Cybersource Infrastructure Enhancement - REST API Access Points
Customer received another email from Cybersource regarding upcoming infrastructure enhancements. Below is the email text. Any action needed here? Also, is there a better way for customers to share this information with us and ask for action needed or is this the preferred route? Seth Halvaksz
Dear Valued Merchant,
To better serve your organization, we are pleased to announce an enhancement to our network routing architecture. Cybersource endpoints will be migrated from the current routing model to a new architecture using updated IP subnet ranges.
This enhancement is designed to improve the performance, resiliency, and reliability of transaction delivery over the Internet. It will also enable seamless transaction routing across multiple Visa data centers, supporting more consistent and reliable transaction processing.
Cybersource Endpoints and IP Addresses Included
Current Application and endpoints:
REST API
Environment
URL
Current IP address
CAS/Test
apitest.cybersource.com
66.185.182.49
Production
api.cybersource.com
66.185.182.149
Potential Impact
Clients who connect to the REST API endpoints listed above using Domain Name System (DNS) are not expecting to experience any impact. DNS records will be updated automatically to use the new routing architecture.
Clients whose networks are configured to whitelist IP addresses or who have hardcoded IP addresses will likely be impacted. These clients must update their proxy or firewall settings to include the new Visa IP address ranges.
There are no changes to TLS/SSL certificates or supported ciphers as part of this migration. However, Cybersource continues to recommend trusting the root TLS certificates for all secure endpoints.
Migration Timeline
Environment
Date
CAS/Test
October 15, 2026
Production
January 31, 2027
Now Available
This technology is now available in both the test and production environments through the domains listed below:
- CAS/Test Environment: apitest.visaacceptance.com
- Production Environment: api.visaacceptance.com
Deploying in the CAS/Test Environment provides a safe environment to test and validate access. Once testing is complete, you may migrate production processing anytime thereafter.
How to Adopt This Change
To use the new routing architecture, your firewall, or your commerce platform provider’s firewall, must be configured to permit outbound traffic to the Visa cloud.
This large, dynamic IP address space represents a significant change from current access configurations. Therefore, it is critically important to test firewall configurations and confirm that connections are successful before migrating production traffic.
Clients who require IP address whitelisting may use one of the following options.
Option 1: Add the following specific subnet ranges to your whitelist
198.217.128.0/17
198.241.128.0/17
66.185.176.0/20
Option 2: Add the following generic subnet ranges to your whitelist
198.241.206.0/24
198.241.207.0/24
Please contact your Customer Support representatives for any questions you may have about this change.
Thank you,
Cybersource Customer Support
-
i'll look into this. We don't have a partnership with Cybersource, so unfortunately this may be the only way we learn about these updates.
Please sign in to leave a comment.
Comments
1 comment
Date Votes