On This Page
Network Routing Architecture Update
Cybersource endpoints will be migrated from the current routing model to a new
architecture using updated IP subnet ranges.
This enhancement is designed to improve the performance, resiliency, and reliability of
transaction delivery over the Internet. It will also enable seamless transaction routing
across multiple Visa data centers, supporting more consistent and reliable transaction
processing.
Cybersource Endpoints and IP Addresses Included
Current Application and endpoints:
CAS/Test
: apitest.cybersource.com
(current IP address:
66.185.182.49
)Production
: api.cybersource.com
(current IP address:
66.185.182.149
)Potential Impact
Clients who connect to the REST API endpoints listed above using Domain Name System (DNS)
are not expecting to experience any impact. DNS records will be updated automatically to
use the new routing architecture.
Clients whose networks are configured to allowlist IP addresses or who have hardcoded IP
addresses will likely be impacted. These clients must update their proxy or firewall
settings to include the new Visa IP address ranges.
There are no changes to TLS/SSL certificates or supported ciphers as part of this
migration. However, Cybersource continues to recommend trusting the root TLS
certificates for all secure endpoints.
Migration Timeline
CAS/Test
: October 15, 2026Production
: January 31, 2027Now Available
This technology is now available in both the test and production environments through
these domains:
CAS/Test
: apitest.visaacceptance.com
Production
: api.visaacceptance.com
Deploying in the CAS/Test Environment provides a safe environment to test and validate
access. Once testing is complete, you may migrate production processing anytime
thereafter.
How to Adopt This Change
To use the new routing architecture, your firewall, or your commerce platform
provider's firewall, must be configured to permit outbound traffic to the Visa
cloud.
This large, dynamic IP address space represents a significant change from current access
configurations. Therefore, it is critically important to test firewall configurations
and confirm that connections are successful before migrating production traffic.
Clients who require IP address allowlists may use one of the following options.
Option 1
: Add these specific subnet ranges to your allowlist:- 198.217.128.0/17
- 198.241.128.0/17
- 66.185.176.0/20
Option 2
: Add these generic subnet ranges to your allowlist:- 198.241.206.0/24
- 198.241.207.0/24