.png)
Cybersource Integration Guide
Integrate Cybersource payment authorization, capture, refunds, tokenization, fraud screening, reporting, and transaction workflows through REST APIs, selected webhooks, legacy SOAP, and batch capabilities.
Cybersource integration options at a glance
Cybersource’s primary integration model is REST APIs using JSON for payments, captures, refunds, voids, payment instruments, tokenization, risk services, transaction search, and reporting. Selected payment and transaction events can be delivered through webhook-style notifications, while legacy SOAP services remain available for existing implementations. Cybersource also supports selected batch, asynchronous, reporting, and file-oriented workflows. Martini can consume these APIs, expose secured endpoints for internal payment operations and webhook receipt, map payment data between systems, orchestrate lifecycle workflows, and persist checkpoints and reconciliation results. HTTP Signature and applicable JWT authentication patterns can be managed through protected Martini secrets and environment configuration.
Common Cybersource integration patterns
Common Cybersource data objects used in integrations
Authentication and security considerations
Authentication and credential protection
Cybersource REST integrations commonly use merchant credentials with HTTP Signature authentication or applicable JWT patterns. Legacy SOAP services use their relevant authentication model.
- Store merchant IDs, API key IDs, secret keys, JWT material, and webhook verification settings in Martini secrets or protected environment configuration.
- Keep sandbox and production credentials separate.
- Validate webhook authenticity and integrity before processing notifications.
- Do not log secret keys, authorization headers, raw card data, or unnecessary sensitive response fields.
Payment-data security
Minimize cardholder-data exposure by preferring tokenized payment instruments or hosted payment experiences where appropriate. Review PCI DSS responsibilities for the selected Cybersource integration model and mask sensitive fields in workflow logs.
Operational considerations for Cybersource integrations
Payment integrity
Use idempotency controls for authorization, capture, refund, void, and webhook processing. Do not blindly retry a timed-out payment operation; first query Cybersource to determine whether the original request succeeded.
Reconciliation and pagination
Use bounded time windows, pagination, stable checkpoints, and replay-safe writes for transaction search, reports, and batch processing. Preserve transaction identifiers, source timestamps, amounts, currencies, and reason codes.
Errors and state
- Separate transport errors, authentication failures, validation errors, processor declines, fraud decisions, and retryable service failures.
- Distinguish authorization, capture, settlement, decline, review, reversal, and refund states.
- Validate partial captures and refunds against the applicable authorized or captured amount.
- Review API and payment-product changes before updating mappings, and test against sandbox scenarios.
Why use Martini instead of scripts or point-to-point integrations?
Controlled orchestration
Martini centralizes Cybersource API calls, webhook receipt, payment lifecycle rules, reconciliation, and downstream updates in maintainable workflows rather than scattering logic across scripts or point-to-point links.
Reusable integration assets
Teams can expose consistent internal APIs, reuse authentication and transformation logic, and maintain separate flows for authorization, capture, refunds, voids, notifications, and reporting.
Operational resilience
- Apply validation, idempotency, retries, checkpoints, and error routing consistently.
- Map Cybersource JSON, XML, batch, and file results into canonical business models.
- Protect secrets and payment data while retaining the identifiers and outcomes needed for audit and reconciliation.