ManagerServices
- Conversion Detail Report Lookback Time: If you are using REVIEW rules and configure theDecision ManagerUpdate Job, set the number of hours to look back for updates to transactions in REVIEW status. The maximum is 24 hours.
- To enable theDecision ManagerUpdate Job to poll for updates to the reviewed transactions, go to and selectPayment:and set these values:Decision ManagerOrder Update
ADDITIONAL INFORMATION
- ID: Enter a job ID.
- Description: Enter the job description.
- ExecuteScriptModule.Module: int_cybs_sfra_base/cartridge/scripts/jobs/DMOrderStatusUpdate.js
- ExecuteScriptModule.FunctionName: orderStatusUpdate
- ExecuteScriptModule.Transactional:
- True: All changes occur as a single atomic operation. If any error occurs during the job, the system rolls back all changes to maintain data consistency.
- False: No automatic rollback is applied. Merchants must handle transaction logic manually. This is often preferred for large batch jobs.
- ExecuteScriptModule.TimeoutInSeconds: Set the function timeout value.
Device FingerPrint
Device FingerPrinting collects information about the device used when paying for an order and can assist in fraud screening decisions.
- Go to .
- Enable theEnable DeviceFingerprint Serviceoption.
- In theOrganization IDfield, enter the Organization ID. Contact support if you do not know this value.
- In theThreatMetrix URLfield, enter the URL that points to the JavaScript that generates and retrieves the fingerprint of the device.
- In theTTL (Time to Live)field, enter how many milliseconds to wait before generating a new fingerprint for any given customer session.
Delivery Address Verification
To verify the customers shipping address during checkout, configure Delivery Address
Verification services.
- Go to .
- Enable theDelivery Address Verification Servicesoption.
Tax Calculation
To calculate local taxes once the customer enters their address at checkout,
configure the Tax Calculation services.
- Go to and set these options:
- Enable theEnable Tax Calculationfield.
- Configure these tax settings:
ADDITIONAL INFORMATION
- List of Nexus States: List the states to calculate tax for.
- List of Nexus States to Exclude: List the states to not calculate tax for.
- Merchants VAT Registration Number: Enter your VAT registration number if you have one.
- Default Product Tax Code: Enter the default tax code to use for products in the basket without a tax code.
- Purchase Order Acceptance City
- Purchase Order Acceptance State Code
- Purchase Order Acceptance Zip Code
- Purchase Order Acceptance Country Code
- Purchase Order Origin City
- Purchase Order Origin State Code
- Purchase Order Origin Zip Code
- Purchase Order Origin Country Code
- Ship From City
- Ship From State Code
- Ship From Zip Code
- Ship From Country Code
RESULT
If you enable Tax Calculation and do not specify any states in
List of Nexus States or List of Nexus States to Exclude, Tax Calculation assumes
every state or province is taxable. You can leave either the
List of
Nexus States
or the List of Nexus States to
Exclude
as empty, but both cannot be empty.Message Level Encryption
Message Level Encryption (MLE) uses certificates to ensure each message is securely
encrypted and tied to the sender's verified identity, without needing to share secret keys
in advance.
MLE provides stronger authentication, easier key management, and better protection
against fraud or tampering.
A shared secret uses the same key for both sending and receiving messages, meaning
both parties must securely exchange and protect that key in advance. While MLE can
be simpler, it offers less identity verification and can be more vulnerable if the
key is compromised.
Message Level Encryption requires that
a .p12 certificate to be created.
- Extract and convert the p12 certificate to the .pemformat using this command:openssl pkcs12 -in <key filename>.p12 -cacerts -nokeys -out <key filename>.crtBe sure to note the serial number of theCybersource_SJC_US certificate.
- Import the certificate, by going to and importing the extracted.crt. Make a note of the alias.
- Enable Message Level Encryption, by going to .
- Enable theEnable Message-Level Encryptionoption.
- In theAlias of the Certificatefield, enter the Alias from when the certificate was imported.
- In theCertificate Serial Numberfield, enter the serial number from theCybersource_SJC_US certificate.
Order Management
Salesforce
B2C Commerce does not natively support order management functions. This cartridge has functions that can be used to process captures and authorization reversals.These functions must be customized before use in the
Salesforce
B2C Commerce user interface.The ServiceFrameworkTest example controllers referenced below are for testing
only. Access is granted only when
all
of the following are true:- The Salesforce instance isnota production instance.
- TheEnable Visa Acceptance Test Endpointspreference (Custom Preferences > Visa Acceptance Cartridge configuration) is enabled. It is disabled by default.
- The caller is anauthenticated, registered customerwho is a member of theVisaAcceptanceTestAdmincustomer group
The VisaAcceptanceTestAdmin customer group is not created by the metadata import — you
must create it in Business Manager under
Merchant Tools > Customers > Customer
Groups
and assign it only to authorized merchant staff. Only members of this
group can access the test endpoints; any request from a non-member (or an
unauthenticated visitor) is redirected to the home page.Capture
The capture function can be found in the script
scripts/http/capture.js
. A
working example is available in the ServiceFrameworkTest-TestCaptureService
controller.Reference the capture.js object and make this request:
var captureObj = require("~/cartridge/scripts/http/capture.js"); var serviceResponse = captureObj.httpCapturePayment(requestID, merchantRefCode, paymentTotal, currency);
The resulting serviceResponse object contains the full response object generated by
the request. The contents of this object determine your logic in handling errors and
successes. These are the Capture request parameters:
Capture Request Parameters:
- requestID: TheCybersourceRequest ID from the initial authorization.
- merchantRefCode: TheSalesforceOrder Number.
- purchaseTotal: The capture amount.
- currency: Currency Code.
Function Signature:
httpCapturePayment(requestID, merchantRefCode, purchaseTotal, currency)
Authorization Reversal
The authorization reversal function can be found in the script called
scripts/http/authReversal.js
. A working example is in the
ServiceFrameworkTest-TestAuthReversal controller.Reference the AuthReversal.js object and make this request:
var reversalObj = require("~/cartridge/scripts/http/authReversal.js"); var serviceResponse = reversalObj.httpAuthReversal(requestID, merchantRefCode, paymentTotal, currency);
The resulting serviceResponse object contains the full response object generated by
the request. The contents of this object determine your logic in handling errors and
successes. These are the Authorization reversal request parameters:
Authorization Reversal Request Parameters:
- requestID: TheCybersourceRequest ID from the initial authorization.
- merchantRefCode: TheSalesforceOrder Number.
- purchaseTotal: The reversal amount.
- currency: Currency Code.
Refund
The refund function can be found in the script called
scripts/http/refund.js
.
A working example is in the ServiceFrameworkTest-RefundService controller.Reference the refund.js object and make this request:
var refundObj = require("~/cartridge/scripts/http/refund.js"); var serviceResponse = refundObj.httpRefundPayment(transactionId, merchantRefCode, paymentTotal, currency, refundEndpointType);
The resulting serviceResponse object contains the full response object generated by
the request. The contents of this object determine your logic in handling errors and
successes. These are the Authorization reversal request parameters:
Authorization Reversal Request Parameters:
- requestID: TheCybersourceRequest ID from the capture or sale.
- merchantRefCode: TheSalesforceOrder Number.
- paymentTotal: The refund amount.
- currency: Currency Code.
- refundEndpointType: 'payments' for ACH/eCheck amd 'captures' for all other payments
Function Signature:
httpRefundPayment(transactionId, referenceInformationCode, total, currency, refundEndpointType)
Refunds are capped at the remaining refundable balance. A
refund (whether full, a single partial, or the running total of multiple
partials) that exceeds the captured amount is rejected before the gateway
call.
Customization
The cartridge for
Salesforce
B2C Commerce has
built-in custom hooks that can be used to customize the request data that is sent to each
service.These hooks can send additional custom data, such as Merchant Defined Data for authorization requests.
How Custom Hooks Work
After a request for a particular service is built, there is a check for any code
registering to the hook
app.payment.modifyrequest
. If present, the
hook is called for that specific request and the request object is passed into the
hook. The return value of the hook is sent to Cybersource
as the
final request object. Through this process, you can inject your own data into the
request object from the custom code you write in a separate cartridge.Implementation
To customize request objects, register the hook
app.payment.modifyrequest
in your cartridge's hooks.json
file. An example would look like this, replacing the script path with your own
script:{ "name": "app.payment.modifyrequest", "script": "./cartridge/scripts/hooks/modifyRequestExample" }
You can copy the
scripts/hooks/modifyRequestExample
script from this cartridge
into your own to use as a template for extending and modifying service request
objects. Note that every hook must return a valid request object for the given
service. Refer to the REST API Field Reference
for
information about any field you want to customize or add.Support and Troubleshooting
Getting Support
If you require support with this extension, visit support.visaacceptance.com to
raise a support case.
Required Information for Support Cases
Provide this information for your support case:
- Summary of the issue.
- Steps to reproduce the issue.
- B2C Commerce cartridge version.
- CybersourceMerchant ID.
- Configuration screenshots: Provide screenshots of custom preference configurations.
- Log file and other relevant data: Download the logs from .
Upgrade
Upgrade the cartridge to a later version.
- Download the code from the ISV Integration Toolkits section on GitHub.
- Zip thepayments_metadatafolder.
- Go to and upload thepayments_metadata.zipfile.
- Import the uploaded zip file.
- Check release notes for any configuration parameters that might have changed.
RESULT
The cartridge is successfully upgraded to the latest version.
AFTER COMPLETING THE TASK
Migrating to v2.0.0
Version 2.0.0 is a major release. When upgrading from an earlier release, review
these changes:
- Add the new Business Manager cartridge.Addbm_cybs_sfrato the Business Manager cartridge path (it provides the Webhook Manager page). See Configuration.
- Update theservice endpoints.The endpoints changed to https://apitest.visaacceptance.com (test) and https://api.visaacceptance.com (production).
- Update thePayment Credentialsservice URL underAdministration > Operations > Services.
- Re-check site preferences.Preference groups were renamed to VisaAcceptance_* and regrouped. Payer Authentication, SCA, Decision Manager, and Transaction Type are now underSalesforce Default Acceptance Configurationand apply to the Salesforce default card form (Direct API) only. ForUnified Checkout, configure these controls in theCybersourceBusiness Center. Confirm your settings after importing metadata.
- Removed features:
- Flex Microform— card capture is nowUnified Checkoutor the Salesforce default payment form (Direct API).
- Standalone Google Pay— Google Pay is now offered throughUnified Checkout. Standalone Apple Pay is still supported.
- Network Token webhook— token updates are now retrieved through theToken Management ServiceAPI.
- Set up webhooks.Order updates are now driven by webhook notifications. Subscribe using the new Webhook Manager. The Salesforce jobs remain as a fallback. See Webhooks.
- Authentication.API authentication continues to use your REST Shared Secret and Key ID. Message-Level Encryption (MLE) uses a P12 certificate.
Message-Level Encryption
Message Level Encryption (MLE) uses certificates to ensure that each message is
securely encrypted and tied to the sender's verified identity, without needing to share
secret keys in advance.
MLE provides stronger authentication, easier key management, and better protection
against fraud or tampering.
A shared secret uses the same key for both sending and receiving messages, which
means that both parties must securely exchange and protect that key in advance.
While a shared secret can be simpler, it offers less identity verification and can
be more vulnerable if the key is compromised.
Message-Level Encryption requires a .p12 certificate to be created.
- Enable Meta Key: Set to yes to tell the cartridge that the keys/certificate provided are Meta Keys
- Import the certificate by going to and importing the extracted.crt. Make a note of the alias.
- Enable Message Level Encryption by going to .
- Enable theEnable Message-Level Encryptionoption.
- In theAlias of the Certificatefield, enter the Alias from when the certificate was imported.
- In theCertificate Serial Numberfield, enter the serial number from theCybersource_SJC_US certificate.
Optional Configuration
Additional optional configurations can be applied based on your specific
requirements.
Message-Level Encryption
Message Level Encryption (MLE) uses certificates to ensure that each message is
securely encrypted and tied to the sender's verified identity, without needing to share
secret keys in advance.
Message Level Encryption (MLE) provides stronger authentication and better protection
against fraud or tampering.
Enabling MLE for transacation is optional, but a
Message-Level Encryption requires a Response MLE certificate to be created. The same certificate is used for Request and Response messgaes. A REST Shared Secret is still required. See
Create a REST—API Response MLE Key
for steps on how to create a Response MLE certificate.- Enable Message Level Encryption by going to .
- Enable theEnable Message-Level Encryptionoption.
- In theAlias of the Certificatefield, enter the Alias from when the certificate was imported.
- In theCertificate Serial Numberfield, enter the serial number from theCybersource_SJC_US certificate.
- Upload the Response MLE certificate.
- Option 1 (recommended): Extract Certificate
ADDITIONAL INFORMATION
- Extract certificate: convert the Response MLE p12 certifcate to .pem format using this command:openssl pkcs12 -in <key filename>.p12 -cacerts -nokeys -out <key filename>.crt
- Open the converted file in a text editor and make sureCyberSource_SJC_USis the first certificate. Make a note of theCyberSource_SJC_USserial number.
- Import certificate: Go toAdministration > Operations > Private Keys and Certificatesand import the extracted .crt. Make a note of the alias.
- Go toMerchant Tools > Site Preferences > Custom Preferences > Message-Level Encryption Configuration:
- Alias of the Certificate:Enter the alias provided when the MLE certificate was imported
- Certificate Serial Number:Enter theCyberSource_SJC_USserial number
- Alias of the Certificate(Egress/Webhooks)
- Option 2: ImPex
Unified Checkout Configuration
Unified Checkout
ConfigurationConfiguration requirements and options for
Unified Checkout
.There are required and optional configuration options for
Unified Checkout
.Unified Checkout
Digital/Alternative Payment Methods Payment Processor
MappingIf you want to offer Digital or Alternative Payment Methods via
Unified Checkout, ensure each payment method has the correct Payment Processor
mapping.
- DW_APPLE_PAY - Payment ProcessorPAYMENTS_APPLEPAY.
- DW_GOOGLE_PAY - Payment ProcessorPAYMENTS_GOOGLEPAY.
- DW_PAZE - Payment ProcessorPAYMENTS_PAZE.
- PAYPAL - Payment ProcessorPAYMENTS_PAYPAL.
- VENMO - Payment ProcessorPAYMENTS_VENMO.
- CLICK_TO_PAY - Payment ProcessorPAYMENTS_CLICK_TO_PAY.
- BANK_TRANSFER - Payment ProcessorBANK_TRANSFER(for)eCheck
Additional transaction responses from
Unified Checkout
are
delivered by webhook notifications. Please see Webhooks for setup steps.- Unified CheckoutOptional ConfigurationTo set the following options, go to .
- Set theCheckout LabelforUnified Checkout.
ADDITIONAL INFORMATION
Choose your own checkout page label. You can choose up to 60 characters and the default value is "Secure Payments powered by Visa Acceptance Solutions" - Set theEnable Express Payoption.
ADDITIONAL INFORMATION
Separates digital wallet payment methods from the main card capture widget. - Set theUnified CheckoutVersionoption.
ADDITIONAL INFORMATION
Pin a specificUnified Checkoutversion. Available for version 1.0 onwards. Leave this field blank for the latest version (recommended). - Set theCard Prefix (BIN)inUnified Checkoutresponse option.
ADDITIONAL INFORMATION
- None: the Card BIN is not returned
- Six-digit: the 6 digit BIN is returned
- Eight-digit: the 8 digit BIN is returned
- Set theNon-WalletUnified CheckoutDisplay Modeoption.
ADDITIONAL INFORMATION
If Express Pay has been enabled, this applies to the non-express pay methods only.- Embedded: the payment widget is displayed within the checkout page
- Sidebar: the payment widget appears on the side of the customer's browser.
Configure Apple Pay Standalone
To offer Apple Pay outside of
Unified Checkout
, enable Apple Pay in your Salesforce
B2C Commerce store.Before you begin, complete Integrating Apple Pay into Your System.
- ConfigureSalesforceBusiness Manager.
- From the menu, choose .
- Select theApple Pay Enabled?check box.
- Complete the Onboarding form:
ADDITIONAL INFORMATION
- Ensure that the Apple Merchant ID and the Apple Merchant Name values you enter match the settings in your Apple account.
- Ensure that all other fields match your supportedCybersourcesettings.
- Country Code: Enter the country code for the location of your site. The country code is a two letter ISO 3166 country code (for example,US).
- Merchant Capabilities: Check the box for 3-D Secure; leave the other fields unchecked.
- Supported Networks: Select the types of payment you support;Amex,Mastercard, andVisaare supported byCybersource.
- Required Shipping Address Fields: Select the fields that are required on the shipping form.CybersourcerecommendsEmail,Name,Phone, andPostal Address.
- Required Billing Address Fields: SelectNameandPostal Address.
- Complete the Storefront Injection form.
ADDITIONAL INFORMATION
Select where to display Apple Pay buttons on your site. - Complete the Payment Integration form.
ADDITIONAL INFORMATION
- Use Commerce Cloud Apple Pay Payment API?Checked.
- Payment Provider URL:
- Test:https://apitest.visaacceptance.com/partner/demandware/payments/v1/authorizations
- Production:https://api.visaacceptance.com/partner/demandware/payments/v1/authorizations
- Payment Provider Merchant ID: Enter yourCybersourcemerchant ID.
- API Version: v1.
- Use Basic Authorization?Unchecked.
- Payment Provider User: —
- Payment Provider Password: —
- Use JWS?Set toYes.
- JWS Private Key Alias: Merchant.p12 Key Alias.
Step Result
The private key alias is generated when you upload your.p12key file (fromCybersourceself-serve) toSalesforceBusiness Manager under . - ClickSubmit.
- Register your domain inSalesforceBusiness Manager.
- Go to .
- Under the Domain Registration section, complete these fields:
ADDITIONAL INFORMATION
- In the Apple Sandbox section, clickRegister Apple Sandboxto registerSalesforceB2C to the Apple Sandbox account.
- In the Apple Production section, clickRegister Apple Productionto registerSalesforceB2C to the Apple Production account.
- Set the transaction type.
ADDITIONAL INFORMATION
Go to and chooseAuthorizationorSale.
Payer Authentication and 3-D Secure
Payer Authentication
and 3-D Secure
Configure
Payer Authentication
and 3-D Secure
for enhanced
transaction security.These settings apply to the Salesforce default card form
(Direct API) only
- Go to .
- InMode, choose one of these options:Payer Authentication
ADDITIONAL INFORMATION
- Yes: All transactions process with3-D Secure.
- No: No transactions process with3-D Secure.
- Data Only + Yes: Data Only is used for Visa and Mastercard/Maestro. All other card brands process with3-D Secure.
- Data Only + No: Data Only is used for Visa and Mastercard/Maestro. All other card brands process without3-D Secure.
- Enable theEnable SCAoption to enforce Strong Customer Authentication.
Tokenization
Tokenization enables your customers to save their payment cards securely for future
payments.
Follow these steps to enable tokenization:
- Go to .
- Enable theEnable Tokenization Servicesoption to turn on Tokenization.
- Enable the option to set the limits associated to saving cards.
- In theSaved Cards Allowedoption, enter the number of cards a customer can save in the defined time limit.
- In theReset Intervaloption, specify the number of hours before the saved card limit resets.
- Enable theNetwork Token Updatesoption to prompt the cartridge to check for Token Life Cycle Updates prior to checkout. YourCybersourceMID needs to be configured for Network Tokens.
AFTER COMPLETING THE TASK
The rate limiter settings for saving cards apply
only to the Salesforce default card form (Direct API) and do not apply to
Unified Checkout
Fraud Screening
Enable Fraud Screening to alert the cartridge to look for fraud screening responses.
Fraud Screening profiles must be set up in the
Business Center
.Follow these steps to enable fraud screening:
- Go to .
- Choose theEnableoption. This setting applies for bothDecision ManagerServicesDecision ManagerandFraud Management Essentials.
- Updates to transactions marked asREVIEWare delivered via webhooks. The Update Job is available as a fallback option.
- Set theConversion Detail Report Lookback Timevalue.
ADDITIONAL INFORMATION
If you are using REVIEW rules and configure theDecision ManagerUpdate Job, set the number of hours to look back for updates to transactions in REVIEW status. The maximum value is 24 hours. - To enable theDecision ManagerUpdate Job to poll for updates to the reviewed transactions, go to and selectPayment:. Set these values:Decision ManagerOrder Update
ADDITIONAL INFORMATION
- ID: Enter a job ID.
- Description: Enter the job description.
- ExecuteScriptModule.Module: int_cybs_sfra_base/cartridge/scripts/jobs/DMOrderStatusUpdate.js
- ExecuteScriptModule.FunctionName: orderStatusUpdate
- ExecuteScriptModule.Transactional:
- True: All changes occur as a single atomic operation. If any error occurs during the job, the system rolls back all changes to maintain data consistency.
- False: No automatic rollback is applied. Merchants must handle transaction logic manually. This is often preferred for large batch jobs.
- ExecuteScriptModule.TimeoutInSeconds: Set the function timeout value.
Device Fingerprint
Device fingerprinting collects information about the device used when paying for an
order and can assist in fraud screening decisions.
The Device Fingerprint settings apply to the Salesforce
default card form (Direct API) only.
- Go to .
- Enable theEnable DeviceFingerprint Serviceoption.
- In theOrganization IDfield, enter the Organization ID. Contact support if you do not know this value.
- In theThreatMetrix URLfield, enter the URL that points to the JavaScript that generates and retrieves the fingerprint of the device.
- In theTTL (Time to Live)field, enter the number of milliseconds to wait before generating a new fingerprint for any given customer session.
Delivery Address Verification
To verify the customer's shipping address during checkout, configure Delivery Address
Verification services.
- Go to .
- Enable theDelivery Address Verification Servicesoption.
Tax Calculation
To calculate local taxes once the customer enters their address at checkout,
configure the Tax Calculation services.
- Go to and set these options:
- Enable theEnable Tax Calculationfield.
- Configure these tax settings:
ADDITIONAL INFORMATION
- List of Nexus States: List the states to calculate tax for.
- List of Nexus States to Exclude: List the states to not calculate tax for.
- Merchants VAT Registration Number: Enter your VAT registration number if you have one.
- Default Product Tax Code: Enter the default tax code to use for products in the basket without a tax code.
- Purchase Order Acceptance City
- Purchase Order Acceptance State Code
- Purchase Order Acceptance Zip Code
- Purchase Order Acceptance Country Code
- Purchase Order Origin City
- Purchase Order Origin State Code
- Purchase Order Origin Zip Code
- Purchase Order Origin Country Code
- Ship From City
- Ship From State Code
- Ship From Zip Code
- Ship From Country Code
RESULT
If you enable Tax Calculation and do not specify any states in
the List of Nexus States or List of Nexus States to Exclude, Tax Calculation assumes
every state or province is taxable. You can leave either the
List of
Nexus States
or the List of Nexus States to
Exclude
as empty, but you cannot leave both empty.Webhooks
The
our platform
sends asynchronous webhook notifications to your
Salesforce B2C Commerce store for fraud decisions, and Unified Checkout
event updates.
Webhooks are the primary mechanism for keeping orders up to date. The Salesforce jobs remain
available as a fallbackWebhook subscriptions are managed from a Business Manager page provided by the
bm_cybs_sfra
cartridge.Prerequisite
- Ensurebm_cybs_sfracartridge is on the Business Manager cartridge path (see Configure for Salesforce B2C Commerce)
- Go to select the role, then go toBusiness Manager Modules, select the required context then enableWebhook ManagerunderVisa Acceptance.
- ForUnified Checkout, the Response Message Level Encryption key must be loaded and configured.
- Webhook Groups and EventsThe cartridge manages two webhook groups. Each notification is delivered to a controller route in the storefront cartridge.GroupProductEvent TypesNotification RouteFraud ManagementDecision Managerrisk.casemanagement.decision.accept, risk.casemanagement.decision.rejectWebhookNotification-dmNotificationFraud ManagementFraud Management Essentialsrisk.profile.decision.review, risk.casemanagement.decision.accept, risk.casemanagement.decision.rejectWebhookNotification-dmNotificationUC Webhook EventsUnified Checkoutuc.orders.transactionresultsWebhookNotification-paymentNotificationSubscribe to Webhooks
- Enable the site preferences for the required webhooks, Decision Manager withinSalesforce Default Acceptance Configurationand Unified Checkout withinSecure Integration Configuration.
- ClickSync. The cartridge will subscribe (or update) each enabled webhook based on the set Custom Site Preferences, and stores the subscription state.
- Confirm each subscription has anACTIVEstatus. If the status isPENDING_REVIEW, INACTIVE,orSUSPENDED, the subscription is not yet live. Wait up to 15 minutes andSyncagain. Please contact Support if the status does not change toACTIVE.
AFTER COMPLETING THE TASK
Subscription Storage
The webhook subscription state is stored in the organization-scoped custom object
VisaAcceptanceWebhookSubscription
(keyed by
ConfigId
), which records the WebhookId, WebhookUrl,
SecurityKey, Status, BaseUrl,
and EgressPublicKey
.
The object is managed by the Webhook Manager. You do not need to edit it
manually.Fallback: Salesforce Jobs
If webhook delivery is interrupted, these jobs can be used to reconcile the order
state:
- Payment: Decision Manager Order Update: polls for Accept/Reject decisions on unconfirmed orders (fallback for Fraud Management webhooks).
- Payment: Refresh Payment Status(on-demand job): enter a comma-separated list of order numbers in the OrderNumbers parameter and useRun Nowto refresh the Visa Acceptance payment status for those orders.
Shopify
The
Cybersource
extension for Shopify
supports popular payment methods and transaction types to help merchants start, grow, and manage their retail businesses.The
Cybersource
for Shopify
provides commerce tools
to start, grow, market, and manage retail businesses. You can accept payments in
multiple currencies and get paid in your local currency. The Cybersource
app on Shopify
supports popular payment methods to meet your
business needs. The
Cybersource
extension on Shopify
supports these
features:- 3-D Secure
- Apple Pay
- Card payments
- Google Pay
- Fraud management tools
- Shopify subscriptions
These transaction types are supported on the
Shopify
extension: - Authorization (authorize only)
- Sale (authorization and capture)
- Capture (capture only)
- Payer Authentication(3-D Secure)
- Refund (credit)
- Void (reversal)
The
Shopify
extension supports these fraud
solutions:- Decision Manager(DM)
- Fraud Management Essentials(FME)
For fraud management, we recommend that you use only an accept/reject model.
Configure Security Credentials
You must have a
Cybersource
Business Center
account. If you do not have one, you must create one before
installing the Shopify
extension. You also must retrieve details
from that account to install the plugin. Creating a Business Center Account
Business Center
AccountFollow these steps to create your
Business Center
account:- Go to the Business Center Registration website, and create an account.
- Follow the email instructions that you received to activate your merchant account.
- Log in to the Business Center to complete the registration process.
Install the Shopify Extension
Install the
Cybersource
app in your Shopify
account for testing or production.You must enable the
Cybersource
extension in your Shopify
account settings. You can install the Shopify
extension in test (CAS) if you are using a sandbox account.
Install the plugin in a live (production) environment when you complete the go-live
process.- Go to cybersource-cas.
- Select the extension and clickInstall.
- A page opens onShopify. Provide the required permissions to the payment app.
- After you set the permissions, theBusiness Centerlogin appears.
- Log in to theBusiness Centerwith yourCybersourcecredentials. This must be your transacting merchant ID. An agreement page appears.
- Check or clear the3-D Secure enrollmentbox based on your business needs. If you enroll for 3-D Secure, ensure that thePayer Authenticationfeature is enabled and configured.
- Submit the form. TheShopifystore settings page re-opens so that you can configure and activate theCybersourceextension.
ADDITIONAL INFORMATION
You must repeat these steps if you have more than oneShopifystore.
Configure the Shopify Extension
Configure the Shopify extension and enable 3-D Secure.
Follow these steps to configure the Shopify store:
- Log in to your Shopify account.
- Go to .
- Select the card brands and payment methods that you want to accept.
- ClickSave.
If you are using the test server, ensure that the
Test Mode
toggle is set
to On
.Reference Information
This section contains reference information to help you use the
Cybersource
app on Shopify
. WooCommerce
WooCommerce
The
Cybersource
extension for WooCommerce
allows you
to connect your WooCommerce
store to the Cybersource
platform, enabling secure and flexible payment acceptance.Supported Features
- Credit and debit cards
- Apple Pay
- Google Pay
- Click to Pay
- Paze
- ACH/eCheck
- PayPal
- Venmo
- Payer Authentication/3-D Secure
- Tokenization including Network Tokens
- Decision ManagerandFraud Management Essentials
- WooCommerceSubscriptions
- WooCommerceCheckout Blocks
Supported Versions
The
WooCommerce
extension requires these versions:- WooCommerce10.3.7+
- WordPress 7.0+
- PHP 8.2+
Prerequisites
This section outlines the required and optional prerequisites for using the
Cybersource
extension with WooCommerce
.Required Products
The Unified Checkout product must be enabled and configured for your merchant ID. See
the
Unified Checkout Developer
Guide
. You must also have a REST shared secret key and a Response MLE certificate. See the
Getting Started with the REST API
guide and the Getting Started with the REST API
guide. Environment Prerequisite
The GMP PHP extension must be enabled on your MAMP or XAMPP server for JSON Web Token
messaging.
Optional Products
These products are optional, but they must be enabled and configured for your
merchant ID if you choose to use them:
- Network Tokens
- Decision Manager
- Fraud Management Essentials
Release Notes
Version 3.0.0: August 2026
This version provides these enhancements:
- Migrated to Unified Checkout v1.x including Unified Checkout becoming responsible for calling Payer Authentication, Tokenization, and fraud screening
- Added webhook support for payment response and fraud management
- Support for PayPal and Venmo
- Network Token Support
- Offer Sidebar and Embedded display for Unified Checkout widget
- Full Message-Level Encryption(MLE)
Version 2.2.2: June 2026
This version provides these enhancements:
- Wordpress 7.0 compatibility
- Added Express Pay configuration
The following bugs were addressed:
- Order Status handling.
Version 2.2.1: April 2026
This version provides these enhancements:
- Updated Cybersource Rest Client SDK to v0.0.72
The following bugs were addressed:
- WordPress validation issue fixed
- Added validation for Express Pay with respect to currencies
- Monolog dependency issue addressed
Version 2.2.0: February 2026
This version provides these enhancements:
- Updated Unified Checkout to v0.33
- Added support for China UnionPay, Maestro, Jaywan, and Paze
- Added Payer Authentication/3-D Securefor Google Pay
- Added Express Pay for Product and Checkout pages
- ReplacedCybersourceendpoints with Visa Acceptance Solutions endpoints
- Added compatibility for Wordpress v6.9
The following bugs were addressed:
- IP address is now collected for all requests.
- CVV input field text was updated.
- Saved card tokens are now only accessible when tokenization is enabled.
- Administrative state field is now properly passed for non-US addresses in3-D Securetransactions.
Version 2.0.1: October 2025
This version provides these bug fixes:
- Removed the Customer ID for a guest user because it exceeded limits within the platform for some processors.
- Removed Commerce Indicator from the Payment Acceptance Request.
Version 2.0.0: August 2025
This version provides these enhancements:
- Unified Checkout Version 0.23
- Apple Pay
- Adoption of Visa Acceptance REST Client SDK
- Message-Level Encryption
- WooCommercesubscriptions and HPOS compatibility
This version is compatible with:
- WooCommerce7.6+
- WordPress 6.5.3+
- PHP 8.0+
Version 1.0.0: June 2025
This initial release supports these products:
- Unified Checkout
- Google Pay
- Click to Pay
- Token Management Service (TMS)
- Payer Authentication
- Decision ManagerandFraud Management Essentials
This version is compatible with:
- WooCommerce7.6+
- WordPress 6.5.3+
- PHP 7.4+
Install the WooCommerce Extension
Follow these steps to install the extension:
- Download the extension from WordPress orWooCommerce.
- Log into yourWooCommerceadmin account.
- Go to .
- ClickInstall Now.
- After the extension is installed, clickActivate.
- ClickConfigureto start configuring the extension.
Alternatively, you can use the
Add to store
functionality in the WooCommerce
order confirmation page or the My Subscriptions section in your WooCommerce
account. Configure the WooCommerce Extension
Follow these steps to configure the extension:
- Select , and then selectorCybersourcePayments.
- ClickManageon theCybersourceline.
Minimum Configuration Requirements
These extension settings must be configured to accept payments with
Cybersource
:As of version 3.0.0, payment settings
including 3D-Secure, Tokenization, and Fraud Screening are managed within the
Visa Acceptance Business Center. Please see this guide for instructions
- Enable/Disable
- Set toEnableto allow the extension to take payments from yourWooCommercestore. When the extension is enabled, card payments are enabled by default.
- Title
- Enter the text that you want to display to your customers as the title on the checkout and order received page.
- Description
- Enter the text that you want to display as a description during the checkout process.
- Charge Virtual-Only Orders
- When this setting is selected, if the order is exclusively for digital or virtual items, the transaction is automatically captured if the authorization is approved.
- Capture Paid Order
- When this setting is selected, if you mark an order asProcessingorCompleted, capture requests are automatically sent.
- Environment
- For testing your test account, chooseTest.
- For live transactions, chooseProduction.
- Merchant ID/Test Merchant ID
- Enter the transacting merchant ID (MID) assigned when you set up your account.
- API Key Detail/Test API Key Detail
- Enter the key from your REST API shared secret key.
- API Shared Secret Key/Test API Shared Secret Key
- Enter the shared secret from your REST API shared secret key.
- Key File Path
- Enter the path to the directory where you have stored the Response MLE certificate, and the filename.
- Key Password
- Enter the password you entered when creating the Response MLE certificate.
- Checkout Display Mode
- Embedded: The payment capture form is displayed within the checkout page.
- Sidebar: The payment form opens as a side panel on the customers browser.
- Registered Webhooks
- View and manage Visa Acceptance Webhook subscriptions. If you delete a Webhook, it can be re-enabled by enabling the feature in the configuration panel and saving.
Message Level Encryption
Message-Level Encryption (MLE) enables you to store information or communicate with
other parties while helping to prevent uninvolved parties from understanding the
stored information. MLE is optional and supported only for payments services. A REST
certificate is required for MLE.
Follow these steps to enable MLE,:
- CheckMessage Level Encryption.
- Enter theKey Directory Pathwhere you have stored the certificate in yourWooCommerce/WordPress environment.
- Enter theKey File Name.
- Enter theKey Passwordwhich you set when generating the REST certificate.
Digital Payment Methods
Digital Payment Methods
: Choose from Apple Pay, Google Pay,
Click to Pay, and Paze.You must enable these for your MID in the
Business Center
. See the
Unified Checkout Developer
Guide
for more information. Tokenization
Tokenization allows you to offer the ability for your customers to save their payment
cards securely for future payments.
- SelectTokenizationto enable this feature.
- SelectSaved Card Verificationto request customers to enter their card security code when paying with a saved card.
Payer Authentication/3-D Secure
- SelectPayer Authentication/3-D Secureto enable added payment security. Some countries/regions mandate this feature.
- SelectStrong Consumer Authenticationto force a 3-D Secure Challenge when a customer chooses to save their card for future transactions.
Fraud Screening
- SelectFraud Screeningto enableDecision ManagerorFraud Management Essentials.
- Configure your fraud screening profiles using theBusiness Center.
Debug Mode
- Select one of these debugging mode options:
- On: Enables the creation of detailed logs for every transaction. This setting is recommended for use only in the test environment or when troubleshooting issues in the production (live) environment.
- Off: Enables the creation of basic logs for transactions.
Optional Configuration
These configuration options are optional.
These configuration options are enabled but may need to be enabled for your
Cybersource
account to be used. - Tokenization: Tick to enable the ability for merchants to save their card. Please enable this in your Unified Checkout settings too
- Network Tokens:Tick to tell the extension to check for token updates prior to a registered customer checking out.
- Fraud Screening:TickFraud Screeningto tell the extension to subscribe to the fraud management webhook notifications.
- Checkout Version:Pin a version of Unified Checkout v1; example format: 1.7. Leaving blank will automatically use the most recent version.
- Message Level Encryption:Tick to turn on Message Level Encryption.Even if you do not turn on Message Level Encryption, a Response MLE certificate is still required for the Unified Checkout response Webhook notification.
Order Management
Orders are marked according to the selected transaction type:
- Authorization: When this option is selected, successful transactions are marked asOn Hold.
- Charge: When this option is selected, successful transactions are marked asProcessing.
Fraud Screening
If fraud screening is enabled, transactions are marked as follows:
- Approved orders are marked asOn HoldorProcessing, depending on your transaction type setting.
- Orders to review are marked asOn Hold.
- Rejected orders are marked asFailedorCancelled.
Orders marked as
On Hold
need to be reviewed in the Business Center
.
The extension checks for transaction status updates every 15 minutes. Rejected
transactions are marked as Cancelled
.Accepted transactions are marked according to your transaction type settings.
If you need to manually trigger the transaction update, follow these steps using the
WooCommerce
Dashboard:- Select .
- Find and selectwc_payment_gateway_update_order.
- ClickApply.
Capture an Order
Follow these steps to capture an order when the transaction type is set to
Authorization
: - Find and open the order from the list of orders.
- ClickCapture Charge.
- Change the order status toProcessing.
- ClickApply.
Refund an Order
Follow these steps to refund an order:
- Find and open the order from the list of orders.
- ClickRefund.
- Enter the refund amount.
- ClickRefund via.Cybersource
Void an Order
Voids can be performed only for transactions when the transaction type is set to
Authorization
and the transaction has not been captured.Follow these steps to void an authorization:
- Find and open the order from the list of orders.
- In theOrder Statusfield, selectCancelled.
- ClickUpdateto save the change and void the authorization.
Upgrade the Extension
Follow these steps to upgrade to a later version of the
WooCommerce
extension.- Select .
- Find theCybersourceextension and clickUpdate Now.
Support and Troubleshooting
Contact the Support Center for help with installation or operational issues, and be ready to provide your platform version, extension version, and steps to reproduce the issue.
If you need support installing or using this extension, contact the Support Center to open a case, and provide this information:
- Summary of the issue
- Steps needed to reproduce the issue
- Platform version
- Extension version
- Platform merchant ID
- Configuration screenshots
- List of themes and additional extensions installed
- Log file and any other data or screenshots related to the issue
ISV Plugin Version Lifecycle and Support Policy
This policy defines how
Cybersource
ISV plugin versions are released, supported, and retired.Overview
This policy defines how
Cybersource
ISV plugin versions are
released, supported, and retired. It outlines versioning standards, fix delivery,
support scope, platform and dependency requirements, merchant responsibilities, and
lifecycle expectations to ensure clarity, predictability, and sustainable
support.Policy Status and Non-Contractual Nature
This policy is provided for informational purposes only and does not constitute a
contractual commitment, service level agreement, warranty, or guarantee. This policy
does not modify, amend, or supplement any agreement between Visa (or its affiliates)
and any merchant, issuer, partner, or ISV. In the event of any conflict, the
applicable executed agreement shall control.
Versioning Standards
Cybersource
ISV integrations follow one of these versioning schemes,
depending on the integration and release model. Version identifiers are provided for
informational purposes only and do not guarantee compatibility, stability, or
continuity of functionality across versions.Calendar Versioning (CalVer)
Calendar Versioning reflects release timing rather than semantic meaning:
YY.RELEASE.PATCH
- A change in the year component reflects a new calendar year only.
- Year changes do not imply breaking or major changes.
- Release and patch increments represent enhancements and fixes.
- CalVer is used for integrations that do not require explicit signaling of breaking changes.
Semantic Versioning (SemVer)
Semantic Versioning is used when release semantics must be explicit.
MAJOR.MINOR.PATCH
- MAJOR— Backward-incompatible changes or migrations.
- MINOR— Backward-compatible enhancements.
- PATCH— Bug fixes or security fixes.
Integrations may transition from CalVer to SemVer when breaking changes are
introduced.
Major Version Releases
Breaking or backward-incompatible changes are released using semantic versioning
(SemVer). When an integration transitions from CalVer to SemVer, the first SemVer
release represents a major lifecycle change and CalVer becomes the previous major
release.
CalVer integrations do not use year changes to indicate breaking changes.
Supported Versions
- Only the latest supported version line of each integration is fully supported, subject to Visa's discretion and the terms of the applicable agreement.
- Merchants may continue using older versions at their discretion, with limited support until the applicable end-of-life (EOL).
- Support assumes required external dependencies and configurations are completed.
- Merchants are encouraged to remain on the latest available release within the supported version line.
Fix Delivery and Backporting
Bug fixes and security fixes are delivered through new releases of the supported
version line. Fixes are not backported to earlier releases.
We may provide patch details at our discretion to merchants who choose to remain on
a previous release so they may apply changes themselves. Providing patch details
does not constitute support, maintenance, or an obligation to remediate issues for
that version.
Limited Support for Previous Major Versions (SemVer Only)
When an integration transitions to a new major version under Semantic Versioning,
the immediately preceding major version enters a limited support period of six (6)
months, starting from the release date of the succeeding major version. Limited
support timelines are based on release dates, not installation dates. Limited
support periods are indicative only and may be shortened, extended, or terminated
by Visa at its discretion.
At the end of the six-month limited support period, the version is considered
end-of-life.
Limited Support Definition
During limited support:
- Critical security fixes may be provided at our discretion.
- No enhancements or new features are provided.
- No non-security bug fixes are provided.
- No configuration or UI changes are provided.
- No parity with newer major versions is maintained.
End-of-Life (EOL)
After the limited support period ends:
- The version is considered end-of-life.
- No fixes, updates, or support are provided.
- Merchants should upgrade or migrate to a supported version.
Visa has no obligation to continue supporting any version beyond its designated
end-of-life, regardless of merchant deployment status or business impact.
Platform and Dependency Support
ISV integrations are supported only on platform versions, frameworks, and runtime
environments that are actively supported by their respective providers.
When a platform provider ends regular or extended support for a specific version,
ISV integrations installed on that version are no longer supported. This includes,
but is not limited to:
- E-commerce platforms.
- Programming languages and runtimes.
- Required databases or infrastructure dependencies.
Support is not extended beyond these end-of-support dates, regardless of plugin
version. Any extended, paid, or bespoke support arrangements agreed directly
between a merchant and a platform or dependency provider do not extend or modify
our support timelines or end-of-life dates. Visa is not responsible for monitoring,
notifying, or coordinating end-of-support timelines for third-party platforms,
dependencies, or infrastructure.
Mandated Platform and Scheme Changes
ISV integrations operate within the requirements of the
Cybersource
platform and any applicable brands using the platform. Where mandated changes are
introduced by Cybersource
, card schemes, or regulatory
bodies—including security, compliance, or encryption requirements—existing
integration versions may be required to change to remain compliant.In such cases, older integration versions may transition to limited support or
end-of-life earlier than the timelines defined in this policy, without liability.
Merchants are responsible for implementing required updates to remain compliant and
continue processing transactions.
External Dependencies and Configuration Responsibility
Some integrations rely on external systems or platforms for configuration and
operation.
- External configuration is the responsibility of the merchant.
- Integrations do not manage, store, or migrate external configuration.
- Issues caused by missing or incomplete external configuration are not considered integration defects.
Version support applies only to integration behavior and documented API
functionality.
Upstream Product Dependencies
ISV integrations may rely on upstream products, services, or APIs provided by
Cybersource
or third parties. We maintain compatibility with
supported versions of these products; however, we do not control their release
schedules, feature changes, or behavioral updates. Changes introduced by upstream
products may impact integration behavior.Issues resulting from upstream product changes are not considered defects in the
integration itself. Support may be limited to general guidance only, mitigation, or
coordination with the relevant product team where appropriate. Visa does not
guarantee resolution, timelines, or outcomes for issues arising from upstream
product changes.
Merchant Responsibility and Suitability
Merchants are responsible for determining whether an ISV integration is suitable for
their business requirements, technical environment, infrastructure, and compliance
obligations.
Integrations are provided
as is
and are intended to support documented,
supported configurations only. We are not responsible for ensuring compatibility
with merchant-specific workflows, customizations, infrastructure, or third-party
systems.To the extent permitted by law and subject to the applicable executed agreement,
Visa disclaims all liability arising from or related to the use, or reliance on an
integration, including but not limited to operational disruption, data loss, or
business interruption.
Customization Disclaimer
ISV integrations are designed to support standard, documented workflows. Merchants
are free to customize, extend, or adapt integrations to meet their specific business
processes or operational requirements. Visa has no obligation to support, maintain,
or remediate issues arising from customized implementations, including where such
customizations are necessary for a merchant's internal business processes.
Therefore:
- Support is provided only for documented, supported configurations.
- Customizations may impact the ability to diagnose or resolve issues.
- Support for customized implementations may be limited or provided on a best-effort basis.
Troubleshooting Requirement
Support may request that customizations, extensions, or self-applied patches be
temporarily disabled or bypassed to assist with troubleshooting and issue
reproduction.
Support Scope Summary
This table is provided for general reference only and does not constitute a
commitment, guarantee, or service level agreement.
Scenario | Support Level |
|---|---|
Supported version line on supported platform | Full support |
Previous major version (within 6 months) | Security fixes only |
End-of-life versions | Not supported |
Unsupported platform or runtime | Not supported |
Missing external configuration | Not supported |
Customized or patched versions | Best effort only |
Policy Changes
This policy may be updated, amended, or withdrawn at any time in Visa's discretion.
Continued use of an integration after a policy update constitutes acceptance of the
revised policy. Nothing in this policy creates any rights in favor of any third
party or limits Visa's rights under applicable agreements or law.
Adobe Commerce REST API
The
Cybersource
extension for Adobe Commerce
/Magento
Open Source enables merchants to connect their Adobe Commerce
/Magento Open Source store to the Cybersource
platform to directly
take credit and debit cards, Apple Pay, Google Pay, and Click to Pay payments.For simplicity in this document, any reference to
Adobe Commerce
also
applies to Magento Open Source, unless otherwise stated.Supported Versions
System Requirements
The
Adobe Commerce
extension has these system requirements:- Adobe Commerce2.4.5+
- PHP 8.1+
Supported Features
The
Cybersource
extension supports these payment methods and security
features.Payment Methods
- Credit and debit cards
- Apple Pay
- Google Pay
- Click to Pay
- eCheck/ACH
Security Features
- Payer Authentication/3-D Secure
- Tokenization
Unsupported Adobe Commerce Features
Adobe Commerce
FeaturesUnsupported Features
These features are not supported by this extension:
- Order void
- Multi-shipping
- Multiple node implementation
- Google reCAPTCHA
Prerequisites
Mandatory Prerequisites
This
Cybersource
product must be configured for your Merchant ID:- Unified Checkout
You also must have a REST Shared Secret Key. See the
Getting Started with REST Developer
Guide
for information on how to get a REST Shared Secret Key.Optional Prerequisites
These
Cybersource
products are optional. If you want these products
you must enable and configure your merchant ID with them.- Payer Authenticationfor3-D Secure
- Tokenization
- Apple Pay
- Google Pay
- Click to Pay
- eCheck
You can also enable Message-Level Encryption (MLE) for additional security. A REST Certificate is required for MLE.
Release Notes
Version history and changes for the
Cybersource
extension for
Adobe Commerce
.Version 26.1.0 March 2026
These enhancements were added with this release:
- Admin orders with credit and debit cards
- Minicart checkout for Apple Pay and Google Pay
- eCheck/ACH support
- Cardinal Commerce URL update for Data Center Migration
- UpdatedUnified Checkoutto version 0.34
- Merchandise Return Authorization support
This release is compatible with:
- Adobe Commerce2.4.5+
- PHP 8.1+
Version 25.2.0 January 2026
These enhancements were added with this release:
- Request Message Level Encryption
- API endpoint updates
- Support for Jaywan card
- Implemented Sub Resource Integrity (SRI)
- UpdatedUnified Checkoutto version 0.33
These bugs were addressed in this release:
- Corrected the country field source in theUnified Checkoutcapture context.
- CSP violation
This release is compatible with:
- Adobe Commerce2.4.5+
- PHP 8.1+
Version 25.1.0 May 2025
Initial release that supports:
- Unified Checkout
- Apple Pay
- Google Pay
- Click to Pay
- TMS
- Payer Authentication
This release is compatible with:
- Adobe Commerce2.4.5+
- PHP 8.1+
Install the Extension
Follow these steps to install the
Cybersource
extension for Adobe Commerce
. Before starting the installation, ensure you have
Adobe Commerce
authentication keys and that they are set
correctly in your environment. See Authentication Keys for details.Go to the
Adobe Commerce
Marketplace and get the free extension.
Choose the appropriate installation method based on your environment:- Adobe Commerce Cloud: for cloud-based installations, go to Adobe Commerce Cloud.
- Adobe CommerceOn-Premise/Magento Open Source: for self-hosted installations, go to Adobe Commerce On-Premise / Magento Open Source.
Adobe Commerce Cloud
Adobe Commerce Cloud
Follow these steps to install in
Adobe Commerce Cloud
environments.- Run this command in your local Cloud project directory:composer require cybersource/module-payment:26.1.0
- After Composer finishes, commit the updated files using these commands:git add composer.json composer.lock git commit -m "AddCybersourcePayment module" git push
- Enable the module with this command:php bin/magento app:config:dump
- After enabling the module, commit the updated configuration file with these commands:git add app/etc/config.php git commit -m "EnableCybersourcePayment module" git push
Adobe Commerce On-Premise / Magento Open Source
Adobe Commerce
On-Premise / Magento Open SourceTo install the module using Composer, run these commands in your
Adobe Commerce
On-Premise and Magento Open Source environments.- Run this command:composer requireCybersource/module-payment:26.1.0 php bin/magento module:enableCybersource_Paymentphp bin/magento setup:di:compile php bin/magento indexer:reindex php bin/magento setup:upgrade php bin/magento setup:static-content:deploy -f php bin/magento cache:clean php bin/magento cache:flush php bin/magento module:status
Configure the Extension
To configure the
Cybersource
extension, go to . Configure these fields:Configure General settings
: - Environment:
- Sandbox: Choose for testing of yourCybersourcetest account.
- Production: Choose for live transactions.
- Merchant ID: Enter the transacting Merchant ID (MID) assigned to you by Visa Acceptance Solutions.
- API Key: Enter the Key from your REST API Shared Secret Key.
- API Shared Secret Key: Enter the Shared Secret from your REST API Shared Secret Key.
- Debug Mode:
- Yes: Compiles detailed logs for every transaction. This option is recommended only for the Test Environment or when troubleshooting issues in Production.
- No: Only basic logging occurs.
- Message Level Encryption:
- Enabled
- Yes: Encrypts the full request message using JSON Web Tokens before being transmitted to the Visa Acceptance Platform.
- No: Uses the HTTP Signature.
JSON Web Tokens use a digital certificate to prove who you are, while HTTP Signature uses a
shared secret key to confirm that the message is genuine. Both methods are PCI
compliant.
- Certificate File: Upload the p12 certificate for yourCybersourceMerchant ID.
- Key Password: Enter the password that was used when you created your p12 certificate.
Configure Secure Payment Methods
: - Enable: ChooseYesto enable the extension.
- Title: Enter the label your customers see on the checkout page.
- Payment Action: Choose one of these options:
- Authorize and Capture: Captures the transaction automatically when the authorization is approved.
- Authorize only: Sends an authorization request, and if it is approved, you must manually request a capture.
- Card Types: Choose the card brands you want to offer to your customers.
- Allowed Payment Methods: Choose the payment methods you want to offer to your customers. These payment card types must be enabled for your MID in theBusiness Center. See theUnified Checkout Developer Guidefor details.
- Select Layout:
- Embedded: The payment widget appears inline on the checkout page.
- Sidebar: The payment widget appears on the right side on the checkout page.
- Payment from Applicable Countries:
- All Allowed Countries: TheAdobe Commerceglobal settings determine which countries to accept payment from.
- Specific Countries: You specify which countries you want to accept payments from.
- : ChoosePayer Authentication/3-D SecureYesto enable3-D Secure.
- Digital Pay button in minicart: ChooseYesto enable Minicart checkout.
- Tokenization: ChooseYesto enable your customers to save their payment cards for future purchases.
- Tokenization Title: Enter the label you want your customers to see when they pay with a saved card.
- Saved Card Verification: ChooseYesto request that your customer enter their card security code when paying with a saved card.
- Enforce Strong Customer Authentication: ChooseYesto enforce a3-D Securechallenge when a customer saves their card for the first time.
Order Management
The
Cybersource
extension provides comprehensive order management
capabilities for handling transactions after they are processed. This includes capturing
authorized payments and processing refunds when necessary.The order management features enable you to:
- Capture authorized transactions to collect funds.
- Process full or partial refunds for completed transactions.
- Manage the payment lifecycle from authorization to settlement.
Capture a Transaction
When you have the
Payment Action
set to
Authorization
, you must capture the transaction to collect the
funds.Follow these steps to capture a transaction:
- Open an order from the list of orders.
- ClickInvoice.
- Check the item(s) that require capturing.
- Ensure the drop-down capture option is set toCapture Online.
- ClickSubmit Invoice.
Refund a Transaction
Refund an order by creating a credit memo in the
Adobe Commerce
admin.Follow these steps to refund an order:
- From the list of orders, choose the order you want.
- ClickInvoices.
- Select the appropriate invoice.
- ClickCredit Memo.
- Check the item(s) to be refunded.
- Verify and if necessary update theRefund Totals.
- ClickRefund.
Place an Admin Order
Follow these steps to place an admin order:
- Go to .
- ClickCreate New Order.
- Select an existing customer or create a new customer.
- Add the required product(s) and enter the shipping and billing addresses.
- Select the shipping method.
- Click theCybersourcepayment method.
- Enter the card details and complete the payment.
Support and Troubleshooting
Get support for the
Cybersource
extension by providing detailed
information about your issue.If you require support with this extension, sign in to the Support Center to open a case
and provide these details:
- Summary of the issue
- Steps needed to reproduce the issue
- Platform version
- Extension version
- CybersourceMerchant ID
- Configuration screenshots
- List of themes/additional extensions installed
- Log file and any other data or screenshots related to the issue
Upgrade the Extension
Upgrade the
Cybersource
extension for Adobe Commerce
to the latest version.To upgrade from an earlier version of our
Adobe Commerce
extension, run these Composer commands.- Update the extension to the latest version:composer requireCybersource/module-payment:26.1.0
- Run the set-up upgrade command:bin/magento setup:upgrade --keep-generated
- Deploy static content:bin/magento setup:static-content:deploy
- Clean the cache:bin/magento cache:clean
Oracle NetSuite
The
Cybersource
SuiteApp enables merchants to connect their NetSuite
account to the Visa Acceptance Solutions
Platform to directly take
credit and debit cards and eCheck payments. It also enables order management for Apple
Pay, Google Pay, Click to Pay, PayPal, Venmo, and Paze payments.The SuiteApp is built on the Oracle NetSuite Payment Processing Plugin Architecture using
the SuitePayments API.
Supported Features
The
Cybersource
SuiteApp for Oracle NetSuite supports these payment and
order management features.Payment Acceptance and Order Management
These payment methods support authorization, sale, capture, refund, credit, and
authorization reversal:
- ACH/eCheck
- Credit and debit cards including Level II and Level III processing
- Fraud Screening
- Google Pay
- Network Tokens
- Payer Authentication for3-D Secure
- Tokenization
Order Management Only
- Apple Pay
- Click to Pay
- PayPal
- Venmo
- Paze
Reporting
These
Visa Acceptance Solutions
reports can be imported to
NetSuite:- Fraud Screening Conversion Detail Report
- Payment Batch Detail Report
- Transaction Request Report
- Conversion Detail Report
Invoicing
- Visa Acceptance Solutionsinvoicing
- NetSuite invoicing
Merchant Initiated Transactions
- Resubmission
- Reauthorization
- Delayed charge
- No show
- Unscheduled or auto top-up
Supported Versions
The
Cybersource
SuiteApp supports Oracle NetSuite 2026.2 and
earlier.Version Requirements
The SuiteApp supports Oracle NetSuite 2026.2 and earlier.
Recommendation
Enable Payment Instruments within your Oracle NetSuite environment. For more details,
see Payment Instruments.
Prerequisites
Before installing and configuring the
Cybersource
SuiteApp for Oracle
NetSuite, ensure you meet the prerequisites for both Cybersource
and
NetSuite.Some prerequisites are required and others are optional depending on your use
case.
Cybersource Prerequisites
Cybersource
PrerequisitesThese are the required and optional
Cybersource
prerequisites for the
Oracle NetSuite SuiteApp.Required
You must have a REST shared secret key. See the
Getting Started with REST Developer
Guide
for how to create a shared secret key.Optional
These
Cybersource
products are optional. To use them, each product
must be enabled and configured for your Merchant ID:- ACH and eCheck
- Decision Manager
- Invoicing (also requiresUnified Checkout)
- Network Tokens
- Payer Authentication for3-D Secure
- Tokenization
NetSuite Prerequisites
These are the required and optional NetSuite prerequisites for the
Cybersource
SuiteApp.Required Features
These NetSuite features must be enabled for the
Cybersource
SuiteApp
to function:From the NetSuite menu, choose .
- On the Company tab, enableFile Cabinet.
- On the Transactions tab, enableCredit Card Payments.
- On the Suite Cloud tab, enableCustom RecordsandSuite Scripts.
Optional Features
These NetSuite features are optional but might be required for your use case. Enable
these features as needed. Access these feature options from the menu at .
- On the Transactions tab, you can enableSales Orders.
- On the Suite Cloud tab, you can enableSOAP/REST Web Services.
Access these accounting options from the menu by choosing .
- On the Items/Transactions tab, you can enable these options:
- Customers can pay online
- Use Card Security Code with Credit Card Transactions
- Allow adjusted Expiration Date to improve recurring payments
- Enable the Sale Payment Operations
- Preserve Transactions when payment is on hold
- On the General tab, verify that theVoid Transactions Using Reversing Journalsoption is unchecked.
Enable NetSuite Payment Instruments
NetSuite Payment Instruments must be enabled for tokenization, ACH, multi-capture,
merchant-initiated transactions, and invoicing.
Some features work only when NetSuite Payment Instruments are enabled. These features
require NetSuite Payment Instruments to be used:
- Tokenization
- Network Tokens
- ACH/eCheck
- Multi-capture
- Delayed shipment
- Merchant-initiated transactions
- Invoicing
- Payment link
Follow these steps to enable Payment Instruments:
- From the NetSuite menu, choose .
- Choose theTransactionstab.
- In the Payment Processing section, in thePayment Instrumentsfield, clickEnable.
Install the SuiteApp
You install the
Cybersource
SuiteApp for Oracle NetSuite from the
SuiteBundler. Follow these steps to install the
Cybersource
SuiteApp for Oracle
NetSuite:- Log in to your Oracle NetSuite environment.
- From the NetSuite menu, choose .
- UnderKeywords, enterand clickCybersourcefor Oracle NetSuiteSearch.
- Verify that the Bundle ID is316818.
- In the Name column, click.Cybersourcefor NetSuite
- ClickInstall.
Configure the SuiteApp
You configure the
Cybersource
SuiteApp in three steps: create the
supported payment methods, map them, and create a payment processing profile.The configuration can be managed from the
Cybersource
SuiteApp user
interface. Go to .Three main steps are required to configure the
Cybersource
SuiteApp:- Create supported Payment Methods.
- Map the Payment Methods.
- Create a Payment Processing Profile.
Create a Payment Method Automatically
The automatic option creates and maps the payment methods that the SuiteApp
supports.
To create supported payment methods automatically, choose
.
This option creates card payment methods, ACH and eCheck payment methods, and
token payment methods. It also maps the payment methods automatically. Any
additional payment methods must be created manually. See Create a Payment Method Manually.
Run Create Supported Payment Methods
(Automatic) after upgrading so that payment methods introduced in later versions of
the SuiteApp are created in your NetSuite environment.
Create a Payment Method Manually
Create a payment method manually when you need one that the automatic option does not
create.
Follow these steps to create a payment method manually:
- To create a payment method manually, choose .
- In thePayment Method Namefield, enter a name.
- In theTypefield, choose the appropriate option.
- For a credit or debit card payment method, choose the appropriate card brand.
- For Order Management operations only, chooseExternal Checkout.
ADDITIONAL INFORMATION
If you want NetSuite to pass line-level data in payment messages, selectRequires Line Level Data. - ClickSave.
- Repeat the procedure for any additional payment methods.
- Proceed to Map the Payment Method.
Map the Payment Method
Each payment method must be mapped to ensure proper processing in the
Cybersource
SuiteApp.If you selected automatic creation of the payment methods, and do not need to add any
additional payment methods, you can skip this step.
Follow these steps to manually add payment methods:
- From the menu, choose .
ADDITIONAL INFORMATION
The payment methods that are available for mapping are listed. - Choose a payment method and clickEdit.
- In thePayment Namefield, enter a name and clickSave. Repeat this process for any additional payment methods that need to be mapped.
- After you finish mapping your payment methods, proceed to Payment Processing Profile.
Configure the Payment Processing Profile
To define how payments are processed through the
Cybersource
SuiteApp, configure the payment processing profile.Go to the Payment Processing Profile by choosing and complete these required settings:
In the Primary section, complete these fields:
- In theNamefield, enter the name of the payment processing profile.
- In theSubsidiaryfield, specify which subsidiary within your NetSuite environment this profile applies to.
- In theCharge Currenciesfield, specify the currency or currencies that you accept.
- Test Mode: Enable only to send transactions to theVisa Acceptance SolutionsPlatform test environment.
In the
Cybersource
Payment Configuration section, complete these
fields:- In theMerchant IDfield, enter yourCybersourceMerchant ID.
- In theLevel Typefield, set the default transaction level type by choosing Basic, Level II, or Level III. This setting can be overridden for individual payments when necessary.
In the Keys Configuration section, complete these fields:
- In theKey IDfield, enter the key ID from your REST shared secret key.
- In theSecret Keyfield, enter the shared secret from your REST shared secret key.
In the Address Verification (AVS) Rules section, complete these fields:
- In theNo AVS Matchfield, choose how to handle orders with a no match (AVS) response.
- In theAVS Service Not Availablefield, specify how to handle orders with an AVS unavailable response.
- In thePartial AVS Matchfield, specify how to handle orders with a partial match AVS response.
In the Card Verification Rules section, complete
these fields:
- In theCSC Not Submittedfield, specify how to handle orders with a Card Security Code (CSC) not submitted response.
- In theCSC Service Not Availablefield, specify how to handle orders with a CSC unavailable response.
- In theCSC Check Failedfield, specify how to handle orders with a CSC check failed response.
- In theCSC Not Supported by Cardholder Bankfield, specify how to handle orders when the card issuer does not support CSC checks.
- In theNo CSC Matchfield, specify how to handle orders with a no match CSC response.
In the Merchant Reference Number Customization section, complete these fields:
- In theFor Capturefield, specify which NetSuite ID to pass as the Merchant Reference Number to theVisa Acceptance SolutionsPlatform during a capture.
- In theFor Refundfield, specify which NetSuite ID to pass as the Merchant Reference Number to theVisa Acceptance SolutionsPlatform during a refund.
- In theFor Customer Depositfield, specify which NetSuite ID to pass as the Merchant Reference Number to theVisa Acceptance SolutionsPlatform during a deposit.
In the Payment Information section, complete these fields:
- In theSupported Payment Methodsfield, select the payment methods that can be processed with this payment processing profile.
- In theGateway Request Typesfield, select the payment actions to enable for the payment processing profile:
- Authorization: Sends an authorization request. When the authorization is approved, you must manually request a capture.
- Sale: Automatically captures the transaction when the authorization is approved.
On the Payment Processing Profile screen, the
Signing
Key
field is marked as mandatory; however, signing keys are not
required for the Cybersource
SuiteApp configuration.Payment Processing Profile: Optional Settings
To define how payments are processed through the
Cybersource
SuiteApp, configure the payment processing profile.These settings are optional, but your
Cybersource
MID configuration or
regional regulations might require some of them.Primary
Complete this field:
- Processor Name: Enter a processor name only when you are processing Level II or Level III transactions.
Fraud Management
Complete these fields:
- Enable Fraud Management: Enable this field when you expect fraud screening responses from theVisa Acceptance SolutionsPlatform. Fraud Screening must still be configured for your MID in theBusiness Center.
- : Specify how to handle transactions with a fraud screening Reject response.Decision ManagerReject
Payment Authentication Configuration
Complete these fields:
- DMPA Required: Enable so that fraud management rules can determine if Payer Authentication3-D Secureshould be used with a transaction.
- Payer Authentication Mode: Choose one of these options:
- Yes: All transactions are processed through3-D Secure.
- No: No transactions are processed through3-D Secure.
- Data Only: Visa and Mastercard transactions are processed through3-D Secure, without challenges. No other card brands are processed with3-D Secure.
- Enforce Strong Consumer Authentication for All Transactions: When this field is enabled, all web store transactions are3-D Securechallenged.
- Enforce Strong Consumer Authentication when Saving Cards: When this field is enabled, any customer saving their card for future purchases is3-D Securechallenged.
Transaction Hold Reason
Complete these fields:
- Hold All Rejected Transactions: When this field is enabled, any transaction that is declined or rejected is marked asOn Holdin NetSuite.
- Hold Transaction Reason Codes: Choose which decline or reject reasons to assign to orders markedOn Holdin NetSuite. This setting is ignored when theHold All Rejected Transactionsoption is enabled. For a list of Reason Codes, see Understanding Reason Codes.
Merchant Defined Data Mapping
: Select up to 20 NetSuite data
elements to pass to the Visa Acceptance Solutions
Platform in
any transaction request. If
these data elements are for fraud screening reasons, the same data elements must be
set in the Business Center
.The data elements must be created in the Merchant Defined Data Mapping custom record
before they can be configured in the Payment Processing Profile. See Map Merchant Defined Data
Fields.
Address Verification (AVS) Rules
Complete these fields:
- Ignore AVS response: When this setting is enabled, the AVS response is ignored.
- Decline AVS flags: Enter the values you want to treat as a decline, separated by commas. By default, N is treated as a decline. WhenIgnore AVS responseis enabled, this setting is ignored. For a list of AVS Codes, see Understanding Address Verification Service (AVS) Result Codes.
Card Verification (CSC) Rules
Complete this field:
- Ignore CSC Response: When this setting is enabled, the CSC/CVV response is ignored.
Override Options
Complete these fields:
- Use Dummy Billing Email Address: When this setting is enabled, a dummy email address is added to a payment transaction when a customer email address is not available.
- Send Token As: If you are usingToken Management Service, choose the TMS token type to use in transactions.
- Network Tokens: If yourCybersourceMID is enabled for Network Tokens, enable this option to tell the SuiteApp to check for Token Life Cycle updates during Sales Order and Cash Sale creation.
- Default PayPal Version: Choose the version that is configured for yourCybersourceMID. To maintain backward compatibility, it can be overridden at transaction level.
Payment Facilitator
Link a Payment Facilitator record to the Payment Processing Profile. See Configure a Payment
Facilitator for more details.
Default Custom Messages and Developer ID
Complete these fields:
- External Reject Message: Enter a custom message to display when a transaction is rejected.
- External Hold Message: Enter a custom message to display when a transaction is kept on hold.
- Developer ID: Enter a developer ID if one has been assigned to the developer or system integrator who supports your implementation.
Tokenization
Complete these fields:
- Replace Payment Card by Token: Enable tokenization of payment cards.
- Payment Card Token Payment Method: Choose the token method used during payment method configuration.
Google Pay
Complete these fields:
- Google Pay Merchant ID: Enter your Google Pay merchant ID.
- Google Pay Merchant Name: Enter the name to display to customers paying with Google Pay.
ACH/eCheck Configuration
In the ACH Configuration section, complete this field:
- Default SEC Code: Choose the default Standard Entry Class (SEC) code for ACH/eCheck transactions. This setting can be overridden for individual payments when required.
In the Tokenization section, complete these fields:
- Replace Payment Card by Token: Enable tokenization of ACH/eCheck accounts.
- General Token Payment Method: Choose the ACH/eCheck token payment method used during payment method configuration.
New Payment Processing Profile View
The New Payment Processing Profile view is an alternative layout for managing payment
processing profiles. It adds the Test Connection feature and the profile-level Enable
Features tab.
To enable the new view, in a payment processing profile toggle
Switch
to New View
. To switch back to
the classic view, toggle Switch
to Classic
View
.Test Connection
The
New View
lets you confirm that the Cybersource
merchant ID and REST shared secret key entered in the payment processing profile are
valid, by testing the connection.A
Test Connection
button is located at the top and bottom of the
Payment Processing Profile screen. Clicking the button validates that the merchant
ID and the REST shared secret key are correct.Map Merchant Defined Data Fields
You can create and configure Merchant Defined Data mapping records for the
SuiteApp.
To create a Merchant Defined Data mapping record, follow these steps:
- From the SuiteApp menu, choose .
- Oncustomdeploy_cs_pymt_map_mdd_mapping_od, clickEditto open the record.
- From theSavedrop-down menu, clickSave and Execute.
ADDITIONAL INFORMATION
This action creates the Merchant Defined Data records. - To view the Merchant Defined Data records you created, from the menu choose .
Configure Webhooks
Some services require a webhook subscription, which you create and configure in the
SuiteApp.
Services Requiring Webhooks
These services require a webhook subscription:
- Visa Acceptance SolutionsInvoicing
Required NetSuite Features
These NetSuite features must be enabled to support webhooks:
Go to to enable features.
- On the Web Presence tab, enable these features:
- Web site
- Host HTML files
- On the SuiteCloud tab, enable these features:
- Client SuiteScript
- Server SuiteScript
- SuiteScript Server Pages
To configure webhooks, go to and enter this information:
- In the Primary Information section, enter a name and description of the webhook.
- In the Webhook Events section, select the webhook events you want.
- In the Symmetric Key Details section, the fields are populated automatically when the webhook subscription is created.
- In the Webhook Configuration section, you can manually enter the merchant credentials for webhook subscriptions or pull the merchant information automatically from an existing Payment Processing Profile or Invoicing Configuration.
When manually entering the merchant credentials, complete these fields:
- In theMerchant IDfield, enter yourCybersourceMerchant ID.
- In theKey IDfield, enter the key ID from your REST shared secret key.
- In theSecret Keyfield, enter the shared secret from your REST shared secret key.
- In theTest Modefield, enable this field only when the webhooks subscription is created in theVisa Acceptance SolutionsPlatform test environment. Leave unchecked for production.
- In theAlways Update Keys from PPPfield, enable this field to automatically apply key updates from the Payment Processing Profile to the webhook subscription.
When automatically entering the merchant credentials, complete these fields:
- In thePayment Processing Profilefield, choose the payment processing profile to collect credentials from.
- In theInvoicing Configurationfield, choose the invoicing configuration to collect credentials from.
When the webhook record is saved, a health check runs. This process can take up to 15
minutes to complete.
Configure SuiteCommerce
You can configure SuiteCommerce to accept payments through
Cybersource
.Your payment requirements determine which steps are required. Additional NetSuite
setup steps might be required. Refer to NetSuite documentation for details.
- From the NetSuite menu, choose .
- Choose the required website and domain and clickConfigure.
- Click theCheckouttab.
- If you are processing with3-D Secure, enable.3-D SecurePayments
- From the menu, choose .
- Edit the payment processing profile to be used for SuiteCommerce.
- Select the required website.
- If you are processing with3-D Secure, selectAuthenticationfrom the Gateway Request Types.
Configure Invoicing
The
Cybersource
SuiteApp supports both NetSuite native invoicing
(payment links) and Visa Acceptance Solutions
Invoicing.You can choose between
Visa Acceptance Solutions
Invoicing or
NetSuite invoicing based on your business requirements.Visa Acceptance Solutions Invoicing
Visa Acceptance Solutions
InvoicingVisa Acceptance Solutions
Invoicing requires that your MID is
enabled for Invoicing and Unified Checkout
.To use Invoicing, your
Visa Acceptance Solutions
MID must
be enabled for Invoicing and Unified Checkout
.- From the menu, choose .
- On the SuiteCloud tab, enableCustom Transactions.
Configure Visa Acceptance Solutions Invoicing
Visa Acceptance Solutions
InvoicingConfigure Invoicing for the
Cybersource
SuiteApp.To configure Invoicing:
- In the menu, choose .
- In the Merchant Details section, complete these fields:
ADDITIONAL INFORMATION
- Name: Enter a name for the configuration.
- Test Mode: Enable this field only when you want the transaction to go to theVisa Acceptance SolutionsPlatform test environment.
- Merchant ID: Enter yourVisa Acceptance SolutionsMerchant ID.
- Key ID: Enter the key ID from your REST shared secret key.
- Secret Key: Enter the shared secret from your REST shared secret key.
- In the NetSuite Invoice Default Value section, set these parameters to be used as the defaults for all created invoices. When necessary, these parameters can be overridden when creating invoices.
ADDITIONAL INFORMATION
- Set as Default MID: Specify a MID as the defaultVisa Acceptance SolutionsMID when processing.
- Use Invoice Number as Pay-By-Link Invoice ID: Use the NetSuite generated invoice number for theVisa Acceptance Solutionsinvoice ID. If this field is left blank,Visa Acceptance Solutionsinvoicing provides the invoice ID.
- Default Invoice Action: Choose one of these options as the default action when creating an invoice:
- Create a draft invoice.
- Create and send the invoice immediately.
- Create an invoice without sending it.
- In the Import Invoice Default Values section, enable theImport Invoicesoption to retrieve invoices from theVisa Acceptance SolutionsPlatform that are not in aPAIDorCANCELLEDstatus.
- Set these defaults as backup values for invoice creation:
ADDITIONAL INFORMATION
- Default Customer
- Item
- Shipping Item
- Tax Item
- Discount Item
- Tax Code
These additional default values might be needed for your NetSuite setup and usage:- Subsidiary
- Location
- Deposit Account
Payment Page Branding
You can configure Invoicing for the
Cybersource
SuiteApp.You can add custom branding to invoices. The branding can be done within the
Business Center
or through the NetSuite configuration. These fields are used in
NetSuite configuration and are optional.- Show VAT Number: Enable to show your VAT number on invoices.
- Delivery Language: Specify the default delivery language.
- Logo File: Upload the logo that you want to appear on invoices. The maximum file size is 1 MB and must be in the gif, jpg, or png format.
- Business Name: Enter your business name.
- Currency: Specify a default currency.
- VAT Registration Number: Enter your VAT number to appear on invoices.
Configure NetSuite Invoicing
NetSuite native invoicing, also called payment links, is configured in NetSuite rather
than in the SuiteApp.
To enable NetSuite invoicing for the
Cybersource
SuiteApp, follow the
directions provided in the NetSuite documentation.Configure a Payment Facilitator
A Payment Facilitator record holds the aggregator and sub-merchant details that a
payment processing profile passes in transactions.
To configure a Payment Facilitator merchant, follow these steps:
- From the SuiteApp menu, choose .
- In theNamefield, enter a name for the record.
- Choose the Aggregator Information tab and complete all of the required fields that are marked with an asterisk.
- Choose the Merchant Information tab and complete all of the required fields that are marked with an asterisk.
- After you configure the Payment Facilitator record, edit the relevant payment processing profile by going to thePayment Facilitatorfield and choosing the required Payment Facilitator record.
- ClickSave.
Feature Management
You can control which features are enabled or disabled within the
Cybersource
SuiteApp at the global and the profile levels.Feature management prevents unwanted features from being configured, so that only the
functionality you need is active. Global settings apply to your whole NetSuite account,
and profile settings apply to an individual payment processing profile.
Configure Global Feature Management
You can enable or disable SuiteApp features for your whole NetSuite
account.
Global feature management enables users to control which features are used within the
Cybersource
SuiteApp. Managing features globally helps avoid the
configuration of unwanted features, ensuring that only necessary functionalities are
active.Follow these steps to enable and disable features globally:
- From the SuiteApp menu, navigate to .
- Select which features to enable (or disable).
Configure Profile Level Feature Management
You can enable or disable SuiteApp features for a single payment processing
profile.
Profile level feature management enables users to control which features are used
within the SuiteApp with each payment processing profile. Managing features at the
profile level helps avoid the configuration of unwanted features, ensuring that only
the necessary functionalities are active.
Follow these steps to enable and disable features at profile level:
- From the SuiteApp menu, navigate to .
- Choose a payment processing profile and ensure that the view isNew View.
- Navigate to theEnable Featurestab.
- Select which features to enable (or disable).
Configure Reporting
To import
Visa Acceptance Solutions
reports into NetSuite, you
must configure reporting.Configure reporting by choosing and completing these fields:
- Merchant ID: Enter yourCybersourceMerchant ID.
- Key: Enter the key ID from your REST shared secret key.
- Secret Key: Enter the shared secret from your REST shared secret key.
- Test Mode: Enable only when you want reports from theVisa Acceptance SolutionsPlatform test environment.
- Conversion Detail Report: Click to enable the fraud screening conversion detail report.
- Report End Date: Specify the date when the report ends. If left blank, there is no end date.
- UnderReporting File Details: Select Payment Batch Detail Report or Transaction Request Report or both.
Order Management
Order Management covers the payment activities you perform on a NetSuite transaction
after the order exists.
With Order Management you manage payment activities that include importing transactions,
importing tokens, capturing authorizations, and processing refunds.
Import a Transaction
You can import an authorization transaction into NetSuite from an external payment
source.
To import an authorization into NetSuite, follow these steps:
- Log in to the SuiteApp.
- Create a new Sales Order or Cash Sale and enter the appropriate details for the order.
- Navigate to .
- Choose the appropriate payment processing profile.
- In theHandling Modefield, chooseRecord External Event.
- In theP/N Reffield, enter theCybersourceRequest ID.
- Choose the appropriatePayment Operation.
- ClickSave.
AFTER COMPLETING THE TASK
You can use a script to import transactions. For further details on using scripts,
refer to NetSuite documentation.
Import a Token
You can import a
Token Management Service
token to a customer record or during a
transaction.There are two ways to import
Token Management Service
tokens:- Direct to customer record
- During a Sales Order or Cash Sale
Import a Token: Direct to a Customer Record
You can import a
Token Management Service
token directly to a NetSuite customer
record.You can import a
Token Management Service
token direct to a customer record:- Select the customer record that needs the token.
- From the menu, choose and selectNew Payment Card Token.
- In thePayment Methodfield, choosePayment Card Token.
- In theTokenfield, enter theToken Management Servicetoken.
- In theToken Familyfield, choose.Cybersource
Import a Token: During the Transaction
You can import a
Token Management Service
token while you create a Sales Order or Cash
Sale.You can import a
Token Management Service
token during a Sales Order or Cash Sale.- While in the Sales Order or Cash Sale, from the menu, choose .
- Click the + icon besidePayment Option.
- In thePayment Methodfield, choosePayment Card Token.
- In theTokenfield, enter theToken Management Servicetoken.
- In theToken Familyfield, choose.Cybersource
ADDITIONAL INFORMATION
Optionally, you can add the expiration date and any substituted card data.
Capture an Authorization
To complete a payment transaction, you must capture the authorization.
To capture an authorization, follow these steps:
- Log in to NetSuite and find and approve the Sales Order.
- ChooseBillorBill Remaining.
ADDITIONAL INFORMATION
This action creates a Cash Sale. - On the Cash Sale page, click theBillingtab.
- In theTransaction Level Typefield, choose one of these options:
ADDITIONAL INFORMATION
- Basic
- Level 2
- Level 3
- Verify that the correct Payment Processing Profile is selected.
- In theHandling Modefield, chooseProcess.
- In thePayment Operationfield, chooseCapture Authorization.
- ClickSave.
Refund a Transaction
You can process a refund for a completed transaction.
To refund a transaction, follow these steps:
- Log in to NetSuite and find the transaction's Cash Sale page.
- Click theRefundbutton to create a cash refund.
- Click theBillingtab.
- In theTransaction Level Typefield, choose one of these options:
ADDITIONAL INFORMATION
- Basic
- Level 2
- Level 3
- Verify that the correct Payment Processing Profile is selected.
- In theHandling Modefield, chooseProcess.
- In thePayment Operationfield, chooseRefund.
- ClickSave.
Invoice Management
You can manage Invoices including creating, updating, resending, canceling, and
searching for invoices.
These invoice management steps are for Invoicing only. For NetSuite invoicing, refer to
the NetSuite user guides.
Create an Invoice
You can create an invoice from a NetSuite invoice record.
Follow these steps to create an invoice:
- From the SuiteApp menu, click thetab.Cybersource
- Select the required Pay-by-Link MID Account.
- Choose thePay-by-Link Create Invoiceaction.
ADDITIONAL INFORMATION
Optionally, you can enter an invoice ID. - To allow partial payments, in thePartial Allowed Amountfield, enter the amount of required partial payment.
- To create an invoice without line items, choose thePay By Link Header Onlyoption.
- ClickSave.
Update an Invoice
You can update an existing invoice.
To update an invoice, follow these steps.
- Edit the invoice record to make the required changes.
- Click thetab and in the Pay-by-Link Create Invoice section, selectCybersourceUpdate.
- ClickSave.
Resend an Invoice
You can resend an existing invoice to the customer.
To resend an invoice, follow these steps:
- Find the invoice.
- Edit the invoice as needed.
- From the menu, choosePay-by-Link Create Invoice.
- ClickSend.
- ClickSave.
Cancel an Invoice
You can void or cancel an existing invoice.
To void or cancel an invoice, follow these steps:
- Find the invoice.
- Edit the invoice as needed.
- From the menu, choosePay-by-Link Create Invoice.
- ClickCancel.
- ClickSave.
Search for an Invoice
You can search for invoices that were created with invoicing. The invoices are
organized into categories.
In the SuiteApp menu, navigate to
>
Cybersource
Integration
> Invoicing
. The
invoices are grouped into these four categories:- : Lists the invoices you created.CybersourceInvoices Created and Sent
- : Lists your paid invoices.CybersourcePaid Invoices
- Errored Invoices When Exporting: Lists the invoice attempts that failed during creation.
- Errored Invoices When Importing: Lists the invoice updates that failed.
Create a Pro-Forma Invoice
You can create pro-forma invoices from sales orders using invoicing.
To create a pro-forma invoice, follow these steps:
- Create a sales order, entering the required details.
- From the menu, choose thetab.Cybersource
- ClickIs Payment Through Order.
- Select the required Pay-by-Link MID account.
- Choose thePay-by-Link Create Invoiceaction.
ADDITIONAL INFORMATION
Optionally, you can enter an invoice ID. - If you want to allow partial payments, in thePartial Allowed Amountfield, enter the partial amount you want.
- To create an invoice without line items, click thePay By Link Header Onlyoption.
- ClickSave.
Support and Troubleshooting
You can get support and help troubleshooting issues with the
Cybersource
SuiteApp for Oracle NetSuite.When you need support or assistance with the
Cybersource
SuiteApp, visit support.visaacceptance.com to
create a support case. You need to provide this information:- Summary of the issue
- Steps to reproduce
- Cybersourcemerchant ID
- NetSuite transaction or order ID
- Cybersourcerequest ID
- SuiteApp version
- Payment processing profile screenshots
- Invoicing configuration screenshots
- Reporting setup screenshots
Run Diagnostics
The Diagnostics page collects the logs and configuration screenshots you need for a
support case.
On the Diagnostics page, select the features or records whose logs and configuration
screenshots you want to download.
In the screenshot of the Payment Processing Profile, the REST
shared secret key is visible. Edit the generated image file to mask the key
before you attach it to a support case.
- In the SuiteApp menu, navigate to .
- SelectAll Logs/Configurationto download all logs and to capture screenshots for all configurations.
View Payment Events
You can view payment event details including the API request and response payloads
for troubleshooting purposes.
Follow these steps to see details about the individual transactions:
- Select a sales order or cash sale you want to troubleshoot.
- From the menu, choose .
ADDITIONAL INFORMATION
On the Payment Events page, you can see an unformatted API request and response payload to aid with troubleshooting.
Release Notes
Release notes for the
Cybersource
SuiteApp for Oracle
NetSuite.Version 26.4.0: August 2026
These enhancements were made:
- 2026.2 Built for NetSuite (BFN) Certification
- Paze Back Office support
- Click to Payupdate
- Network Token Life Cycle management updated
- Transaction Response Display Harmonization
- Reintroduce JWT authentication
- Added workaround to suppress NetSuite auto email for draft invoices
These bugs were addressed:
- Fix for Customer Record Load Error on First-Time Checkouts
Version 26.3.1: June 2026
This bug was addressed:
- Reverted JWT Header back to HTTP signature forCybersourceAPI requests due toCybersourceplatform error
Version 26.3.0: June 2026
These enhancements were made:
- Back office operations support for PayPal v2 and Venmo.
- Added JWT Header forCybersourceAPI requests.
- Support for PayFac Aggregator IDs per card brand.
- Server-side scripting for creating of Pay-by-Link and Pro-Forma invoices.
- Removed unnecessary payment details from follow on requests.
Version 26.2.0: April 2026
These enhancements were made:
- 2026.1 Built for NetSuite (BFN) certification.
- Added support for Pro-forma Invoicing.
- Added workaround to pass line items for multiple Invoices.
- Added Pay-by-Link Invoices payment page configuration.
Version 26.1.0: February 2026
These enhancements were made:
- Added3-D SecureData Only.
- Added multiple3-D Secureprocessing options.
- Added Google Pay payments for SuiteCommerce.
These bugs were addressed:
- Auto Populating MIT fields in Customer Refund.
- Tokenization issues in captures.
Version 25.6.0: December 2025
These enhancements were made:
- Level II/III processing for Visa Platform Connect (VPC).
- Support Hold Reason Codes for Captures.
These bugs were addressed:
- Payment Type field loading issue.
- Screenshot capture failing when exporting logs.
Version 25.5.0: September 2025
These enhancements were made:
- Support for Line-Level Data in authorization requests.
- Added Level III eligibility response field (Chase Paymentech only).
- Ability for merchants to set their own Reconciliation ID.
- Clean up of Follow on Credit requests.
Version 25.4.0: August 2025
These enhancements were made:
- 2025.2 Built for NetSuite (BFN) certification.
- Visa Acceptance SolutionsInvoicing Webhook support.
- Automated Webhook Configuration.
- Ability to accept transactions with CVN code N.
These bugs were addressed:
- Removed dependency on “Available without Login” from Lookup Suitelet.
- Remove passing of field credentialStoredOnFile when Payment Instrument is disabled.
- Combined line items to a single line forVisa Acceptance SolutionsInvoicing when line items exceed 30.
Version 25.3.3: July 2025
This enhancement was made:
- Allow merchants to choose TMS token type.
Version 25.3.2: July 2025
These enhancements were made:
- Strip numeric characters from Bill to first/last name when Decision Manager is enabled.
- Pass TMS paymentInstrumentId instead of TMS customerId.
- Remove including token ID for a follow on credit.
- Collect address line 1 and postal code from payment instrument record instead of customer address.
This bug was addressed:
- NetSuite payment links (invoicing) processing as authorization instead of sale when3-D Secureenabled.
Version 25.3.1: May 2025
This bug was addressed:
- Removed NetSuite dependencies for Webhooks.
Version 25.3.0: May 2025
These enhancements were made:
- Reintroduced support for Network Tokens.
- Support for log type in Pay by Link Invoicing scripts.
- Include street address and postal code from payment instruments.
- Support all Hold Transaction Reason Codes.
- Revised Reauthorization period.
These bugs were addressed:
- Addressed User Event script trigger during Edit operation.
Version 25.2.0: March 2025
These enhancements were made:
- 2025.1 Built for NetSuite (BFN) certification.
- UI to export logs based on chosen features.
These bugs were addressed:
- Corrected commerceIndicator for SuitePayments.
- Addressed Level II/III downgrade warning when Payment Instrument is disabled.
Version 25.1.1: January 2025
These bugs were addressed:
- Latency issue with the Client Script.
- Fix for automatic selection of Enable Features checkbox in Payment Processing Profile.
- 2025.2 Built for NetSuite (BFN) certification.
Version 25.1.0: January 2025
These enhancements were made:
- RemovedCybersourceSOAP APIs.
- Removed support forCybersourceSecure Acceptance.
- Introduced Partner Solution ID forVisa Acceptance SolutionsInvoicing.
- Enhancements to Hold Transaction Reason Codes.
- Enhancements to handling AVS/CVN soft declines.
- 3-D Securebundled with authorization/sale requests.
- Support for DMPA.
- Remove special characters from bill to Company Name before sending request.
- Added Global Feature Management functionality.
- Added new UI for Payment Processing Profile.
- Added Test Connection button.
These bugs were addressed:
- Follow on Refunds for Invoice Payments.
- AVS CSC Values not populating in Payment Event when DM is enabled.
- Search in SUT | LOOKUP script.
- Expiry Date excluded when paying with token.
Version 24.3.0: September 2024
These enhancements were made:
- 2024.2 Built for NetSuite (BFN) certification
- Enable Customer Deposit Number as Merchant Reference Number
- Skip Transaction Hold Reason Codes for WebStore transactions
- Added bill to Company Name
- Resend emails for partially paid Invoices
This bug was addressed:
- log.debug and log.audit errors in Client Scripts
Version 24.2.0: July 2024
These enhancements were made:
- Level II support for American Express Direct
- Level II/III support for FDC Compass
- Level II/III support for FDMS Nashville
Version 24.1.3: June 2024
This bug was addressed:
- Merchant Initiated Transactions incorrectly processed as Customer Initiated Transactions
Version 24.1.2: June 2024
This bug was addressed:
- Merchant Defined Data being duplicated causing timeouts and database operations degrade
Version 24.1.1: May 2024
This enhancement was made:
- Added the date field to the REST HTTP Signature header
Version 24.1.0: April 2024
These enhancements were made:
- 2024.1 Built for NetSuite (BFN) certification
- Decision Manager AVS/CVN rule processing enhancements for REST API
- Strip special characters from beginning of bill to First Name and Last Name
These bugs were addressed:
- Error with standalone ACH/eCheck credits
- $0 item issue for PayPal transactions
- Empty XID for Mastercard transactions
Version 23.5.0: January 2024
These enhancements were made:
- Remove unsupported characters from bill to and ship to fields
- Added support for WEB sec code for ACH/eCheck
- Include line items for Basic transactions
- Level II/III support for Barclaycard Merchant Services
- Remove delete function for Network Tokens
- Capture device information as backup to Cardinal Device Data Collection for3-D Secure
- Decouple3-D Securetransactions from authorization calls
- Removed DMPA support
These bugs were addressed:
- Quantity field for ACH/eCheck REST transactions
- Delay Shipment with Partial Capture
- PayPal Multi-Capture
- Delayed Shipment without Multi-currency
- 2024.2 Built for NetSuite (BFN) certification
Version 23.4.0: September 2023
These enhancements were made:
- Strong Customer Authentication enhancements
- Introduced source based Partner Solution IDs
- Map NetSuite ID on reporting records
- DMPA support
- Payment Facilitator Support
- Network Tokens
- CybersourceHTTP Authentication Signature update
These bugs were addressed:
- Delayed Shipment with Multi-currency
- Declined Sale operations being accepted in NetSuite with SOAP API
Version 23.3.1: August 2023
These enhancements were made:
- 2023.2 Built for NetSuite (BFN) certification
- Company name support for Invoice links
- Multi-select Hold Transaction Reason Codes
- Auto cancel Secure Acceptance Payment Invoices
These bugs were addressed:
- Mastercard Level III processing for TSYS
- Unexpected token in JSON in the User Event Script
- Incorrect fields being passed for MOTO customer initiated transactions
Version 23.3.0.1: July 2023
Patch for anti-clickjacking
Version 23.3.0: June 2023
These enhancements were made:
- Support for PayPal Order Management operations
- SuiteApp optimization
- Raw request/response rendering
- Invoicing rollup feature
- Alternate email address for invoicing
- Webstore Invoice URL support for Secure Acceptance Invoices
- Reinstate dummy email address
- Date search for Transaction Request Report
- Map Payment Batch Detail Report details to NetSuite transactions
These bugs were addressed:
- HTML in Saved Search formula
- REST Reason Code mapping
Version 23.2.0: March 2023
These enhancements were made:
- 2023.1 Built for NetSuite (BFN) certification
- 3-D Securev2 REST API support
These bugs were addressed:
- Secure Acceptance Invoice Payment Reject scenario
- Secure Acceptance Alphanumeric Transaction IDs
- Log.error
- Customer Name special characters
Version 23.1.0: January 2023
These enhancements were made:
- Introduction of REST APIs
- Warning message if transaction data does not meet Level II/III criteria
- Invoice payments through webstore
- Unit of Measure abbreviation
- Secure Acceptance request/response on the same Payment Event
- $0 filtering for Sale Transaction Requests
Version 22.2.2: September 2022
These enhancements were made:
- International AVS CVN support
- Secure Acceptance tokenization
- Secure Acceptance Hold Transaction Reason Codes
- Default SEC code for ACH/eCheck
- Reporting Fields mapping updated
- Field validation updated
These bugs were addressed:
- Invoicing secondary tax issue
- Void transactions error
Version 22.2.1
These enhancements were made:
- Level II/III processing support
- Secure Acceptance Strong Customer Authentication
- Enhanced Secure Acceptance flow
- Ability to customize Secure Acceptance Cancel Pending time gap
This bug was addressed:
- getAddressee issue
Version 22.2.0
These enhancements were made:
- 2022.2 Built for NetSuite (BFN) certification
- External MIT initial authorization support
- Redirect message display for External Checkout
- AVS/CVN Response Code display for Sale transactions
- Invoicing import optimization
- Installed SuiteApp version display
- Payment Method Mapping simplification
- Default Merchant ID for invoicing configuration
- Default create action for invoicing configuration
- Default Invoice ID to NetSuite Invoice mapping
- ACH/eCheck support
These bugs were addressed:
- Auth response issue
- $0 shipping and handling for Customer Deposit
Version 22.1.0
These enhancements were made:
- 2022.1 Built for NetSuite (BFN) certification
- Group email update on SuiteApp configuration page
- Merchant ID and SOAP Key ID marked mandatory on Payment Processing Profile
- Level II/III support for Elavon Americas
- Display error message on Payment Event Details
- $0 shipping and handling for Customer Deposit
- Pay by Link Invoice amount based on NetSuite Invoice Due Amount
- Pay by Link Invoice hyperlink update
- Saved Search for Execution Logs
- Get Secure Acceptance URL
Version 21.1.0: December 2021
This enhancement was made:
- Hold NetSuite UI transactions with Reason Codes
Version 1: September 2021
Initial release supporting:
- Payments for SuiteCommerce/SuiteCommerce Advanced using NetSuite checkout or Secure Acceptance redirect
- Secure Acceptance Payer Authentication/3-D Secure
- Order Management for Apple Pay, Google Pay, and PayPal
- Level II/III support for GPN
- Level II/III support for Chase Paymentech
- Level II/III support for FDC Nashville Global
- Level II/III support for TSYS
- Level II/III support for Omnipay Direct
Upgrade the SuiteApp
You upgrade the
Cybersource
SuiteApp for Oracle NetSuite from the
SuiteBundler.To upgrade to the latest version of the
Cybersource
SuiteApp for
Oracle NetSuite, follow these steps:- From the NetSuite menu, choose .
- UnderKeywordsenterand clickCybersourcefor Oracle NetSuiteSearch.
- Verify that theBundle IDis316818.
- In the Name column, click on.Cybersourcefor NetSuite
- ClickUpdate.
- In the Preview Bundle, ensure thatReplace Datais selected for these options:
ADDITIONAL INFORMATION
- API response code/message
- Processor name
- Sec code
- Start the update by clickingUpdate Bundle.
Frequently Asked Questions
These are frequently asked questions about the
Cybersource
SuiteApp
for Oracle NetSuite.How do I change or add a Payment Logo?
These NetSuite Guides explain how to work with a payment logo:
How do I check Card Mapping or add a Local Scheme?
- From the SuiteApp menu, choose .
- Select the custom recordCard Type Mapping, and clickList. A list of card brands and the associated card type IDs appears.
- To edit an existing card brand, clickEditon the required card type line and make your changes.
- To add a new brand, clickNew Card Type Mapping, and enter the name, card type ID, and card type name.
- For the list ofVisa Acceptance Solutionscard type IDs, seepaymentInformation.card.cardTypein theREST API Field Reference.
Why are Merchant Initiated Transactions not processing with a Custom Role?
Verify that you have provided the Payment Instrument permission to the custom
role.
The
Payment Type
field in a sales order or cash sale is only
supported when the NetSuite Payment Instrument feature is enabled.What do I need to consider when processing a Merchant Initiated Transaction with an imported TMS token?
When processing a transaction with an imported token, ensure that the associated
Network Transaction ID is entered into the
Payment Network
Reference
field.What Acquirers/Processors are supported by the Cybersource
SuiteApp?
Cybersource
SuiteApp?The
Cybersource
SuiteApp is processor agnostic, but note that Level
II and Level III processing is only supported for these processors:- American Express Direct (Level II only)
- Barclaycard Merchant Services
- Chase Paymentech Solutions
- Elavon Americas
- First Data Compass
- First Data Nashville Global
- Global Payments Network
- OmniPay Direct
- TSYS Acquiring Solutions
- Visa Platform Connect
Can I pass my own Reconciliation ID?
To pass your own Reconciliation ID, populate the
Reconciliation
ID
field in the Payment subtype of the transaction record before
processing the transaction.OpenCart
The Visa Acceptance Solutions plug-in for OpenCart connects your OpenCart store to
the
Cybersource
platform, enabling secure and flexible payment
acceptance.Supported Features
The Visa Acceptance Solutions OpenCart integration supports these payment methods and security
features.
Payment Methods and Features
- Credit and debit cards
- Apple Pay
- Google Pay
- Click to Pay
- Paze
- PayPal
- Venmo
- Payer Authentication for 3-D Secure
- Tokenization including network tokens
- Fraud Management EssentialsCybersourceDecision Manager and
- Tax calculation
Supported Versions
This topic lists version compatibility for the OpenCart integration.
Compatibility Requirements
The OpenCart integration works with OpenCart 3.0.3.9 to 3.0.5.1 and PHP 8.2+.
Release Notes
Version history and changes for the OpenCart integration.
Version 3.0.0
Compatible with OpenCart v3.0.3.9 to v3.0.5.1
- Switched to Semantic Versioning
- Migrated toUnified Checkoutv1.x includingUnified Checkoutbecoming responsible for calling Payer Authentication, Tokenization, and fraud screening.
- Added webhook support for payment response and fraud management
- Offer Sidebar and Embedded display forUnified Checkoutwidget
- Support for PayPal and Venmo
- ACH/eCheck reintroduced
- Full Message Level Encryption (MLE)
- Network Token Support
- Upgraded to Cybersource REST PHP SDK v0.0.75
Bug Fixes:
- Address line exceeding Unified Checkout limit addressed.
Version 26.1.0
Compatible with OpenCart v3.0.3.9 to v3.0.5.0
- Upgraded Unified Checkout to v0.35
- Upgraded to Cybersource REST PHP SDK v0.0.71
- Replaced authorization/sale API calls with Unified Checkout Complete Mandate
- Replaced standalone Apple Pay support with Unified Checkout Apple Pay
- Temporarily removed eCheck/ACH support
- Message Level Encryption (MLE) support for requests
- Replaced legacy Cybersource endpoints with Visa Acceptance Solutions endpoints
- Added China UnionPay and Jaywan payment methods
- Added Microform for securely capturing CVV for saved card transactions
- Added display of additional response fields in back office order screens
Bug Fixes:
- JSON error when line items had special characters
- Fixed the order 'Add History' button issue
Version 24.1.0
Compatible with OpenCart 3.0.3.7, 3.0.3.8 and 3.0.3.9
- Added support for Unified Checkout (Card Payment, Google Pay and Click to Pay)
- Added support for Network Tokens
- Added support for Apple Pay
Prerequisites
These required and optional products must be configured before using the Visa
Acceptance Solutions OpenCart integration.
Required
This product must be enabled and configured for your Merchant ID:
- Unified Checkout
You must also have a REST Shared Secret Key Pair and a Response MLE Key.
Optional
These products are optional. If you choose to use any of these products, they must be
enabled and configured for your Merchant ID:
- Decision Manager
- Fraud Management Essentials
- Network Tokens
As of version 3.0.0, accepted card brands, payment methods, Payer Authentication for
3-D Secure
, fraud screening, and payment action are configured and
enabled in the Business Center
. For more information, see the
Unified Checkout Developer
Guide
.Required Environment Prerequisite
The GMP PHP extension must be enabled on your MAMP or XAMPP server for JSON Web Token messaging.
Install OpenCart
Install the Visa Acceptance Solutions module from
the OpenCart marketplace.
To install the module, complete these steps:
- Download our extension from OpenCart.
- Log in to your OpenCart admin account.
- Go to .
- ClickUploadand select the module file.
- Go to and chooseModulesfrom the drop-down menu.
- Scroll down toVisa Acceptance Solutions Configurationand click theInstallbutton.
- Go to and choosePaymentsfrom the drop-down menu.
- Scroll down toVisa Acceptance Solutions Unified Checkoutand click theInstallbutton.
- From the OpenCart menu, choose and chooseOrder Totalsfrom the drop-down menu.
- Scroll down toVisa Acceptance Solutions Taxand click theInstallbutton.
Configuration
The Visa Acceptance Solutions OpenCart module
requires configuration in three areas: general settings, payment methods, and tax
calculation.
The Visa Acceptance Solutions OpenCart module requires
configuration in three areas:
- Visa Acceptance Solutions Configuration: General settings
- Visa Acceptance Solutions Unified Checkout configuration: Payment method settings
- Visa Acceptance Solutions Tax Calculation configuration: Tax service settings (optional)
Each configuration area has specific settings that control different aspects of the payment processing functionality.
Configure the General Settings
You must configure the general settings for the Visa Acceptance Solutions
module.
Access the Module Configuration
You can access the configuration module
by choosing and choosing Modules
from the drop-down menu.
Scroll down to
Visa Acceptance Solutions Configuration
and click
Edit
to view and complete the settings below. General Configuration settings
- Sandbox Mode: For testing your test account, set toEnabled. For production transactions, set toDisabled.
- Merchant ID: Enter the transacting merchant ID (MID) assigned to you when you set up your account.
- Merchant Key ID: Enter the key from your REST API shared secret key.
- Merchant Secret Key: Enter the shared secret from your REST API shared secret key.
- Key File Path: Enter the path and filename for the Response MLE certificate created inBusiness Center.
- Key Password: Enter the password for the Response MLE certificate.
- Response MLE: Set toEnableto use Response MLE.
- Fraud Management: Set toEnableto inform the module that yourCybersourceaccount is configured for fraud screening and needs to subscribe to the REVIEW webhook notification.
- Delivery Address Verification: When enabled, the module checks that the delivery address is correct. This is a chargeable service.
- Status: Set toEnableto use the module.
The Response MLE is required for the
transaction webhook response and must be added even if you are not enabling
Response MLE.
Enhanced Logs
Enable only when you are troubleshooting issues.
Reporting Configuration
- Payment Batch Detail Report: SeePayment Batch Detailfor details. This report must be enabled in theCybersourceBusiness Center. When enabling, set the download path.
- Transaction Request Report: SeeTransaction Requestfor details. This report must be enabled in theCybersourceBusiness Center. When enabling, set the download path.
The report functionality is designed to work with a scheduler. You can use any
OpenCart supported Cron Job module or other online Cron service provider for the
required scheduler functionality. The reporting URL is
extension/payment/cybersource/cron
.Order Status Configuration
You can change the mapping of order statuses based on transaction outcomes. These
statuses are pre-set with the recommended mapping.
Registered Webhooks
View information about subscribed webhooks. Webhooks are automatically subscribed to
based on your configuration settings.
Webhooks can be deleted, but this may affect transaction response
handling.
Configure Unified Checkout Settings
Unified Checkout
SettingsConfigure the
Unified Checkout
payment method settings.- Go to and choosePaymentsfrom the drop-down menu.
- Scroll down toVisa Acceptance Solutions Unified Checkoutand click theEditbutton and configure these options.
ADDITIONAL INFORMATION
- Checkout Label: This text is displayed on your checkout page to your customers.
- Status: Set toEnableto use the module.
- Unified Checkout Display Mode:
- Embedded: The payment widget loads within the browser page.
- Sidebar: The payment widget appears to the side of the browser.
- Sort Order: Specify the order in which the payment methods are displayed during checkout.
- Tokenization: Set toEnableto allow your customers to save their cards for future payments.
- Network Token Updates: Enable this option if your MID is enabled for network tokens.
- Checkout Version: Optional field to force a version of Unified Checkout. Format 1.x. It is recommended to leave this blank to always take the latest version.
Configure Tax Calculation
The optional tax calculation service settings require minimal
configuration.
- From the menu, choose and chooseOrder Totalsfrom the drop-down menu.
- Scroll down toVisa Acceptance Solutions Taxand clickEdit.
- To use the module, setStatustoEnable.
Order Management
Reverse, capture, refund, and void OpenCart orders from the back office.
Orders are marked differently depending on the
Unified Checkout
payment
processing choice.- Authorize: When this option is chosen, successful transactions are marked asAwaiting Payment.
- Sale: When this option is chosen, successful transactions are marked asProcessed.
Reverse an Authorization
To reverse an authorization, enter the order in your OpenCart back office and click
Cancel
.Capture an Order
To capture an order, enter the order in your OpenCart back office and click
Capture
. Alternatively, you can click Partial
Capture
and choose which part of the order to capture and click
Yes
.Refund an Order
To refund an order, enter the order in your OpenCart back office and click
Refund
. Alternatively, you can click Partial
Refund
, choose which part of the order to refund and click
Yes
.Void an Order
To void an order, enter the order in your OpenCart back office and click
Void/Void
Capture/Void Refund
.Support and Troubleshooting
Contact support and find troubleshooting resources for the OpenCart integration.
Getting Support
If you require support with installing, configuring, or using this extension, go to
Customer Support to raise a support
case.
For resold accounts,
contact your reseller first.
Required Information
Provide this information:
- Summary of the issue
- Steps to reproduce the issue
- OpenCart version
- Visa Acceptance Solutions extension version
- CybersourceMerchant ID
- Configuration screenshots
- List of additional themes and extensions installed
- Log file
- Any additional information related to the issue
Upgrade the Extension for OpenCart
Upgrade the Visa Acceptance Solutions OpenCart module to the latest version.
Complete these steps to upgrade to a later version of the Visa Acceptance Solutions
OpenCart extension:
- Make a note of the existing Visa Acceptance Solutions configuration values.
- Go to and chooseModulesfrom the drop-down menu. Scroll down toVisa Acceptance Solutions Configurationand clickUninstall.
- Go to and choosePaymentsfrom the drop-down menu. Scroll down toVisa Acceptance Solutions Unified Checkoutand clickUninstall.
- Go to and chooseOrder Totalsfrom the drop-down menu. Scroll down toVisa Acceptance Solutions Taxand click theUninstallbutton.
- Go to and deletevisaacceptance.ocmod.zip.
- Go to and verify that theVisa Acceptance Solutions modificationwas removed.
- To upgrade to the latest version, follow the steps in Install OpenCart.
Optional Configuration
Additional optional configurations can be applied based on your specific
requirements.
Alternative and Digital Payment Methods
Apple Pay can be a standalone options, or it can be offered as payment options with
Click to Pay
within Unified Checkout
.- To configureUnified Checkout, go to .
- In theDigital Payment Methods infield, select Apple Pay, Google Pay, orUnified CheckoutClick to Pay. You can choose any or all of the options.
ADDITIONAL INFORMATION
If you are usingUnified Checkoutfor digital payment methods, the payment methods must be enabled for your Merchant ID in theBusiness Center. For more information about enabling digital payments, see Configure Payment Options. - EnableUnified Checkoutfor Cart and Mini Cart: Enable this option to display digital payment methods for quick checkout on the cart and mini cart pages.
- Go to and confirm that these options are enabled for the methods you accept:
ADDITIONAL INFORMATION
- DW_APPLE_PAY: Verify that the Payment Processor isPAYMENTS_APPLEPAY.
- DW_GOOGLE_PAY: Verify that the Payment Processor isPAYMENTS_GOOGLEPAY.
- DW_PAZE: Verify that the Payment Processor isPAYMENTS_PAZE.
- CLICK_TO_PAY: Verify that the Payment Processor isPAYMENTS_CLICK_TO_PAY.
- PAYPAL: Verify that the Payment Processor isPAYMENTS_PAYPAL.
- VENMO: Verify that the Payment Processor isPAYMENTS_VENMO.
- BANK_TRANSFER: Verify that the Payment Processor isBANK_TRANSFER.
- Standalone Apple Pay Configuration
- To enable Apple Pay outside ofUnified Checkout, follow the Salesforce guide.
ADDITIONAL INFORMATION
ThePayment Provider URLis:- Test:https://apitest.visaacceptance.com/partner/demandware/payments/v1/authorizations
- Production:https://api.visaacceptance.com/partner/demandware/payments/v1/authorizations
ForPayment Provider Merchant ID, enter yourCybersourceMerchant ID.Use Basic Authorizationshould be unchecked. - To choose between processing as authorization or sale, go to .
Configure Apple Pay Standalone
To offer Apple Pay outside of
Unified Checkout
, enable Apple Pay in your Salesforce
B2C Commerce store.Before you begin, complete Integrating Apple Pay into Your System.
- ConfigureSalesforceBusiness Manager.
- From the menu, choose .
- Select theApple Pay Enabled?check box.
- Complete the Onboarding form:
ADDITIONAL INFORMATION
- Ensure that the Apple Merchant ID and the Apple Merchant Name values you enter match the settings in your Apple account.
- Ensure that all other fields match your supportedCybersourcesettings.
- Country Code: Enter the country code for the location of your site. The country code is a two letter ISO 3166 country code (for example,US).
- Merchant Capabilities: Check the box for 3-D Secure; leave the other fields unchecked.
- Supported Networks: Select the types of payment you support;Amex,Mastercard, andVisaare supported byCybersource.
- Required Shipping Address Fields: Select the fields that are required on the shipping form.CybersourcerecommendsEmail,Name,Phone, andPostal Address.
- Required Billing Address Fields: SelectNameandPostal Address.
- Complete the Storefront Injection form.
ADDITIONAL INFORMATION
Select where to display Apple Pay buttons on your site. - Complete the Payment Integration form.
ADDITIONAL INFORMATION
- Use Commerce Cloud Apple Pay Payment API?Checked.
- Payment Provider URL:
- Test:https://apitest.Cybersource.com/partner/demandware/payments/v1/authorizations
- Production:https://api.Cybersource.com/partner/demandware/payments/v1/authorizations
- Payment Provider Merchant ID: Enter yourCybersourcemerchant ID.
- API Version: v1.
- Use Basic Authorization?Unchecked.
- Payment Provider User: —
- Payment Provider Password: —
- Use JWS?Set toYes.
- JWS Private Key Alias: Merchant.p12 Key Alias.
Step Result
The private key alias is generated when you upload your.p12key file (fromCybersourceself-serve) toSalesforceBusiness Manager under . - ClickSubmit.
- Register your domain inSalesforceBusiness Manager.
- Go to .
- Under the Domain Registration section, complete these fields:
ADDITIONAL INFORMATION
- In the Apple Sandbox section, clickRegister Apple Sandboxto registerSalesforceB2C to the Apple Sandbox account.
- In the Apple Production section, clickRegister Apple Productionto registerSalesforceB2C to the Apple Production account.
- Set the transaction type.
ADDITIONAL INFORMATION
Go to and chooseAuthorizationorSale.
Configure Google Pay Standalone
To offer Google Pay outside of
Unified Checkout
, follow these steps to enable Google Pay in your Salesforce
B2C Commerce store.- Go to .
- On the Google Pay page, configure these settings:
ADDITIONAL INFORMATION
- Enable Google Pay: Enable.
- Enable Google Pay on Mini Cart: Enable to show Google Pay as a checkout option in the mini cart.
- Enable Google Pay on Cart: Enable to show Google Pay as a checkout option in the cart.
- Google Pay Merchant Id: Enter your Google Pay merchant ID (for live processing only).
- Google Pay Environment: ChooseTestfor testing orProductionfor live.
- Google Pay Transaction Type: ChooseAuthorizationorSale.
Fraud Screening
Enable Fraud Screening to alert the cartridge to look for fraud screening responses.
Fraud Screening profiles must be set up in the
Business Center
.Follow these steps to enable fraud screening:
Decision Manager settings apply to the Salesforce default card form (Direct
API) only.
- Go to .
- Choose theEnableoption.Decision ManagerServices
- Set theConversion Detail Report Lookback Timevalue.
ADDITIONAL INFORMATION
If you are using REVIEW rules and configure theDecision ManagerUpdate Job, set the number of hours to look back for updates to transactions in REVIEW status. The maximum value is 24 hours. - To enable theDecision ManagerUpdate Job to poll for updates to the reviewed transactions, go to and selectPayment:. Set these values:Decision ManagerOrder Update
ADDITIONAL INFORMATION
- ID: Enter a job ID.
- Description: Enter the job description.
- ExecuteScriptModule.Module: int_cybs_sfra_base/cartridge/scripts/jobs/DMOrderStatusUpdate.js
- ExecuteScriptModule.FunctionName: orderStatusUpdate
- ExecuteScriptModule.Transactional:
- True: All changes occur as a single atomic operation. If any error occurs during the job, the system rolls back all changes to maintain data consistency.
- False: No automatic rollback is applied. Merchants must handle transaction logic manually. This is often preferred for large batch jobs.
- ExecuteScriptModule.TimeoutInSeconds: Set the function timeout value.
Delivery Address Verification
To verify the customer's shipping address during checkout, configure Delivery Address
Verification services.
- Go to .
- Enable theDelivery Address Verification Servicesoption.
Tax Calculation
To calculate local taxes once the customer enters their address at checkout,
configure the Tax Calculation services.
- Go to and set these options:
- Enable theEnable Tax Calculationfield.
- Configure these tax settings:
ADDITIONAL INFORMATION
- List of Nexus States: List the states to calculate tax for.
- List of Nexus States to Exclude: List the states to not calculate tax for.
- Merchants VAT Registration Number: Enter your VAT registration number if you have one.
- Default Product Tax Code: Enter the default tax code to use for products in the basket without a tax code.
- Purchase Order Acceptance City
- Purchase Order Acceptance State Code
- Purchase Order Acceptance Zip Code
- Purchase Order Acceptance Country Code
- Purchase Order Origin City
- Purchase Order Origin State Code
- Purchase Order Origin Zip Code
- Purchase Order Origin Country Code
- Ship From City
- Ship From State Code
- Ship From Zip Code
- Ship From Country Code
RESULT
If you enable Tax Calculation and do not specify any states in
the List of Nexus States or List of Nexus States to Exclude, Tax Calculation assumes
every state or province is taxable. You can leave either the
List of
Nexus States
or the List of Nexus States to
Exclude
as empty, but you cannot leave both empty.Order Management
Salesforce
B2C Commerce does not natively support order management functions. This cartridge has functions that can be used to process captures and authorization reversals.These functions must be customized before use in the
Salesforce
B2C Commerce user interface.The ServiceFrameworkTest example controllers referenced below are for testing
only. Access is granted only when
all
of the following are true:- The Salesforce instance isnota production instance.
- TheEnable Visa Acceptance Test Endpointspreference (Custom Preferences > Visa Acceptance Cartridge configuration) is enabled. It is disabled by default.
- The caller is anauthenticated, registered customerwho is a member of theVisaAcceptanceTestAdmincustomer group
The VisaAcceptanceTestAdmin customer group is not created by the metadata import — you
must create it in Business Manager under
Merchant Tools > Customers > Customer
Groups
and assign it only to authorized merchant staff. Only members of this
group can access the test endpoints; any request from a non-member (or an
unauthenticated visitor) is redirected to the home page.Capture
The capture function can be found in the script
scripts/http/capture.js
. A
working example is available in the ServiceFrameworkTest-TestCaptureService
controller.Reference the capture.js object and make this request:
var captureObj = require("~/cartridge/scripts/http/capture.js"); var serviceResponse = captureObj.httpCapturePayment(requestID, merchantRefCode, paymentTotal, currency);
The resulting serviceResponse object contains the full response object generated by
the request. The contents of this object determine your logic in handling errors and
successes. These are the Capture request parameters:
Capture Request Parameters:
- requestID: TheCybersourceRequest ID from the initial authorization.
- merchantRefCode: TheSalesforceOrder Number.
- purchaseTotal: The capture amount.
- currency: Currency Code.
Function Signature:
httpCapturePayment(requestID, merchantRefCode, purchaseTotal, currency)
Authorization Reversal
The authorization reversal function can be found in the script called
scripts/http/authReversal.js
. A working example is in the
ServiceFrameworkTest-TestAuthReversal controller.Reference the AuthReversal.js object and make this request:
var reversalObj = require("~/cartridge/scripts/http/authReversal.js"); var serviceResponse = reversalObj.httpAuthReversal(requestID, merchantRefCode, paymentTotal, currency);
The resulting serviceResponse object contains the full response object generated by
the request. The contents of this object determine your logic in handling errors and
successes. These are the Authorization reversal request parameters:
Authorization Reversal Request Parameters:
- requestID: TheCybersourceRequest ID from the initial authorization.
- merchantRefCode: TheSalesforceOrder Number.
- purchaseTotal: The reversal amount.
- currency: Currency Code.
Refund
The refund function can be found in the script called
scripts/http/refund.js
.
A working example is in the ServiceFrameworkTest-RefundService controller.Reference the refund.js object and make this request:
var refundObj = require("~/cartridge/scripts/http/refund.js"); var serviceResponse = refundObj.httpRefundPayment(transactionId, merchantRefCode, paymentTotal, currency, refundEndpointType);
The resulting serviceResponse object contains the full response object generated by
the request. The contents of this object determine your logic in handling errors and
successes. These are the Authorization reversal request parameters:
Authorization Reversal Request Parameters:
- requestID: TheCybersourceRequest ID from the capture or sale.
- merchantRefCode: TheSalesforceOrder Number.
- paymentTotal: The refund amount.
- currency: Currency Code.
- refundEndpointType: 'payments' for ACH/eCheck amd 'captures' for all other payments
Function Signature:
httpRefundPayment(transactionId, referenceInformationCode, total, currency, refundEndpointType)
Refunds are capped at the remaining refundable balance. A
refund (whether full, a single partial, or the running total of multiple
partials) that exceeds the captured amount is rejected before the gateway
call.
Customization
The Visa Acceptance cartridge for
Salesforce
B2C Commerce has
built-in custom hooks that can be used to customize the request data that is sent to each
service.These hooks can send additional custom data, such as Merchant Defined Data for authorization requests.
How Custom Hooks Work
After a request for a particular service is built, there is a check for any code
registering to the hook
app.payment.modifyrequest
. If present, the
hook is called for that specific request and the request object is passed into the
hook. The return value of the hook is sent to Cybersource
as the
final request object. Through this process, you can inject your own data into the
request object from the custom code you write in a separate cartridge.Implementation
To customize request objects, register the hook
app.payment.modifyrequest
in your cartridge's hooks.json
file. An example would look like this, replacing the script path with your own
script:{ "name": "app.payment.modifyrequest", "script": "./cartridge/scripts/hooks/modifyRequestExample" }
You can copy the for
information about any field you want to customize or add.
scripts/hooks/modifyRequestExample
script from this cartridge
into your own to use as a template for extending and modifying service request
objects. Note that every hook must return a valid request object for the given
service. Refer to the Cybersource
REST API Field ReferenceSupport and Troubleshooting
Getting Support
If you require support with this extension, visit support.visaacceptance.com to
raise a support case.
Required Information for Support Cases
Provide this information for your support case:
- Summary of the issue.
- Steps to reproduce the issue.
- CybersourceB2C Commerce cartridge version.
- CybersourceMerchant ID.
- Configuration screenshots: Provide screenshots of custom preference configurations.
- Log file and other relevant data: Download the logs from .
Release Notes
Release history and updates for the Visa Acceptance
Salesforce
B2C Commerce cartridge.Version 2.0.0 (August 2026)
Versioning changed from Calendar Versionion to Semantic Versioning
Enhancements:
- Renamed integration from Cybersource to Visa Acceptance Solutions
- UpgradedUnified Checkoutto version 1.x, supporting multiple payment methods and services in a single integration
- Added Refund function
- Added webhook notifications for Fraud Screening andUnified Checkoutevents
- Added new Business Manager cartridgebm_cybs_sfra, including webhook manager page.
- Reorganised meta and site preference groupings
- Updated the authentication method to JSON web token
- Full support for Message Level Encryption
Changes:
- Business Manager controls for Payer Authentication (including SCA), Decision Manager, and Transaction Type now only applies to the Salesforce default card form (direct API).
- Unified Checkoutpayment methods/services now configured inBusiness Center
- Google Pay now only supported throughUnified Checkout
- Replaced Network Token lifecycle notifications with API based updates
- Added webhook notifications for Fraud Screening and Unified Checkout events
- Replaced Network Token lifecycle notifications with API based updates
Security:
- Addressed security issues
Removed:
- Microform
Version 26.2.0 (March 2026)
Enhancements:
- Updated Payer Authentication flow to align with SFRA best practices
- Added fallback device data capture for Payer Authentication
- Updated Mastercard3-D SecureData Only transactions
- Updated Cardinal Commerce URLs for Data Center Migration
- Modified subscription creation during the authorization call in checkout
- Decision Manager support for Apple Pay Transactions
- Apple Pay address handling improvements
- Checkout page: collect address from checkout page
- Cart/Mini Cart page: collect address from Apple Pay
Bug Fixes:
- Corrected page routing for failed Apple Pay scenarios
- Fetch the total amount from the server side instead of capturing it on the frontend to avoid issues for different currencies across different locales
- Correct handling of AUTHORIZED_RISK_DECLINED response for post authorization scenarios
- CheckoutServices Error Fix: Resolved TypeError occurring when the cartridge is disabled
- Fixed issue where the Unified Checkout capture context did not refresh when the Delivery Address Verification is enabled
- Corrected page redirection issue for Decision Manager reject scenarios
- Fixed bug causing "setAddress1" of null when performing follow‑up transactions with a registered customer after updating shipping address.
- Fixed issue where the eCheck transient token exceeded the session.privacy 2000‑character limit
Version 26.1.0 (January 2026)
New Feature:
- Added support for3-D SecureData Only transactions.
Version 25.4.0 (December 2025)
New Feature:
- Added support forUnified Checkoutv0.32 (Card Payments, Apple Pay, Google Pay,Click to Pay, andeCheck).
Enhancement:
- End of support forClick to Paylegacy.
Version 25.3.0 (May 2025)
New Features:
- AddedPayer Authenticationsupport for Google Pay.
- Added multi-currency support for Google Pay.
Bug Fixes:
- Handled session variables in SCA flow.
- Removed encryption type from Microform v2 request.
Version 25.2.0 (March 2025)
New Feature:
- Message-Level Encryption (MLE).
Enhancement:
- Added support for Cartes Bancaires, Elo, China UnionPay, and JCB.
Version 25.1.0 (January 2025)
New Feature:
- Replaced Microform v0.11 with v2.
Bug Fixes:
- Added webhook subscription deletion if the subscription is deleted atCybersourceorSalesforcecustom object.
- Handled undefined exception scenario for3-D Securetransactions.
Version 24.4.0 (September 2024)
New Feature:
- DMPA support.
Enhancement:
- Upgraded to jQuery v3.7.0.
Version 24.3.0 (August 2024)
Enhancements:
- Upgraded the cartridge to support SFRA v7.0.
- Added MOTO Commerce Indicator.
Version 24.2.1 (May 2024)
Bug Fixes:
- Checkmarx issues fixed.
- Device fingerprint bug fixed.
Version 24.2.0 (April 2024)
New Features:
- Network token support
Enhancements:
- Implemented Direct API integration forPayer Authentication, adding Payer Authentication Setup and Device Data Collection.
- Enhanced Strong Consumer Authentication (SCA).
Version 24.1.0 (February 2024)
New Features:
- Added Strong Customer Authentication retries for card payments.
Enhancements:
- SFRA v6.3 support.
- SalesforceB2C Commerce Release 22.7 support.
- Renamed Visa SRC toClick to Pay.
- Implemented Sale functionality for Credit Card, Google Pay,Click to Payand Apple Pay.
- Updated flex script referring from v0.11.0 to v0.11.
- Updated API header in Http Signature Authentication.
Version 21.1.0 (June 2021)
Enhancements:
- ImprovedPayer Authenticationscreen (modal).
Bug Fixes:
- Added descriptive error messages on certain fail cases and invalid inputs.
- Reloading on the final confirmation page does not result in a failed authorization.
Version 20.2.0 (February 2021)
New Features:
- Google Pay
- Visa Secure Remote Commerce payment method
- Improved the security on the My Account page by adding Microform to tokenize payment cards.
Bug Fixes:
- Improved the security of keys by changing data type of password fields fromStringtopassword.
- Added more security to the exposed parameters of device fingerprint.
Version 20.1.1 (November 2020)
Bug Fixes:
- Improved the security on accessing and modifying sensitive fulfillment-related actions on an order (for example, order acceptance, canceling etc.).
Version 20.1.0 (August 2020)
Initial release supporting:
- Credit/debit cards
- Apple Pay
- Payer Authentication/3-D Secure
- Delivery Address Verification service
- Tax Calculation service
- Authorization, Capture, Authorization Reversal
Built by Our Partners
Explore solutions built by our industry-leading partners that offer real-time fraud
screening, account takeover protection, and comprehensive payment solutions. Our
partners provide potential use cases such as personalizing shopping experiences through
advanced analytics. Offer your customers a seamless omnichannel experience and improve
site performance for higher customer satisfaction. Benefit from the centralized
management of product information, automated order processing and fulfillment, and
real-time data synchronization between SAP Commerce Cloud and existing ERP systems.
Moreover, our partners' solutions offer scalable infrastructure, flexible integration
capabilities, advanced reporting tools, and enhanced visibility into supply chain and
inventory management.
This solution is built by our partners:
BigCommerce
BigCommerce
BigCommerce
provides a software-as-a-service (SaaS) payment
platform where you can manage your online business. BigCommerce
provides customizable functionality ready for you to build and integrate with
Cybersource
. This section describes the payment methods and
services that the platform provides. These payment features and methods are
supported: - Card Payments
- Apple Pay
- Google Pay
- 3-D Secure
- Token Management Service
- Decision ManagerandFraud Management Essentials
- OAuth for connecting yourBigCommerceaccount withCybersource
Release Information
This section provides information about the releases for
BigCommerce
.Version 2 includes these features:
- Global availability in more than 190 countries
- Transaction currency support in all available countries
- Support for the these card brands:
- American Express
- Diners Club
- Discover
- JCB
- Maestro
- Mastercard
- Visa
For more information, see New Features Available in
Cybersource
.Requirements and Prerequisites
Before installing and configuring the
Cybersource
Extension, ensure that
you meet these requirements:- Have aBigCommercemerchant account.
- Have Optimize One Page Checkout. For more information, see Optimize One Page Checkout.
- Have aBusiness Centeraccount. To create an account, go to theBusiness CenterRegistration website.
- Have the ability to accept payments in one of the supported currencies.
- Have cardinal credentials saved within yourBusiness Centeraccount for3-D Securetransactions.
Supported Features
This section describes payment, services, and features provided by
BigCommerce
through Cybersource
.These are the supported payment methods:
- Credit and debit card payments
- Card types:
- American Express
- Diners Club
- Discover
- JCB
- Maestro
- Mastercard
- Visa
These are the supported services:
- Authorization only
- Authorization and capture
- Captures
- Partial Refunds
- Refunds
These are the supported features:
- Token Management Service (TMS): Removes your customer's stored card information from your environment and exchanges sensitive payment data for tokens that cannot be reversed. ContactCybersourcecustomer support to request that TMS be enabled to use the Stored credit cards feature on yourCybersourcemerchant account.
- OAuth is an industry-standard authorization protocol that enables you to use yourBusiness Centeraccount credentials to connect toBigCommercefor transaction processing. For more information about OAuth, see the OAuth 2.0 Implementation Guide.
Configure BigCommerce
BigCommerce
This section describes how to connect your
BigCommerce
account to
Cybersource
. Before you begin, make sure that you have a
Business Center
account. Create an Evaluation Account
If you do not have an
Business Center
account, go to the Business Center
website to create one. To complete the registration process, follow the email instructions that you received to
activate your merchant account, and log in to the
Business Center
.Enable the Extension
Follow these steps to enable the
Cybersource
extension.- Log in to the BigCommerce website and navigate to .
- From the list of Online Payment Methods, choose.Cybersource
- From theSettings tab, clickCybersourceSign upto create an account.
ADDITIONAL INFORMATION

Connect to Cybersource
Cybersource
Follow these steps to connect
BigCommerce
on the Cybersource
Settings page. - FromCybersourceSettings page, choose the environment you want to connect to yourBigCommerceaccount, and chooseConnect with.
ADDITIONAL INFORMATION
You are redirected to theCybersourcelogin page.
- Enter your credentials and clickAllowto giveBigCommercepermission to connect to your account.
ADDITIONAL INFORMATION
If you used OAuth to log in, your account automatically connects toCybersourcewith the appropriate permissions.
Configuration Settings
This section describes the configuration settings for the
Cybersource
Extension.In the
Cybersource
Settings page, configure your preferences based on
the services you use. Display Name
: Manages how the payment gateway appears at
checkout. Cybersource
recommends something like
Credit/Debit
.
Merchant ID
: Enter the merchant ID (such as 87654321
)
that you received when you signed up with Cybersource
.

Transaction
Type
: Choose Authorize and Capture
or
Authorize Only
. Authorize Only
enables you to capture the funds manually. See Manually Capturing Transactions (Authorize
Only) for more information.

Test Mode
: Determines whether your store is in Test Mode.
When you are ready to take payments, set to No
(Recommended)
.

Require CVV
(credit card security codes): Using this option
requires users to enter the CVV/CVV2/CVD code for their credit card during checkout.
Enabling this option adds extra security on credit card transactions.

Enable
: This option enables an additional security layer that helps to
prevent unauthorized transactions. For more information, see 3-D Secure
3-D Secure
.
Enable Google Pay
: This option enables shoppers to use Google
Pay on your storefront. For more information, see Connecting with Google Pay.
Set up Apple Pay
: This option enables shoppers to use Apple
Pay on your storefront. To configure this feature, see Connecting with Apple Pay for more information. Show the Card Element
: This option displays or hides the
credit card field at checkout. For more information on this feature, see Show Card Element.

Save
. Upgrade
If you already have an account, you can upgrade to V2 from the
Cybersource
Settings page. For more details, see Upgrading from Cybersource
to
Cybersource
V2.