Skip to main content
HighRiskPaymentProvider.comPayment provider reviews
Cybersource global payment platform

Company overview

About Cybersource

What the company provides

  • Gateway
  • Orchestrator
  • Payout orchestrator

Available countries, payment methods, data access, contracts and funds handling depend on the selected product.

Cybersource, a Visa company, provides a global payment gateway and orchestration platform, Unified Checkout, REST payment APIs, Token Management Service, Decision Manager, payer authentication, payment reporting and card-network payout connectivity.

Its standard gateway path connects the merchant to external processors and acquirers; those parties provide any merchant account or MID, perform merchant underwriting, hold funds and settle transactions. The production Cybersource or Visa counterparty is determined by the signed agreement and territory rather than the non-production Developer Center terms. A current United States card-services package uses a separate agreement with Global Payments Direct, Inc., while the Cybersource Payment Services Agreement remains separate.

Founded 1994cybersource.comUpdated Aug 15, 2026

Selected product

Cybersource global payment platform

Global Payment Gateway and platform services

Gateway account & connected payment providers

  1. Product account

    Cybersource supplies the gateway account and API; the merchant's processor or acquiring bank supplies the merchant account and acquiring

  2. Client activation

    Cybersource technical activation plus the merchant's processor or acquiring bank merchant approval

    Gateway activation covers API credentials, tokenization and message transmission, not a merchant account, MID or acquiring relationship.

Primary legal entity

Jurisdiction
United States
Company type
Delaware corporation

Legal entities by jurisdiction

5 legal entities across 4 jurisdictions

  • United States2 entities
  • Australia1 entity
  • Brazil1 entity
  • United Kingdom1 entity

Operating scale

Platform country and territory reach
≥160 countries and territories connected by platform network

The legal entity supplying a product can differ by product and country.

Product portfolio

Cybersource products

Compare payment technology and payouts by account setup, approval, payment or data flow, and contract terms.

Cybersource global payment platform

Role in this product

  • Payment gateway
  • Checkout vault and fraud technology

Use Global Payment Gateway, REST payment APIs, Unified Checkout, Token Management Service, Decision Manager, payer authentication and reporting through one platform.

Cybersource supplies the gateway, checkout, vault and risk technology; the connected acquirer or processor retains the merchant account, MID, financial authorization and settlement responsibilities.

Related services
Alternative payment methodsDirect APIEmbedded checkoutFraud preventionHosted checkoutPayment orchestrationPayment routingPayment vaultRecurring billing
Features
PSP and acquirer connectionsGatewayOrchestrationPayment operationsCheckoutFraud and riskReportingClient onboardingUnderwritingPricingComplianceSupport

United States card-services arrangement

Role in this product

  • Payment gateway

A packaged United States route in which Cybersource supplies payment technology and Global Payments Direct, Inc. supplies the separate card-services agreement, merchant underwriting, merchant account, acquiring relationship, financial processing and settlement.

The current merchant application expressly separates the Global Payments Card Services Agreement from the Cybersource Payment Services Agreement.

Related services
Direct APIFraud preventionPayment vault
Features
GatewayPayment operationsFraud and riskOnboardingUnderwritingPricingComplianceSupport

Cybersource Payouts

Role in this product

  • Payout orchestrator

Submit original-credit and card-network payout requests through Cybersource APIs for approved use cases, including merchant disbursements and regulated gaming payouts.

Cybersource supplies the API and transaction connection; the sponsoring acquirer, Visa or Mastercard programme and card network move the funds under their programme approvals and rules.

Related services
Customer payoutsPayout orchestration
Features
PayoutsPayment operationsClient onboardingUnderwritingPricingComplianceSupport

Selected product

Cybersource global payment platform

Related services
9 capabilities
Features
12 capabilities

Product setup, provider connections & funds handling

Who supplies the software, which payment providers must be connected, who approves live processing and who handles merchant funds.

01 · Role in this product
Payment gateway · Checkout vault and fraud technology
02 · Connected payment account
Cybersource supplies the gateway account and API; the merchant's processor or acquiring bank supplies the merchant account and acquiring
03 · Connected-provider approval
Cybersource reviews gateway access; the merchant's processor or acquiring bank retains merchant-account and underwriting approval
04 · Funds handling
Cybersource transmits payment messages; the merchant's processor or acquiring bank controls authorization, funds and merchant settlement

Selected product: Cybersource global payment platform.

Checkout

Cybersource global payment platform: checkout, payment data & provider connections

Review checkout ownership, payment-data handling, supported integrations and the connected providers required for live payments.

Selected product: Global Payment Gateway and platform services

Included in Cybersource global payment platform

Features included with this product.

Solutions
Alternative payment methodsDirect APIEmbedded checkoutFraud preventionHosted checkoutPayment orchestrationPayment routingPayment vaultRecurring billing
Capabilities
PSP and acquirer connectionsGatewayOrchestrationPayment operationsCheckoutPayment vaultRecurring billingFraud and riskReportingClient onboardingUnderwritingPricingComplianceSupport

Checkout, payment data & provider roles

Who operates checkout, handles payment data, authorizes payments and handles merchant funds for Cybersource global payment platform.

Included

Payment gateway, PSP and acquirer connections

Integration options, connected PSPs and acquirers, tokenization, 3DS and merchant tools.

Fraud & authentication connections

Screen → authenticate → return decision

Gateway availability
The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.
Transaction processing
No
Merchant settlement
No
Merchant funds
No
Merchant funds
Does not handle merchant funds
Merchant account
No
MID
No
Direct acquiring
No
Merchant account model
Cybersource supplies the gateway and platform account. A supported processor or acquirer supplies the financial merchant account and MID under its own approval and contract.
  1. 01Merchant integrationIntegration options and connected payment providers
  2. 02Payment securityTokenization, authentication and transport security
  3. 03Development & operations

Gateway connections

Merchant integration, PSP and acquirer connections

Integration options

Integration options
  • REST API
  • Unified checkout web SDK
  • Secure acceptance
  • Commerce platform integrations

Gateway

Payment technology

Connected payment provider

Types of connected payment providers
  • Acquirer
  • Bank
  • Digital wallet
  • Payment processor
  • PSP
Acquirer-independent
Yes
Processor-independent
Yes
Works with multiple PSPs and acquirers
Yes
Single integration
Yes
Pre-integrated provider connections
Yes
Separate PSP or acquirer approval required
Yes
Provider integration maintenance
Yes
Connected providers
≥200 acquirers and processors
Types of connected payment providers
  • Acquirers
  • Payment processors
  • Banks
  • Payment methods
  • Fraud and authentication services
Capabilities
  • Single platform payment connectivity
  • Merchant selected processor connection
  • Multi acquirer platform access
  • Payment method connectivity
  • Fraud and authentication service composition
Product access
  • Payments REST API and Unified checkout: ≥200 acquirers and processors · payment-method count not disclosed

Security controls

Tokens and payment authentication

Tokenization
Yes
3-D Secure
Yes
Token formats
  • Transient token
  • Cybersource vault token
  • Network token

Operations

Webhooks, Control Panel and test environment

Tools used to test an integration and manage live payments.

Webhooks
Yes
Sandbox
Yes
Merchant control panel
Yes
API-oriented
Yes
Gateway included
Yes
Merchant chooses merchant services
Yes
Onboarding included
Yes
Gateway features
  • Payments REST API
  • Payment request transmission
  • Processor and acquirer connections
  • Authorization capture reversal and refund messages
  • Payment event webhooks
  • Test and production endpoints
Webhook events
  • Payment authorization status
  • Payment reversal status
  • Unified checkout transaction result
  • Recurring billing event
  • Network token event
Role in this product
Gateway
Questions to confirm

Which connectors apply to Global Payment Gateway and platform services?

Connectors are not specified for Global Payment Gateway and platform services.

How are new PSP or acquirer connections added to Global Payment Gateway and platform services?

The process and lead time for adding a new PSP or acquirer connection are not specified.

Which alternative payment methods apply to Global Payment Gateway and platform services?

Alternative payment methods are not specified for Global Payment Gateway and platform services.

What account setup, data retention, export, support and termination terms apply to this product?

These product-account and data terms are not fully specified.

Product account · Global Payment Gateway and platform services

What is required to activate this product?

Cybersource reviews gateway and API access; the merchant's processor or acquiring bank retains merchant-account and underwriting approval.

Product eligibility

The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

Gateway activation covers API credentials, tokenization and message transmission, not a merchant account, MID or acquiring relationship.

Product account review

Cybersource technical activation plus the merchant's processor or acquiring bank merchant approval

The provider reviews the company and product use before activating the technology account.

Account review
Platform account review
Product
Global Payment Gateway and platform services
Regulated-business license
Required license type and issuing jurisdiction are not specified
01Product eligibility & acceptable use

Which businesses and uses are accepted for this product?

The product's acceptable-use rules determine which businesses and use cases can activate an account.

Restricted activity

Business restrictions

Product · MCC · jurisdiction · sales practice

Product, MCC, sales-practice and jurisdiction restrictions are not specified for this product.

02Product account application

What is needed to activate the product account?

Company information, intended product use, commercial terms and integration details required before activation.

Product account application

Open product account → agree terms → configure integration → test → activate

Product access begins after account review, configuration and testing are complete.

Business, use-case & processor inputs

Documents to prepare

  1. 01Business, use-case & processor inputs

Gateway integration & certification

  1. 01

    Gateway integration & certification

Product account requirements

Account setup and activation

Application and activation requirements.

API, token & transaction-message requirements

  • API, token & transaction-message requirements

Gateway activation covers API credentials, tokenization and message transmission, not a merchant account, MID or acquiring relationship.

Security, processor & production checks

  • Security, processor & production checks

Gateway activation covers API credentials, tokenization and message transmission, not a merchant account, MID or acquiring relationship.

Approved gateway scope

  • Approved gateway scope

Gateway activation covers API credentials, tokenization and message transmission, not a merchant account, MID or acquiring relationship.

Before applying

Application requirements to confirm

Company eligibility, acceptable-use restrictions, account requirements and activation timing are not fully specified.

Approval & restrictions

Who reviews the business and which products, jurisdictions or MCCs are excluded.

  1. 01

    Which processor or acquirer supplies the merchant account, MID, underwriting, authorization, funds and settlement?

    Those financial roles are outside the gateway-only agreement.

  2. 02

    Which API, tokenization, transaction-message and reporting functions are enabled?

    Gateway scope depends on the configured integration.

  3. 03

    Which processor credentials, tests and production gates must pass?

    Technical activation depends on the external processing route.

Payment methods & countries · Global Payment Gateway and platform services

Which countries and payment methods are available for this gateway or orchestration setup?

Gateway reach is the configured API, token and processor compatibility; merchant acquiring reach belongs to the external processor.

Selected product

Global Payment Gateway and platform services

Gateway configuration plus external processor

Selected product

Client company

The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

Business availability and connected-service coverage are separate requirements.

Gateway compatibility

  • Configured API token and processor connections

The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

Availability depends on

  • Client
  • Market
  • Configuration
  • Agreement

The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

01Selected product

Global Payment Gateway and platform services capabilities and connections

These capabilities belong to the selected product. Connected-provider and regional availability is set during configuration.

Connected payment providers

Connected payment providers are not identified for this product.

Connected payment provider
02Countries & availability

Where can the client be based, which PSP or acquirer serves each target market, and where can customers pay?

Client eligibility, merchant-account approval, acquiring coverage and customer-country availability are separate parts of the payment setup.

Country coverage

Client, connected-provider, customer and product countries

  1. 01

    Client location

    Where can the company using the technology be registered?

    The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

    This is where the business is registered; it does not determine acquiring-country or customer-country availability.

    Client and merchant-account eligibility
  2. 02

    Acquiring countries

    Where is merchant acquiring available?

    Handled by the payment provider

    The merchant's processor or acquiring bank

    Cybersource supplies gateway technology; the merchant's processor or acquiring bank retains underwriting, MID, authorization, funds and settlement.

    Connected payment provider
  3. 03

    Customer location

    Where can customers pay from?

    The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

    The merchant's processor or acquiring bank defines merchant, payer, payment-method and country availability.

    Connected payment provider

Countries and payment methods

Countries and payment methods to confirm

  1. Which processors, acquirers, APIs, token services and transaction types are certified?

    Gateway coverage depends on the configured external route.

  2. Which merchant-account, MID, authorization, funds and settlement terms belong to the merchant's processor or acquiring bank?

    Those terms are outside the gateway-only product.

Pricing & funds · Global Payment Gateway and platform services

What does Global Payment Gateway and platform services cost, and which related charges are governed by another agreement?

Gateway/API price & external merchant-services boundary

Pricing

Gateway/API price & external merchant-services boundary

Pricing method

Quote or contract specific; amounts not publicly disclosed

Gateway account, API call, transaction-message, tokenization, implementation, support and service-level charges.

01Commercial terms

What makes up the quoted price?

Review the pricing plan, pricing model, fees and contract duration.

Contracted price model

Not specified

Quote or contract specific; amounts not publicly disclosed

Gateway account, API call, transaction-message, tokenization, implementation, support and service-level charges.

02External processor pricing

Which external processor pricing terms apply?

The merchant's processor or acquiring bank separately sets processing, interchange, scheme, reserve and settlement terms.

Commercial responsibility split

Cybersource: gateway technology · The merchant's processor or acquiring bank: merchant processing and acquiring terms

The gateway-only agreement does not create a merchant account or acquiring relationship.

03Merchant settlement

Which provider settles merchant funds?

The merchant settlement provider and terms are not specified unless listed below. Customer or third-party payouts are a separate service and may use another provider.

Merchant settlement

Sale proceeds and settlement responsibility

Settlement makes processed sale proceeds available to the merchant.

Funds responsibility

Assigned outside this product

The merchant's processor or acquiring bank retains authorization, funds and merchant settlement

Cybersource transmits messages and does not hold or settle merchant funds on this product.

Pricing & settlement terms

Terms to confirm in the agreement

External processor pricing

  1. Which processing, interchange, scheme, reserve and settlement costs belong to the merchant's processor or acquiring bank?

    Financial-service pricing is outside the gateway-only agreement.

Other terms

  1. Which gateway account, API, message, tokenization, implementation and support charges apply?

    Gateway pricing and billable events are contract-specific.

  2. What credential, token, transaction-data and integration exit terms apply?

    Gateway continuity and portability affect switching cost.

Payment lifecycle · Global Payment Gateway and platform services

How do checkout, payment processing, settlement and reconciliation work?

Gateway/API integration, token lifecycle & external processing

Payment lifecycle

Checkout → authorization → settlement → reconciliation

The selected product determines the integration, transaction controls, payment processing, merchant settlement and reporting.

Selected product

Global Payment Gateway and platform services

Integration, processing, merchant settlement and reporting for this product.

  1. Gateway & Payment API

    Cybersource gateway account, API and tokenization

  2. Merchant processor & acquiring connection

    The merchant's processor or acquiring bank

  3. Gateway & external financial responsibilities

    Cybersource: API, tokenization & messages · The merchant's processor or acquiring bank: approval, processing, funds & settlement

  4. Gateway logs & processor reconciliation

    Cybersource message records reconciled to the merchant's processor or acquiring bank financial and settlement records

01

Gateway & Payment API

Choose the integration option and who controls the payment page

Credentials, request and response messages, tokenization, webhooks, environments, certification and production activation.

Integration path

Cybersource gateway account, API and tokenization

The production contracting entity and territorial scope come from the signed Cybersource or Visa agreement. The published Developer Center terms cover testing and other non-production access and do not establish that production counterparty. Each live route also requires product enablement and a supported processor or acquirer relationship.

02

Merchant processor & acquiring connection

Gateway integration, security and transaction tools

Processor credentials, routing identifiers, message compatibility and external production approval.

Selected setup

Gateway entry point

How requests enter this product and which integration boundary applies.

Merchant processor & acquiring connection details are not specified.

Merchant processor & acquiring connection

Tokenization, 3-D Secure, webhooks and transaction controls

Gateway
01

Connected parties

Processor credentials, routing identifiers, message compatibility and external production approval.

The merchant's processor or acquiring bank

Transaction-message lifecycle

From customer consent to scheduled payments and retries

Stored-credential consent, payment scheduling and retry rules apply to each recurring-payment setup.

Other recurring-payment terms

Lifecycle

Token or credential · gateway request · processor response · capture or reversal · status

Token creation or use, authorization message, processor response, capture or reversal message, refund and status updates where supported.

03

Gateway & external financial responsibilities

Who processes transactions, settles merchant funds and controls authorization and capture?

The provider supplies gateway technology; the external processor or acquirer supplies the merchant account, MID, authorization, acquiring, funds and settlement.

Gateway & external financial responsibilities

Cybersource: API, tokenization & messages · The merchant's processor or acquiring bank: approval, processing, funds & settlement

Vault or orchestration modules do not redefine this explicit gateway-only service role.

04

Gateway logs & processor reconciliation

What reports and reconciliation tools are available?

Gateway requests, responses, tokens and statuses reconciled to the external processor's authoritative financial records.

Additional operational terms

Additional reporting and operations terms for this product.

Records & reconciliation

Cybersource message records reconciled to the merchant's processor or acquiring bank financial and settlement records

Gateway requests, responses, tokens and statuses reconciled to the external processor's authoritative financial records.

Before integration

Integration details not specified

  1. 01

    Which messages, token operations, webhooks, environments, retries and certification tests are enabled?

    Gateway operations depend on the configured processor route.

  2. 02

    Which authorization, capture, reversal, refund, dispute and settlement controls belong to the merchant's processor or acquiring bank?

    The external processor remains financially authoritative.

  3. 03

    How are credentials, tokens, logs, incidents, portability and termination handled?

    Gateway continuity and exit procedures must be explicit.

Product responsibility, continuity & support

Cybersource global payment platform: risk, licenses & support

Product responsibilities, connected providers, service continuity, contracting entity and support.

Cybersource global payment platformService: Global Payment Gateway and platform services
01 / Product responsibility & continuity

Which responsibilities belong to this product?

Connected-provider roles, service availability, data access, suspension and post-termination continuity.

Roles & continuity

Cybersource gateway with external merchant processing

Cybersource supplies API, tokenization and transaction-message technology. The merchant's processor or acquiring bank retains merchant approval, authorization, funds and settlement.

Role in this product
Payment gateway · Checkout vault and fraud technology
Connected providers & merchant funds
Cybersource transmits payment messages; the merchant's processor or acquiring bank controls authorization, funds and merchant settlementThe gateway may tokenize credentials and relay transaction messages, but it does not supply the merchant account, MID, acquiring, funds custody or settlement on this route.

Service continuity

What happens during an outage or after termination?

Availability, data access, suspension, migration and post-termination terms belong in the agreement.

  • Which underwriting, authorization, dispute, reserve, funds and settlement controls belong to the merchant's processor or acquiring bank?

  • Which PCI, token, credential, encryption, access, incident and audit controls apply?

Before signingService availability, data access and termination terms3 items to confirmReview contract terms
03 / Support

How can merchants reach support?

Company support hours and contact channels are available. It is not specified which ones cover Global Payment Gateway and platform services and integration failures, service outages or data-access issues. First-response and resolution targets are also not specified.

Support contacts

Company support hours and contacts

The contacts that cover this product and integration failures, service outages or data-access issues are not specified.

Other company contacts

Support hours are not specified for these contacts.

Before signingSupport contacts, hours and response times2 items to confirmReview contract terms
Global Payment Gateway and platform services / Before signing

What should the technology services agreement include?

Confirm product scope, software pricing, connected-provider responsibilities, data handling, service levels, support and termination.

Before signing

Global Payment Gateway and platform services: terms to confirm

Confirm the product scope, connected-provider responsibilities, pricing, data handling, service levels and exit terms.

Product, usage & pricing

Included features, environments, usage allowances, overage rates, third-party costs and contract term

Data, service levels & exit

Data handling, security, uptime, recovery, support, suspension, portability and termination

Contract checklist

Terms to review by topic

Jump to the underlying product details

  1. 01Availability, security & continuityService levels, incident handling, data access, suspension and post-termination continuity.
  2. 02Contracting entity & service responsibilitiesTechnology contract, data roles, connected-provider agreements and any regulated service involved.
  3. 03Technical supportSupport contacts, hours, severity levels, response targets and escalation.
Technology services agreement

Product terms to confirm

Review software pricing, integration scope, connected-provider responsibilities, data handling, service levels, support and termination.

Availability, security & continuityService levels, incident handling, data access, suspension and post-termination continuity.
  1. Which PCI, token, credential, encryption, access, incident and audit controls apply?

    Gateway security scope must be explicit.

  2. Which underwriting, authorization, dispute, reserve, funds and settlement controls belong to the merchant's processor or acquiring bank?

    Those controls are outside the gateway-only product.

  3. How are processor outages, message retries, duplicate prevention, token portability and termination handled?

    Gateway continuity depends on the configured processor route.

Contracting entity & service responsibilitiesTechnology contract, data roles, connected-provider agreements and any regulated service involved.
  1. Which entity contracts for gateway access, and which processor or acquirer agreement controls the merchant account?

    Technology and financial contracts must be separated.

  2. Which regulatory and card-network responsibilities belong to the merchant's processor or acquiring bank?

    The gateway provider is not the financial acquirer on this route.

  3. Which PCI, privacy, residency, token, incident, audit and deletion terms apply?

    Gateway and token data duties require explicit allocation.

Technical supportSupport contacts, hours, severity levels, response targets and escalation.
  1. Which contacts, hours and response targets cover API access, tokenization, transaction messages, processor connectivity and incidents?

    Gateway support must distinguish technical and financial issues.

  2. How are authorization, merchant-account, funds and settlement incidents escalated to the merchant's processor or acquiring bank?

    Those issues belong to the external processor or acquirer.

Product summary

What this product already includes

What this technology product includes, which configuration restrictions apply and which service terms are not specified.

Included capabilities

Capabilities included with Global Payment Gateway and platform services.

  • Open architecture payment composition, Multi acquirer connectivity, Payment method and provider selection, Modular payment fraud and security services, Single platform transaction view, Processor routing, Acquirer routing, and Payment method routing

  • Payment gateway technology

Product restrictions and conditions

Acceptable use, supported connections, configuration limits, data conditions and account restrictions.

  • Connected-provider requirements, operating limits, event coverage and service levels depend on the selected configuration.

Terms to confirm

Pricing, integration, data, service-level, support and termination terms to include in the technology agreement.

  • Unit prices, usage allowances, overage rates, contract length, minimum spend and renewal terms are not specified.