Payments Developer Guide {#payments-about-guide}
================================================

This section describes how to use this guide and where to find further information.

Audience and Purpose
:
This guide is written for application developers who want to use the `Simple Order API` to integrate payment card processing into an order management system.

    Implementing the `Cybersource` payment services requires software development skills. You must write code that uses the API request and response fields to integrate the payment card services into your existing order management system.

Conventions
:
These statements appear in this document:
> An *Important* statement contains information essential to successfully completing a task or learning a concept.

    > A *Warning* contains information or instructions, which, if not heeded, can result in a security risk, irreversible loss of data, or significant cost in time or revenue or both.

Related Documentation
:
Visit the [`Cybersource` documentation hub](https://developer.cybersource.com/docs.md "") to find additional processor-specific versions of this guide and additional technical documentation.

Customer Support
:
For support information about any service, visit the Support Center:  
<http://support.visaacceptance.com>

Recent Revisions to This Document {#payments-doc-revisions}
===========================================================

26.04.01
--------

Added related reference information (Related to this Page) to applicable topics.  
Added [Void a Payment](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-processing-basic-intro/payments-processing-sale-void-intro.md "").

26.02.01
--------

Pre-Authorization
:
Added an important note about using strong customer authentication. See [Pre-Authorization](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-processing-basic-intro/payments-processing-pre-auth-intro.md "").
:
Updated required fields and examples. See [Required Fields for a Pre-Authorization](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-processing-basic-intro/payments-processing-pre-auth-intro/payments-processing-pre-auth-required.md "").

Credentialed Transactions
:
Removed content that is available in the *Credentialed Transactions Developer Guide* . See [`Cybersource` Documentation hub](https://developer.cybersource.com/docs.md "").

26.01.02
--------

This revision contains only editorial changes and no technical updates.

26.01.01
--------

This revision contains only editorial changes and no technical updates.

25.09.02
--------

This revision contains only editorial changes and no technical updates.

25.09.01
--------

This revision contains only editorial changes and no technical updates.

25.08.01
--------

This revision contains only editorial changes and no technical updates.

25.07.01
--------

This revision contains only editorial changes and no technical updates.

25.05.01
--------

International Transaction Compliance
:
Added a section about international transaction compliance. See [Compliance](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-intro/payments-intro-transactions-overview/payments-intro-transactions-intl/payments-intro-compliance.md "").

Introduction to Payments {#payments-intro}
==========================================

This introduction provides the basic information that you need to successfully process payment transactions. It also provides an overview of the payments industry and provides workflows for each process.  
With `Cybersource` payment services, you can process payment cards (tokenized or non-tokenized), digital payments such as Apple Pay and Google Pay, and customer ID transactions. You can process payments across the globe and across multiple channels with scalability and security. `Cybersource` supports a large number of payment cards and offers a wide choice of gateways and financial institutions, all through one connection.  
Visit the [`Cybersource` documentation hub](https://developer.cybersource.com/docs.md "") to find additional processor-specific versions of this guide and additional technical documentation.

Financial Institutions and Payment Networks {#payments-intro-banks-overview}
============================================================================

Financial institutions and payment networks enable payment services to function. These entities work together to complete the full payment cycle.

Merchant Financial Institutions (Acquirers) {#payments-intro-banks-acquiring}
=============================================================================

A merchant financial institution, also known as an *acquirer*, offers accounts to businesses that accept payments. Before you can accept payments, you must have a merchant account from an acquirer. Your merchant account must be configured to process card-not-present or mail-order/telephone-order (MOTO) transactions.  
Each acquirer has connections to a limited number of payment processors. You must choose a payment processor that your acquirer supports.  
You can expect to pay these fees:

* Discount rates: your acquirer charges a fee and collects a percentage of every transaction. The combination of the fee and the percentage is called the *discount rate* . These charges can be *bundled* (combined into a single charge) or *unbundled* (charged separately).

* Interchange fees: payment networks, such as Visa or Mastercard, each have a base fee, called the *interchange fee*, for each type of transaction. Your acquirer and processor can show you ways to reduce this fee.

* Chargebacks: when cardholders dispute charges, you can incur *chargebacks*. A chargeback occurs when a charge on a customer's account is reversed. Your acquirer removes the money from your account and could charge you a fee for processing the chargeback.  
  Take these precautions to prevent chargebacks:

* Use accurate merchant descriptors so that customers can recognize the transactions on their statements.

* Provide good customer support.

* Ensure rapid problem resolution.

* Maintain a high level of customer satisfaction.

* Minimize fraudulent transactions.  
  If excessive chargebacks or fraudulent changes occur, these actions might be taken:

* You might be required to change your business processes to reduce the number chargebacks, fraud, or both.

* Your acquiring institution might increase your discount rate.

* Your acquiring institution might revoke your merchant account.  
  Contact your sales representative for information about products that can help prevent fraud.

Customer Financial Institutions (Issuers) {#payments-intro-banks-issuing}
=========================================================================

A customer financial institution, also known as an *issuer*, provides payment cards to and underwrites lines of credit for their customers. The issuer provides monthly statements and collects payments. The issuer must follow the rules of the payment card companies to which they belong.

Payment Networks {#payments-intro-card-companies}
=================================================

Payment networks manage communications between acquirers and issuing banks. They also develop industry standards, support their brands, and establish fees for acquiring institutions.  
Some payment networks, such as Visa and Mastercard, are trade associations that do not issue cards. Issuers are members of these associations, and they issue cards under license from the association.  
Other networks issue their own cards. Before you process cards from these companies, you must sign agreements with them.

Payment Processors {#payments-intro-processors}
===============================================

Payment processors connect with acquirers. Before you can accept payments, you must register with a payment processor. An acquirer might require you to use a payment processor with an existing relationship with the acquirer.  
Your payment processor assigns one or more merchant IDs (MIDs) to your business. These unique codes identify your business during payment transactions.  
This table lists the processors and corresponding card types that are supported for payment services. Only the card types explicitly listed here are supported.

| Payment Processor |                       Supported Card Types                       | Notes |
|-------------------|------------------------------------------------------------------|-------|
| `HSBC`            | Visa, Mastercard, Maestro (UK Domestic), Maestro (International) |       |
[Payment Processor and Supported Card Types]

{#payments-intro-processors_supported-cards}

Card Types {#payments-intro-cards-types}
========================================

You can process payments with these kinds of cards:

* Credit cards
* Debit cards  
  For a list of supported card types, see [Payment Processors](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-intro/payments-intro-banks-overview/payments-intro-processors.md "").

Credit Cards {#payments-intro-credit-cards}
===========================================

Cardholders use credit cards to borrow money from issuing banks to pay for goods and services offered by merchants that accept credit cards.

Debit Cards {#payments-intro-debit-cards}
=========================================

A debit card is linked to a cardholder's bank account. The funds are taken out of the customer's bank account, and the transaction is included on the customer's bank account statement. The customer does not receive a credit card bill as with a regular credit card.

Transaction Types {#payments-intro-transactions-overview}
=========================================================

This topic provides information about transaction types that are supported by your processor.

Card-Not-Present Transactions {#payments-intro-transactions-card-not-present}
=============================================================================

When a customer provides a card number, but the card and the customer are not physically present at the merchant's location, the purchase is known as a *card-not-present transaction*. Typical card-not-present transactions are internet and phone transactions. Card-not-present transactions pose an additional level of risk to your business because the customer's identification cannot be verified. You can reduce that risk by using features such as the Address Verification System (AVS) and Card Verification Numbers (CVNs). The AVS and CVNs provide additional protection from fraud by verifying the validity of the customer's information and notifying you when discrepancies occur.

Authorizations with Card Verification Numbers {#payments-auth-cvn-intro}
========================================================================

Card verification numbers (CVNs) are a required feature for the authorization service.  
The CVN is printed on a payment card, and only the cardholder can access it. The CVN is used in card-not-present transactions as a verification feature. Using the CVN helps reduce the risk of fraud.  
CVNs are not included in payment card track data and cannot be obtained from a card swipe, tap, or dip.  
CVNs must not be stored after authorization.  
In Europe, Visa mandates that you not include a CVN for mail-order transactions and not record a CVN on any physical format such as a mail-order form.

CVN Locations and Terminology {#payments-auth-cvn-locations}
============================================================

For most cards, the CVN is a three-digit number printed on the back of the card, to the right of the signature field. For American Express, the CVN is a four-digit number printed on the front of the card above the card number.

#### Figure:

CVN Locations ![Image depicting the location of the CVN on the back of most cards and the front
of an American Express card.](/content/dam/documentation/cybs/en-us/topics/payments-processing/card-processing/payments/images/CVV_Location.svg/jcr:content/renditions/original)  
Each payment card company has its own name for the CVN value:

* Mastercard calls it the *card validation code* (CVC2).
* Visa calls it the *card verification value* (CVV2).

International Transactions {#payments-intro-transactions-intl}
==============================================================

Consider compliance and merchant remittance funding when processing international transactions.

Compliance {#payments-intro-compliance}
=======================================

Accepting payments from a country other than your own requires that you observe the processing rules and practices of the payment systems in that country. This list describes areas of compliance that are especially important:

* Merchant descriptor requirements---A merchant descriptor communicates merchant information to customers to remind them of the circumstances that triggered a payment. Merchant descriptors reduce the possibility of a chargeback. Accordingly, the merchant descriptor displayed on a customer's statement should be a close match to the name on your website. It is not good practice to consolidate multiple websites into a single merchant account and use a generic descriptor that more-or-less covers all offerings.
* Excessive chargebacks---To prevent an excessive number of chargebacks, you must maintain good customer support, rapid problem resolution, a high level of customer satisfaction, and transaction management processes that minimize fraudulent transactions. When payment card chargebacks become excessive, you must change business processes to reduce chargebacks. If chargebacks are not reduced to a satisfactory level, your account can be terminated.

Merchant Remittance Funding {#payments-intro-transactions-intl-remittance}
==========================================================================

You can request that the transaction proceeds be converted to another currency. Currency conversion uses a foreign exchange rate to calculate the conversion to the requested currency. The foreign exchange rate might be explicitly stated as a rate or implicitly stated as a transaction amount. The funded amount and can vary from day to day. The foreign exchange rate might also include an increase for the foreign exchange risk, sales commissions, and handling costs.

Payment Services {#payments-services-intro}
===========================================

Various services are involved in processing payments.  
These services enable customers to purchase goods and services. They also enable merchants to receive payments from customer accounts, to provide refunds, and to void transactions.

Authorization {#payments-intro-processing-auth}
===============================================

An authorization confirms that a payment card account holds enough funds to pay for a purchase. Authorizations can be made online or offline.

Micropayment Authorization {#payments-intro-processing-auth-micropayment}
=========================================================================

Micropayments are payments for less than one unit in the transaction's currency.  
For `HSBC`, `Cybersource` supports micropayment authorizations for Mastercard and Visa payment cards.

Online Authorization {#payments-intro-processing-auth-online}
=============================================================

Online authorizations provide immediate confirmation of funds availability. The customer's financial institution also reduces the amount of credit available in the customer's account, setting aside the authorized funds for the merchant to capture at a later time. Authorizations for most payment cards are processed online. Typically, it is safe to start fulfilling the order when you receive an authorization confirmation.  
AnAn online authorization confirmation and the subsequent hold on funds expire after a specific length of time. Therefore it is important to capture funds in a timely manner. The issuing bank sets the expiration time interval, but most authorizations expire within 5 to7 days.  
The issuing bank does not inform `Cybersource` when an authorization confirmation expires. By default, the authorization information for each transaction remains in the `Cybersource` database for 180 days after the authorization date. To capture an authorization that expired with the issuing bank, you can resubmit the authorization request.

Offline Authorization {#payments-intro-processing-auth-offline}
===============================================================

Online transactions require an internet connection. In situations where the internet is not available, for example, due to an outage, merchants can continue to take credit card payments using offline transactions. An offline authorization is an authorization request for which you do not receive an immediate confirmation about the availability of funds.  
Offline authorizations have a higher level of risk than online transactions because they do not confirm funds availability or set aside the funds for later capture. Further, it can take up to 5 days to receive payment confirmations for offline transactions. To mitigate this risk, merchants may choose to fulfill orders only after receiving payment confirmation.

Pre-Authorization {#payments-intro-pre-auths}
=============================================

A pre-authorization enables you to authorize a payment when the final amount is unknown. The system places the funds on hold until you request a follow-up transaction. Pre-authorizations are typically used for lodging, auto rental, e-commerce, and restaurant transactions.
Payment Services Directive 2 (PSD2) rules in the European Union (EU) and European Economic Area (EEA) require the initial pre-authorization to use strong customer authentication for merchants or customers in PSD2-applicable countries.  
When you have a specific merchant category code (MCC) assigned to your account, you are allowed to capture up to 20% more than the cumulatively authorized amount on Visa, Diners Club, Discover, and JCB cards. Contact your account manager to have your account enabled for this option.  
For a pre-authorization:

* The authorization amount is greater than zero.
* Submit the authorization for capture within 30 calendar days of its request.
* When you do not capture the authorization, reverse it.  
  In the US, Canada, Latin America, and Asia Pacific, Mastercard charges an additional fee for a pre-authorization that is not captured and not reversed.  
  In Europe, Russia, Middle East, and Africa, Mastercard charges fees for all pre-authorizations.
* Chargeback protection is in effect for 30 days after the authorization.

Payment Network Token Authorization {#payments-intro-processing-auth-pnt}
=========================================================================

You can integrate authorizations with payment network tokens into your existing order management system. For an incremental authorization, you do not need to include any payment network tokenization fields in the authorization request because `Cybersource` obtains the payment network tokenization information from the original authorization request.

Authorization Workflow {#payments-intro-processing-auth-workflow}
=================================================================

This image and description show the authorization workflow:  
![](/content/dam/documentation/cybs/en-us/topics/payments-processing/card-processing/payments/images/Authorization2.svg/jcr:content/renditions/original)

1. The customer purchases goods or services from the merchant using a payment card.
2. You send an authorization request over secure internet connection to `Cybersource`. When the customer buys a digitally delivered product or service, you can request both the authorization and the capture at the same time. When the customer buys a physically fulfilled product, do not request the capture until you ship the product.
3. `Cybersource` validates the order information then contacts your payment processor and requests authorization.
4. The processor sends the transaction to the payment card company, which routes it to the issuing bank for the customer's payment card. Some card companies, including Discover and American Express, act as their own issuing banks.
5. The issuing bank approves or declines the request.
   * If funds are available, the issuing bank reserves the amount of the authorization request and returns an authorization approval to `Cybersource`.
   * If the issuing bank denies the request, it returns an authorization denial to `Cybersource`.
     {#payments-intro-processing-auth-workflow_ul_smg_gg5_rbc}
6. `Cybersource` runs its own tests then tells you whether the authorization succeeded.

Sale {#payments-intro-processing-sales}
=======================================

A sale is a bundled authorization and capture. Some processors and acquirers require a sale transaction instead of using separate authorization and capture requests. For other processors and acquirers, you can request a sale instead of a separate authorization and capture when you provide the goods or services immediately after taking an order.  
There are two types of sale processing: dual-message processing and single-message processing.

Dual-Message Processing {#payments-intro-processing-sales-dual}
===============================================================

Dual-message processing is a two-step process. The authorization is processed first. If the authorization is successful, the capture is processed immediately afterward. The response includes the authorization and the capture information. If the authorization is declined, the capture is not processed, and the response message includes only the authorization information.

Partial Authorizations {#payments-intro-processing-sales-dual-partialauth}
==========================================================================

All debit and prepaid card processors as well as a limited number of credit card processors support partial authorizations when dual-message processing is in place.  
When partial authorization is enabled, the issuing financial institution can approve a partial amount when the balance on the card is less than the requested amount. When a partial amount is authorized, the capture is not processed. The merchant can then use a second card to cover the balance, adjust the total cost, or void the transaction.

Single-Message Processing {#payments-intro-processing-sales-single}
===================================================================

Single-message processing treats the authorization and capture as a single transaction. There are important differences between dual-message processing and single-message processing:

* Single-message processing treats the request as a full-financial transaction, and with a successful transaction, funds are immediately transferred from the customer account to the merchant account.
* Authorization and capture amounts must be the same.
* Some features cannot be used with single-message processing.

Authorization Reversal {#payments-intro-processing-reversal}
============================================================

The authorization reversal service releases the hold that an authorization placed on a customer's payment card funds.  
Each card-issuing financial institution has its own rules for deciding whether an authorization reversal succeeds or fails. When a reversal fails, contact the card-issuing financial institution to learn whether there is a different way to reverse the authorization.  
If your processor supports authorization reversal after void (ARAV), you can reverse an authorization after you void the associated capture. If your processor does not support ARAV, you can use the authorization reversal service only for an authorization that has not been captured and settled.  
An authorization reversal is a follow-on transaction that uses the request ID returned from an authorization. The main purpose of a follow-on transaction is to link two transactions. The request ID links the follow-on transaction to the original transaction. The authorization request ID is used to look up the customer's billing and account information in the `Cybersource` database. You are not required to include those fields in the full authorization reversal request. The original transaction and follow-on transaction are linked in the database and in the `Business Center`.  
For processors that support debit cards and prepaid cards, the full authorization reversal service works for debit cards and prepaid cards in addition to credit cards.
You cannot perform an authorization reversal if a transaction is in a review state, which can occur if you use a fraud management service. You must reject the transaction prior to authorization reversal. For more information, see the fraud management documentation in the ` Business Center `.

Capture {#payments-intro-processing-capture}
============================================

A capture is a follow-on transaction to an authorization. It is used to transfer the authorized funds from the customer's account to the merchant account. To link the authorization transaction to the capture transaction, you include a request ID in your capture request. This request ID is returned to you in the authorization response.  
Captures are typically not performed in real time. They are placed in a batch file and sent to the processor, and the processor settles all of the captures at one time. In most cases, these batch files are sent and processed outside of the merchant's business hours. It usually takes 2 to 4 days for the acquiring financial institution to deposit the funds into the merchant account.  
When fulfilling only part of a customer's order, do not capture the full amount of the authorization. Capture only the cost of the delivered items. When you deliver the remaining items, request a new authorization, and then capture the new authorization.
It is not possible to perform a capture if a transaction is in a review state, which can occur if you use a fraud management service. You must accept the transaction prior to capture. For more information, see the fraud management documentation in the ` Business Center `.

Capture Workflow {#payments-intro-processing-capture-workflow}
==============================================================

The capture workflow begins when you send a request for a capture.  
![](/content/dam/documentation/cybs/en-us/topics/payments-processing/card-processing/payments/images/payments-capture-flow-660x225.svg/jcr:content/renditions/original)

1. The merchant sends a request for a capture to the `Cybersource` gateway.
2. For online captures, `Cybersource` validates the order information then sends an online capture to the payment processor. For offline captures, `Cybersource` stores the capture request in a batch file and sends the batch file to the payment processor after midnight.
3. The processor validates the request and forwards it to the issuing bank.
4. The issuing bank transfers funds to the acquiring bank.

The payment processor does not notify ` Cybersource ` that the money has been transferred. To ensure that all captures are processed correctly, you should reconcile your capture requests with the capture reports from your processor.

Credit {#payments-intro-processing-credit}
==========================================

Credits are payment refunds from a merchant to the cardholder after a cardholder pays for a product or service and that payment is captured by the merchant. When a credit request is successful, the issuer transfers funds from the merchant bank (acquirer) account to the customer's account. It typically takes 2 to 4 days for the acquirer to transfer funds from your merchant account.  
There are two types of credits: a *follow-on credit* that is linked to an original capture or sale, and a *stand-alone credit* that is not linked to an original capture or sale.

Follow-on Credit
----------------

Follow-on credits, also known as *refunds*, use the capture request ID to link the refund to the original transaction. This request ID is returned during the capture request (also known as a *settlement*) and is used in all subsequent refunds associated with the original capture. The request ID links the transaction to the customer's billing and account information, so you are not required to include those fields in the follow-on credit request.
When you combine a request for a follow-on credit with a request for another service, such as the tax calculation service, you must provide the customer's billing and account information.  
Unless otherwise specified, follow-on credits must be requested within 180 days of a settlement. You can request multiple follow-on credits against a single capture or sale transaction as long as the total amount does not exceed the original purchase amount. To perform multiple follow-on credits, use the same request ID in each request.

Stand-Alone Credits
-------------------

Stand-alone credits are not connected to an original transaction. Stand-alone credits do not have a time restriction, and they can be used to issue refunds more than 180 days after a transaction settlement.

Refund and Credit Workflow {#payments-intro-processing-credit-workflow}
=======================================================================

This workflow applies to follow-on credits, also known as refunds, and stand-alone credits. It begins when you send a request for a refund or credit.  
Refunds and credits do not happen in real time. All of the credit requests for a day are typically placed in a file and sent to the processor as a single *batch* transaction. In most cases, the batch transaction is settled overnight.  
![](/content/dam/documentation/cybs/en-us/topics/payments-processing/card-processing/payments/images/payments-credit-660x225.svg/jcr:content/renditions/original)

1. The merchant sends the refund or credit request to `Cybersource`.
2. For online refunds and credits, `Cybersource` validates the order information then sends the request to the payment processor. For offline refunds and credits, `Cybersource` stores the request in a batch file and sends the batch file to the payment processor after midnight.
3. The processor validates the request and forwards it to the acquiring bank.
4. The acquiring bank transfers funds to the issuing bank.

Not all processors support stand-alone credits.

Void {#payments-intro-processing-void}
======================================

A void cancels a capture or credit request that you submitted to `Cybersource` but has not already been submitted to your processor. Capture and credit requests are usually submitted to your processor once a day, so your window for successfully voiding a capture or credit request is small. A void request is declined when the capture or credit request has already been sent to the processor.  
After a void is processed, you cannot credit or capture the funds. You must perform a new transaction to capture or credit the funds. Further, when you void a capture, a hold remains on the authorized funds. If you are not going to re-capture the authorization, and if your processor supports authorization reversal after void (ARAV), you should request an authorization reversal to release the hold on the unused funds.  
A void uses the capture or credit request ID to link the transactions. The authorization request ID is used to look up the customer's billing and account information, so there is no need to include those fields in the void request. You cannot perform a follow-on credit against a capture that has been voided.

Payment Features {#payments-features-intro}
===========================================

You can apply features to different payment services to enhance the customer payment processing experience. This section includes an overview of these features:

* [Debit and Prepaid Card Payments](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-intro/payments-features-intro/payments-debit-prepaid-intro.md "")
* [Payer Authentication](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-intro/payments-features-intro/payments-processing-pa-intro.md "")

Debit and Prepaid Card Payments {#payments-debit-prepaid-intro}
===============================================================

Debit cards are linked to a cardholder's checking account. The funds are taken out of the customer's bank account, and the transaction is included on the customer's bank account statement. The customer does not receive a credit card bill as with a regular credit card.  
You can process debit cards using these services:

* Credit card services

Payer Authentication {#payments-processing-pa-intro}
====================================================

Payer authentication is run before a transaction is submitted for authorization. Most of the time payer authentication is bundled with authorization so that after payer authentication happens, the transaction is automatically submitted for authorization. Payer authentication and authorization can be configured to occur as separate operations. This section shows you how to run payer authentication as a separate process and pass the payer authentication data when seeking authorization for a transaction.  
Payer authentication consists of a two-step verification process that adds an extra layer of fraud protection during the payment process. During transactions, the transaction device, location, past purchasing habits, and other factors are analyzed for indications of fraud. This process collects customer data during the transaction from at least two of these three categories:

* **Something you have**: A payment card or a payment card number
* **Something you know**: A password or pin
* **Something you are**: Facial recognition or fingerprint

Each of these payment card companies has its own payer authentication product:

* **Mastercard**: Identity Check
* **Visa**: Visa Secure

Payer authentication can be used to satisfy the Strong Customer Authentication (SCA) requirement of the Payment Services Directive (PSD2). SCA applies to the European Economic Area (EEA) and the United Kingdom. SCA requires banks to perform additional checks when customers make payments to confirm their identity.  
See [Payer Authentication Processing](/docs/cybs/en-us/payments/developer/hsbc/so/payments/payments-processing-pa-process-intro.md "") for information about how to process payments with payer authentication.

Testing the Payment Services {#payments-testing-services}
=========================================================

To ensure that requests are processed correctly, you must test the basic success and error conditions for each service you plan to use.

Requirements for Testing {#payments-testing-requirements}
=========================================================

Before you can test, contact customer support to activate the credit card services and configure your account for testing. You must also contact your processor to set up your processor account.
When building your connection to the ` Cybersource ` payment gateway, ensure that you have implemented controls to prevent card testing or card enumeration attacks on your platform. For more information, see the [best practices guide](https://www.cybersource.com/content/dam/documents/en/payment-card-testing-bot-attacks.pdf ""). When we detect suspicious transaction activity associated with your merchant ID, including a card testing or card enumeration attack, ` Cybersource ` reserves the right to enable fraud management tools on your behalf in order to mitigate the attack. The fraud team might also implement internal controls to mitigate attack activity. These controls block traffic that is perceived as fraudulent. Additionally, if you are using one of our fraud tools and experience a significant attack, our internal team might modify or add rules to your configuration to help prevent the attack and minimize the threat to our infrastructure. However, any actions taken by ` Cybersource ` would not replace the need for you to follow industry standard best practices to protect your systems, servers, and platforms.  
Follow these requirements when you test your system:

* Use your regular merchant ID.
* Use a real combination for the city, state, and postal code.
* Use a real combination for the area code and telephone number.
* Use a nonexistent account and domain name for the customer's email address.
* Simple Order API test server: `https://ics2wstesta.ic3.com/commerce/1.x/transactionProcessor`

Test Card Numbers {#payments-testing-cards}
===========================================

Use these payment card numbers to test the authorization, capture, and credit services. Remove the spaces from the test card numbers when sending them to the test system. Do not use real payment card numbers. To test card types that are not included in the list, use an account number that is in the card's BIN range. For best results, try each test with a different service request and with different test payment card numbers.

> The test card numbers that are provided are formatted with Xs for zeroes in the card number. When testing with these card numbers, remove the spaces and replace each X with a 0 (zero).

* American Express---3782 8224 631X XX5
* Discover---6X11 1111 1111 1117
* JCB---3566 1111 1111 1113
* Maestro (International)
  * 5X33 9619 89X9 17
  * 5868 2416 0825 5333 38
    {#payments-testing-cards_ul_1}
* Maestro (UK Domestic)---the issue number is not required for Maestro (UK Domestic) transactions.
  * 6759 4111 XXXX XXX8
  * 6759 56XX 45XX 5727 054
  * 5641 8211 1116 6669
    {#payments-testing-cards_ul_2}
* Mastercard
  * 2222 42XX XXXX 1113
  * 2222 63XX XXXX 1125
  * 5555 5555 5555 4444
    {#payments-testing-cards_ul_3}
* Visa---4111 1111 1111 1111

Using Amounts to Simulate Errors {#payments-testing-amounts}
============================================================

You can simulate error messages by requesting authorization, capture, or credit services with specific amounts that trigger the error messages. These triggers work only on the test server, not on the production server.  
Each payment processor uses its own error messages. For more information, see: [Simple Order API Testing Information](https://developer.cybersource.com/docs/cybs/en-us/test-data/developer/all/so/test-data/so_overview.md "")

Test American Express Card Verification {#payments-testing-amex}
================================================================

Before using CVN with American Express, it is strongly recommended that you follow these steps:

1. Contact customer support to have your account configured for CVN. Until you do this, you will receive a `1` in the ccAuthReply_cvCode response field.
2. Test your system in production using a small currency amount, such as one currency unit. Instead of using the test account numbers, use a real payment card account number, and send an incorrect CVN in the request for authorization. The card should be refused and the request declined.

Standard Payment Processing {#payments-processing-basic-intro}
==============================================================

This section shows you how to process various authorization, capture, credit, and sales transactions.

Basic Authorization {#payments-processing-basic-auth-intro}
===========================================================

This section provides the information you need in order to process a basic authorization.
All supported card types can process authorizations.

Endpoint {#payments-processing-basic-auth-intro_d8e16}
------------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Declined Authorization {#payments-intro-processing-auth-decline}
================================================================

If an authorization is declined, you can use response categories to help you decide whether to retry or block a declined transaction. These response fields provide additional information:

* ccAuthReply_paymentInsightsInformation_responseInsightsCategory
* ccAuthReply_paymentInsightsInformation_responseInsightsCategoryCode  
  These fields are available starting in the XML schema version 1.193.

Category codes have possible values (such as `01`) each of which corresponds to a category that contains a description.  
You cannot retry this category code and category:

* `01 ISSUER_WILL_NEVER_APPROVE`

{#payments-intro-processing-auth-decline_ul_wxl_1yx_f5b}For these values, you can retry the transaction a maximum of 15 times over a period of 30 days:


* `02 ISSUER_CANNOT_APPROVE_AT_THIS_TIME`
* `03 ISSUER_CANNOT_APPROVE_WITH_THESE_DETAILS`: Data quality issue. Revalidate data prior to retrying the transaction.
* `04 GENERIC_ERROR`
* `97 PAYMENT_INSIGHTS_INTERNAL_ERROR`
* `98 OTHERS`
* `99 PAYMENT_INSIGHTS_RESPONSE_CATEGORY_MATCH_NOT_FOUND`
  {#payments-intro-processing-auth-decline_ul_zf4_4yx_f5b}

Required Fields for Processing a Basic Authorization {#payments-processing-basic-auth-required}
===============================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Processing a Basic Authorization {#payments-processing-basic-auth-ex-so}
==============================================================================================

Request

```keyword
billTo_city=Ann Arbor
billTo_country=US
billTo_email=null@cybersource.com
billTo_firstname=John
billTo_lastname=Smith
billTo_postalCode=48104-2201
billTo_state=MI
billTo_street1=201 S. Division St.
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2023
ccAuthService_run=true
merchant_id=npr_paymentech
merchant_referenceCode=TC42703-1
purchaseTotals_currency=usd
purchaseTotals_grandTotalAmount=100
```

Response to a Successful Request

```
requestID=6629977932421985593067
decision=ACCEPT
reasonCode=100
merchantReferenceCode=TC42703-1
purchaseTotals_currency=usd
ccAuthService_reconciliationID=57953165A7YFPS77
ccAuthReply_amount=100.00
ccAuthReply_avsCode=5
ccAuthReply_authorizationCode=570110
ccAuthReply_processorResponse=1
ccAuthReply_authorizedDateTime=2022-09-12T154953Z
ccAuthReply_paymentNetworkTransactionID=123456789619999
```

Response to a Declined Request

```
requestID=6629977932421985593067
merchantReferenceCode=Merchant_REF
decision=REJECT
ccAuthReply_avsCode=Y
ccAuthReply_avsCodeRaw=Y
ccAuthReply_paymentNetworkTransactionID=111222
ccAuthReply_transactionID=111222
ccAuthReply_paymentInsightsInformation_responseInsightsCategory=
    ISSUER_CANNOT_APPROVE_WITH_THESE_DETAILS
ccAuthReply_paymentInsightsInformation_responseInsightsCategoryCode=03
ccAuthReply_processorResponse=183  
ccAuthReply_reasonCode=233
```

Authorization with Line Items {#payments-processing-basic-auth-lineitem-intro}
==============================================================================

This section shows you how to process an authorization with line items.
The main difference between a basic authorization and an authorization that includes line items is that the purchaseTotals_grandTotalAmount field, which is included in a basic authorization, is substituted with one or more line items that are included in the item_#_ fields, starting with the item_0_ fields.

Fields Specific to this Use Case
--------------------------------

These fields are required for each line item that you use:

item_#_unitPrice
:

item_#_quantity
:

item_#_productCode
:

item_#_productSKU
:
Optional when item_#_productCode is set to `default`, `shipping_only`, `handling_only`, or `shipping_and_handling`

item_#_productName
:
Optional when item_#_productCode is set to `default`, `shipping_only`, `handling_only`, or `shipping_and_handling`
{#payments-processing-basic-auth-lineitem-intro_dl_ht4_hlx_rxb}  
At a minimum, you must include the item_#_unitPrice field in order to include a line item in an authorization. When this field is the only field included in the authorization, the system sets:

* item_#_productCode: `default`
* item_#_quantity: `1`

For example, these three line items are valid.

```
item_0_unitPrice=10.00
item_1_unitPrice=5.99
item_1_quantity=3
item_1_productCode=shipping_only
item_2_unitPrice=29.99
item_2_quantity=3
item_2_productCode=electronic_good
item_2_productSKU=12384569
item_2_productName=receiver
```

Endpoint {#payments-processing-basic-auth-lineitem-intro_d8e16}
---------------------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Optional Line Item Fields {#payments-processing-basic-auth-lineitem-inst-ops-so}
================================================================================

These fields can be used to provide more line item information. For more information on each field, see the field reference guide:

* item_#_buyerRegistration
* item_#_commodityCode
* item_#_nationalTax
* item_#_orderAcceptanceCity
* item_#_orderAcceptanceCountry
* item_#_orderAcceptancePostalCode
* item_#_orderAcceptanceState
* item_#_orderOriginCity
* item_#_orderOriginCountry
* item_#_orderOriginPostalCode
* item_#_orderOriginState
* item_#_otherTax_#_passengerFirstName
* item_#_otherTax_#_passengerLastName
* item_#_productCode
* item_#_productDescription
* item_#_productName
* item_#_productSKU
* item_#_quantity
* item_#_shippingDestinationType
* item_#_unitPrice

Required Fields for Processing an Authorization with Line Items {#payments-processing-basic-auth-lineitem-required}
===================================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:
:
Required when billTo_personalID is included in the request.

purchaseTotals_currency

purchaseTotals_grandTotalAmount
:
Either purchaseTotals_grandTotalAmount or item_#_unitPrice must be included in the request.

Simple Order Example: Processing an Authorization with Line Items {#payments-processing-basic-auth-lineitem-ex-so}
==================================================================================================================

Request

```keyword
billTo_city=Palo Alto
billTo_country=US
billTo_email=null@cybersource.com
billTo_firstname=Julia
billTo_lastname=Fernandez
billTo_postalCode=94053
billTo_state=CA
billTo_street1=123 Main St.
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2023
ccAuthService_run=true
dcc_dccIndicator=1
merchant_id=MID23
merchant_referenceCode=Merchant_REF
purchaseTotals_currency=usd
item_0_unitPrice=10.00
item_1_unitPrice=5.99
item_1_quantity=3
item_1_productCode=shipping_only
item_2_unitPrice=29.99
item_2_quantity=3
item_2_productCode=electronic_good
item_2_productSKU=12384569
item_2_productName=receiver
purchaseTotals_exchangeRate=0.91
purchaseTotals_originalAmount=107.33
purchaseTotals_originalCurrency=eur
```

Response to a Successful Request

```
additional_processor_response=e1cdcafc-cdbb-4ef7-8788-a1234e844805
request_id=6461515866500167772420
decision=ACCEPT
reasonCode=100
merchantReferenceCode=Merchant_REF
purchaseTotals_currency=usd
cardCategory=FccAuthService_reconciliationID=ZUDCXJO8KZRFXQJJ
ccAuthReply_amount=117.94
ccAuthReply_avsCode=5
ccAuthReply_authorizationCode=570110
ccAuthReply_processorResponse=1
ccAuthReply_authorizedDateTime=2022-03-01T161947Z
ccAuthReply_paymentNetworkTransactionID=111222
```

Authorization with Payment Network Tokens {#pnt-auth-intro}
===========================================================

This section shows you how to successfully process an authorization with payment network tokens.

> Due to mandates from the Reserve Bank of India, merchants based in India cannot store personal account numbers (PAN). Use network tokens instead. For more information on network tokens, see the Network Tokenization section of the [` Token Management Service ` Guide.](https://developer.cybersource.com/docs.md#TokenManagementService "")

Endpoint {#pnt-auth-intro_d12e16}
---------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Authorizations with Payment Network Tokens {#pnt-req-fields}
================================================================================

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_street1
:

ccAuthService_networkTokenCryptogram
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

token_expirationMonth
:

token_expirationYear
:

Optional Fields for Authorizations with Payment Network Tokens {#pnt-optional-fields}
=====================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:
Required only for transactions in the U.S. and Canada.

billTo_state
:
Required only for transactions in the U.S. and Canada.

billTo_street1
:

card_accountNumber
:
Set to the token value that you received from the token service provider.

card_cardType
:
It is strongly recommended that you send the card type even if it is optional for your processor. Omitting the card type can cause the transaction to be processed with the wrong card type.

card_expirationMonth
:
Set to the token expiration month that you received from the token service provider.

card_expirationYear
:
Set to the token expiration year that you received from the token service provider.

ccAuthService_cavv
:
For 3-D Secure in-app transactions for Visa, set to the 3-D Secure cryptogram. Otherwise, set to the network token cryptogram.

ccAuthService_commerceIndicator
:

ccAuthService_networkTokenCryptogram
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount or item_#_unitPrice
:

paymentNetworkToken_transactionType
:

paymentNetworkToken_requestorID

ucaf_authenticationData
:
For Mastercard requests, set this field to the Identity Check cryptogram.

ucaf_collectionIndicator
:
For Mastercard requests, set the value to `2`.

Simple Order API Example: Authorizations with Payment Network Tokens {#pnt-ex-so}
=================================================================================

Request

```
&lt;requestMessage&gt;
    &lt;purchaseTotals&gt;
        &lt;currency&gt;USD&lt;/currency&gt;
        &lt;grandTotalAmount&gt;16.00&lt;/grandTotalAmount&gt;
    &lt;/purchaseTotals&gt;
    &lt;card&gt;
        &lt;accountNumber&gt;4111111111111111&lt;/accountNumber&gt;
        &lt;expirationMonth&gt;12&lt;/expirationMonth&gt;
        &lt;expirationYear&gt;2031&lt;/expirationYear&gt;
    &lt;/card&gt;
    &lt;ccAuthService run="true"&gt;
        &lt;networkTokenCryptogram&gt;qE5juRwDzAUFBAkEHuWW9PiBkWv=&lt;/networkTokenCryptogram&gt;
    &lt;/ccAuthService&gt;
    &lt;paymentNetworkToken&gt;
        &lt;transactionType&gt;1&lt;/transactionType&gt;
    &lt;/paymentNetworkToken&gt;
&lt;/requestMessage&gt;
```

Successful Response

```
&lt;c:replyMessage&gt;
    &lt;c:merchantReferenceCode&gt;Postman-1684858432&lt;/c:merchantReferenceCode&gt;
    &lt;c:requestID&gt;6848584316126969103007&lt;/c:requestID&gt;
    &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:purchaseTotals&gt;
        &lt;c:currency&gt;USD&lt;/c:currency&gt;
    &lt;/c:purchaseTotals&gt;
    &lt;c:ccAuthReply&gt;
        &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
        &lt;c:amount&gt;16.00&lt;/c:amount&gt;
        &lt;c:authorizationCode&gt;888888&lt;/c:authorizationCode&gt;
        &lt;c:avsCode&gt;X&lt;/c:avsCode&gt;
        &lt;c:avsCodeRaw&gt;I1&lt;/c:avsCodeRaw&gt;
        &lt;c:authorizedDateTime&gt;2023-05-23T16:13:51Z&lt;/c:authorizedDateTime&gt;
        &lt;c:processorResponse&gt;100&lt;/c:processorResponse&gt;
        &lt;c:reconciliationID&gt;78849228NHPFQCKD&lt;/c:reconciliationID&gt;
        &lt;c:paymentNetworkTransactionID&gt;123456789619999&lt;/c:paymentNetworkTransactionID&gt;
     &lt;/c:ccAuthReply&gt;
     &lt;c:card&gt;
         &lt;c:cardType&gt;001&lt;/c:cardType&gt;
     &lt;/c:card&gt;
&lt;/c:replyMessage&gt;
```

Authorization with a Card Verification Number {#payments-auth-cvn-procedure}
============================================================================

This section shows you how to process an authorization with a Card Verification Number (CVN).

CVN Results
-----------

The response includes a raw response code and a mapped response code:

* The raw response code is the value returned by the processor. This value is returned in the ccAuthReply_cvCodeRaw field. Use this value only for debugging purposes; do not use it to determine the card verification response.
* The mapped response code is the pre-defined value that corresponds to the raw response code. This value is returned in the ccAuthReply_cvCode field.  
  Even when the CVN does not match the expected value, the issuing bank might still authorize the transaction. You will receive a CVN decline, but you can still capture the transaction because it has been authorized by the bank. However, you must review the order to ensure that it is legitimate.  
  Settling authorizations that fail the CVN check might have an impact on the fees charged by your bank. Contact your bank for details about how card verification management might affect your discount rate.  
  When a CVN decline is received for the authorization in a sale request, the capture request is not processed unless you set the businessRules_ignoreCVResult field to `true`.

CVN Results for Visa and Mastercard
:
A CVN code of `D` or `N` causes the request to be declined with a reason code value of `230`. You can still capture the transaction, but you must review the order to ensure that it is legitimate.

    `Cybersource`, not the issuer, assigns the CVN decline to the authorization. You can capture any authorization that has a valid authorization code from the issuer, even when the request receives a CVN decline.

    When the issuer does not authorize the transaction and the CVN does not match, the request is declined because the card is refused. You cannot capture the transaction.

Endpoint {#payments-auth-cvn-procedure_d8e16}
---------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing an Authorization with a Card Verification Number {#payments-auth-cvn-required}
=============================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_cvNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Optional Fields for Processing an Authorization with a Card Verification Number {#payments-auth-cvn-optional}
=============================================================================================================

You can use these optional fields to include additional information when processing an authorization with a card verification number.

businessRules_ignoreCVResult
:

card_cvIndicator
:

Simple Order Example: Processing an Authorization with a Card Verification Number {#payments-auth-cvn-ex-so}
============================================================================================================

Request

```
ccAuthService_run=true
merchantID=Napa Valley Vacations
merchantReferenceCode=482046C3A7E94F5
billTo_firstName=John
billTo_lastName=Doe
billTo_street1=1295 Charleston Rd.
billTo_city=Mountain View
billTo_state=CA
billTo_postalCode=94043
billTo_country=US
billTo_phoneNumber=650-965-6000
billTo_email=jdoe@example.com
item_0_unitPrice=49.95
item_0_quantity=1
purchaseTotals_currency=USD
card_expirationMonth=12
card_expirationYear=2031
card_accountNumber=4111111111111111
card_cvNumber=999
card_cardType=001
```

Response to a Successful Request

```
requestID=0305782650000167905080
decision=ACCEPT
reasonCode=100
merchantReferenceCode=482046C3A7E94F5
purchaseTotals_currency=USD
ccAuthReply_reconciliationID=ABCDE12345FGHIJ67890
ccAuthReply_cardCategory=F^
ccAuthReply_cardGroup=0
ccAuthReply_reasonCode=100
ccAuthReply_amount=49.95
ccAuthReply_authorizationCode=123456
ccAuthReply_avsCode=Y
ccAuthReply_avsCodeRaw=YYY
ccAuthReply_processorResponse=A
ccAuthReply_paymentNetworkTransactionID=3312345
```

Authorization with Strong Customer Authentication Exemption {#payments-processing-pa-sca-exempts-intro}
=======================================================================================================

This section shows you how to process an authorization with a strong customer authentication (SCA) exemption.  
You can use SCA exemptions to streamline the payment process. SCA exemptions are part of the European second Payment Services Directive (PSD2) and allow certain types of low-risk transactions to bypass additional authentication steps while still remaining compliant with PSD2. You can choose which exemption can be applied to a transaction, but the card-issuing bank actually grants an SCA exemption during card authentication.  
You can process an authorization with two types of SCA exemptions:

* **Exemption on Authorization**: Send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you may be required to request further authentication upon retry.
* **Exemption on Authentication**: Request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details.  
  Depending on your processor, use one of these exemption fields:

> If you send more than one SCA exemption field with a single authentication, the transaction is denied.

* **Authentication Outage**: Payer authentication is not available for this transaction due to a system outage.
* **B2B Corporate Card**: Payment cards specifically for business-to-business transactions are exempt.
* **Delegated Authentication**: Payer authentication was performed outside of the authorization workflow.
* **Follow-On Installment Payment**: Installment payments of a fixed amount are exempt after the first transaction.
* **Follow-On Recurring Payment**: Recurring payments of a fixed amount are exempt after the first transaction.
* **Low Risk**: The average fraud levels associated with this transaction are considered low.
* **Low Value**: The transaction value does not warrant SCA.
* **Merchant Initiated Transactions**: As follow-on transactions, merchant-initiated transactions are exempt.
* **Stored Credential Transaction**: Credentials are authenticated before storing, so stored credential transactions are exempt.
* **Trusted Merchant**: Merchants registered as trusted beneficiaries.

Fields Specific to the Strong Customer Authentication Exemptions {#payments-processing-pa-sca-exempts-intro_fields-specific-to-auth}
------------------------------------------------------------------------------------------------------------------------------------

Use one of these fields to request an SCA exemption:

> If you are using the ` HSBC ` processor, you must obtain approval from ` HSBC ` before you use strong customer authentication (SCA) exemptions on authorization transactions for these exemption types:
>
> * Authentication outage
> * Follow-on recurring payment
> * Low-risk transaction
>   This requirement does not apply to low-value transactions.

ccAuthService_authenticationOutageExemptionIndicator
:
Exemption type: Authentication Outage
:
Value: `1`

ccAuthService_commerceIndicator
:
Exemption type: Follow-on Recurring Payment
:
Value: `recurring`

ccAuthService_riskAnalysisExemptionIndicator
:
Exemption type: Low Risk Transaction
:
Value: `1`

ccAuthService_lowValueExemptionIndicator
:
Exemption type: Low Value Transaction
:
Value: `1`

subsequentAuthReason
:
Exemption type: Merchant Initiated Transaction
:
Value: See field description.

subsequentAuthStoredCredential
:
Exemption type: Stored Credential Transaction
:
Value: `1`

Processor Support for SCA Exemptions
------------------------------------

You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you may be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:

|        |                                            **Authentication Outage**                                            |                                         **Follow-On Recurring Payment**                                         |                                                  **Low Value**                                                  |                                          **Transaction Risk Analysis**                                          |
|--------|-----------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------|
| `HSBC` | ![](/content/dam/documentation/cybs/en-us/common/images/circlecheck-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlecheck-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlecheck-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlecheck-filled.svg/jcr:content/renditions/original) |
[Processor Support for SCA Exemption on Authorization]

You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:

|        |                                           **B2B Corporate Card**                                            |                                          Delegated Authentication                                           |                                                **Low Risk**                                                 |                                                **Low Value**                                                |                                            **Trusted Merchant**                                             |
|--------|-------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------|
| `HSBC` | ![](/content/dam/documentation/cybs/en-us/common/images/circlex-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlex-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlex-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlex-filled.svg/jcr:content/renditions/original) | ![](/content/dam/documentation/cybs/en-us/common/images/circlex-filled.svg/jcr:content/renditions/original) |
[Processor Support for SCA Exemption on Authentication]

For more information, see the [Exemption Test Cases](https://developer.cybersource.com/docs/cybs/en-us/payer-authentication/developer/all/rest/payer-auth/pa-testing-intro/pa-testing-exemption-test-intro.md "") section of the *Payer Authentication Developer Guide*.

Endpoint {#payments-processing-pa-sca-exempts-intro_d8e16}
----------------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing an Authorization with an SCA Exemption {#payments-processing-pa-sca-exempts-required}
====================================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Processing an Authorization with an SCA Exemption for Low Value Transactions {#payments-processing-pa-sca-exampts-ex-so}
==============================================================================================================================================

Request

```keyword
&lt;requestMessage&gt;
  &lt;merchantID&gt;{{merchantID}}&lt;/merchantID&gt;
  &lt;merchantReferenceCode&gt;Postman-{{$timestamp}}&lt;/merchantReferenceCode&gt;
  &lt;billTo&gt;
    &lt;firstName&gt;John&lt;/firstName&gt;
    &lt;lastName&gt;Doe&lt;/lastName&gt;
    &lt;street1&gt;1295 Charleston Road&lt;/street1&gt;
    &lt;city&gt;Mountain View&lt;/city&gt;
    &lt;state&gt;CA&lt;/state&gt;
    &lt;postalCode&gt;94043&lt;/postalCode&gt;
    &lt;country&gt;US&lt;/country&gt;
    &lt;email&gt;null@cybersource.com&lt;/email&gt;
  &lt;/billTo&gt;
  &lt;purchaseTotals&gt;
    &lt;currency&gt;USD&lt;/currency&gt;
    &lt;grandTotalAmount&gt;1.01&lt;/grandTotalAmount&gt;
  &lt;/purchaseTotals&gt;
  &lt;card&gt;
    &lt;accountNumber&gt;4111111111111111&lt;/accountNumber&gt;
    &lt;expirationMonth&gt;12&lt;/expirationMonth&gt;
    &lt;expirationYear&gt;2023&lt;/expirationYear&gt;
    &lt;cardType&gt;001&lt;/cardType&gt;
  &lt;/card&gt;
  &lt;ccAuthService run="true"&gt;
    &lt;lowValueExemptionIndicator&gt;1&lt;/lowValueExemptionIndicator&gt;
  &lt;/ccAuthService&gt;
&lt;/requestMessage&gt;
```

Response to a Successful Request

```
&lt;c:replyMessage&gt;
  &lt;c:merchantReferenceCode&gt;Postman-1666374834&lt;/c:merchantReferenceCode&gt;
  &lt;c:requestID&gt;6663748348516429203007&lt;/c:requestID&gt;
  &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
  &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
  &lt;c:purchaseTotals&gt;
    &lt;c:currency&gt;USD&lt;/c:currency&gt;
  &lt;/c:purchaseTotals&gt;
  &lt;c:ccAuthReply&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:amount&gt;1.01&lt;/c:amount&gt;
    &lt;c:authorizationCode&gt;888888&lt;/c:authorizationCode&gt;
    &lt;c:avsCode&gt;X&lt;/c:avsCode&gt;
    &lt;c:avsCodeRaw&gt;I1&lt;/c:avsCodeRaw&gt;
    &lt;c:authorizedDateTime&gt;2022-10-21T17:53:54Z&lt;/c:authorizedDateTime&gt;
    &lt;c:processorResponse&gt;100&lt;/c:processorResponse&gt;
    &lt;c:reconciliationID&gt;66737280B9CGUCCP&lt;/c:reconciliationID&gt;
    &lt;c:paymentNetworkTransactionID&gt;123456789619999&lt;/c:paymentNetworkTransactionID&gt;
  &lt;/c:ccAuthReply&gt;
  &lt;c:card&gt;
    &lt;c:cardType&gt;001&lt;/c:cardType&gt;
  &lt;/c:card&gt;
&lt;/c:replyMessage&gt;
```

Account Verification with a Zero Amount Authorization {#payments-processing-basic-zero-auth-intro}
==================================================================================================

Account verification with zero amount authorization is a standard e-commerce practice where you send a zero amount transaction to verify a card is valid and whether the card is lost or stolen. You cannot capture a zero amount authorization.  
Most card networks refer to card account validation as zero amount authorization (ZAA). These card networks have their own names for the service:

* Discover Zero Dollar Authorization
* Visa Account Verification

{#payments-processing-basic-zero-auth-intro_ul_j3f_tsl_qhc}

Processor-Specific Information
------------------------------

`HSBC`
:
AVS and CVN are supported.
:
Card types: Maestro (International), Maestro (UK Domestic), Mastercard, Visa
:
The commerce indicator must be `internet` or `moto`.
:
The authorization code is not returned.

Endpoint {#payments-processing-basic-zero-auth-intro_d8e16}
-----------------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Account Verification with Zero Amount Authorization {#payments-processing-basic-zero-auth-required}
=======================================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency

purchaseTotals_grandTotalAmount
:

Simple Order Example: Account Verification with a Zero Amount Authorization {#payments-processing-basic-zero-auth-ex-so}
========================================================================================================================

Request

```keyword
billTo_city=Sao Paulo
billTo_country=BR
billTo_email=null@cybersource.com
billTo_firstname=Julia
billTo_lastname=Fernandez
billTo_postalCode=01310-000
billTo_state=SP
billTo_street1=R. Augusta
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2023
ccAuthService_run=true
merchant_id=MID23
merchant_referenceCode=Merchant_REF
purchaseTotals_currency=mxn
purchaseTotals_grandTotalAmount=0
```

Response to a Successful Request

```
additional_processor_response=e1cdcafc-cdbb-4ef7-8788-a1234e844805
request_id=6461515866500167772420
decision=ACCEPT
reasonCode=100
merchantReferenceCode=Merchant_REF
purchaseTotals_currency=mxn
cardCategory=FccAuthService_reconciliationID=ZUDCXJO8KZRFXQJJ
ccAuthReply_amount=0
ccAuthReply_avsCode=5
ccAuthReply_authorizationCode=570110
ccAuthReply_processorResponse=1
ccAuthReply_authorizedDateTime=2022-03-01T161947Z
ccAuthReply_paymentNetworkTransactionID=111222
```

Pre-Authorization {#payments-processing-pre-auth-intro}
=======================================================

This section provides the information you need in order to process a pre-authorization.  
A pre-authorization enables you to authorize a payment when the final amount is unknown. The system places the funds on hold until you request a follow-up transaction. Pre-authorizations are typically used for lodging, auto rental, e-commerce, and restaurant transactions.
Payment Services Directive 2 (PSD2) rules in the European Union (EU) and European Economic Area (EEA) require the initial pre-authorization to use strong customer authentication for merchants or customers in PSD2-applicable countries.  
When you have a specific merchant category code (MCC) assigned to your account, you are allowed to capture up to 20% more than the cumulatively authorized amount on Visa, Diners Club, Discover, and JCB cards. Contact your account manager to have your account enabled for this option.  
For a pre-authorization:

* The authorization amount is greater than zero.
* Submit the authorization for capture within 30 calendar days of its request.
* When you do not capture the authorization, reverse it.  
  In the US, Canada, Latin America, and Asia Pacific, Mastercard charges an additional fee for a pre-authorization that is not captured and not reversed.  
  In Europe, Russia, Middle East, and Africa, Mastercard charges fees for all pre-authorizations.
* Chargeback protection is in effect for 30 days after the authorization.

Endpoint {#payments-processing-pre-auth-intro_d8e16}
----------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for a Pre-Authorization {#payments-processing-pre-auth-required}
================================================================================

Use these required fields for processing a pre-authorization.

authIndicator
:
Set the value to `0`.

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Processing a Pre-Authorization {#payments-processing-pre-auth-ex-so}
==========================================================================================

Request

```keyword
billTo_city=Ann Arbor
billTo_country=US
billTo_email=null@cybersource.com
billTo_firstname=John
billTo_lastname=Smith
billTo_postalCode=48104-2201
billTo_state=MI
billTo_street1=201 S. Division St.
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2023
ccAuthService_run=true
merchant_id=npr_paymentech
merchant_referenceCode=TC42703-1
purchaseTotals_currency=usd
purchaseTotals_grandTotalAmount=100
authIndicator=0
```

Response to a Successful Request

```
requestID=6629977932421985593067
decision=ACCEPT
reasonCode=100
merchantReferenceCode=TC42703-1
purchaseTotals_currency=usd
ccAuthService_reconciliationID=57953165A7YFPS77
ccAuthReply_amount=100.00
ccAuthReply_avsCode=5
ccAuthReply_authorizationCode=570110
ccAuthReply_processorResponse=1
ccAuthReply_authorizedDateTime=2022-09-12T154953Z
ccAuthReply_paymentNetworkTransactionID=123456789619999
```

Response to a Declined Request

```
requestID=6629977932421985593067
merchantReferenceCode=Merchant_REF
decision=REJECT
ccAuthReply_avsCode=Y
ccAuthReply_avsCodeRaw=Y
ccAuthReply_paymentNetworkTransactionID=111222
ccAuthReply_transactionID=111222
ccAuthReply_paymentInsightsInformation_responseInsightsCategory=
    ISSUER_CANNOT_APPROVE_WITH_THESE_DETAILS
ccAuthReply_paymentInsightsInformation_responseInsightsCategoryCode=03
ccAuthReply_processorResponse=183  
ccAuthReply_reasonCode=233
```

Final Authorization Indicator {#payments-final-auth-indicator}
==============================================================

The purpose of this feature is to ensure that unused funds are reversed, so that customer's funds are available again when an order is not fulfilled.  
For an authorization with an amount greater than zero, indicate whether the authorization is a final authorization, a pre-authorization, or an undefined authorization.  
You can set a default authorization type in your account. To set the default authorization type in your account, contact customer support.  
Chargeback protection is in effect for seven days after the authorization.

Supported Services
------------------

* Authorization
* Incremental authorization

Supported Card Types {#payments-final-auth-indicator_lcr-process-prereq}
------------------------------------------------------------------------

* Maestro (International)
* Maestro (UK Domestic)
* Mastercard

Requirements for Final Authorizations {#payments-final-auth-indicator-final-auth}
=================================================================================

For a final authorization:

* The authorization amount must be greater than zero.
* The authorization amount must be the final amount that the customer agrees to pay.
* The authorization should not be cancelled after it is approved except when a system failure occurs.
* The authorization must be submitted for capture within seven calendar days of its request.
* The capture amount and currency must be the same as the authorization amount and currency.

Pre-Authorizations {#payments-final-auth-indicator-preauth}
===========================================================

A pre-authorization enables you to authorize a payment when the final amount is unknown. The system places the funds on hold until you request a follow-up transaction. Pre-authorizations are typically used for lodging, auto rental, e-commerce, and restaurant transactions.
Payment Services Directive 2 (PSD2) rules in the European Union (EU) and European Economic Area (EEA) require the initial pre-authorization to use strong customer authentication for merchants or customers in PSD2-applicable countries.  
When you have a specific merchant category code (MCC) assigned to your account, you are allowed to capture up to 20% more than the cumulatively authorized amount on Visa, Diners Club, Discover, and JCB cards. Contact your account manager to have your account enabled for this option.  
For a pre-authorization:

* The authorization amount is greater than zero.
* Submit the authorization for capture within 30 calendar days of its request.
* When you do not capture the authorization, reverse it.  
  In the US, Canada, Latin America, and Asia Pacific, Mastercard charges an additional fee for a pre-authorization that is not captured and not reversed.  
  In Europe, Russia, Middle East, and Africa, Mastercard charges fees for all pre-authorizations.
* Chargeback protection is in effect for 30 days after the authorization.

Unmarked Authorizations {#payments-final-auth-indicator-unmarked-auth}
======================================================================

An authorization is unmarked when the default authorization type is not set in your account and you do not include the authIndicator field in the authorization request. To set the default authorization type in your account, contact customer support.  
Unmarked authorizations are supported only in the US, Canada, Latin America, and Asia Pacific. They are not supported in Europe, Russia, Middle East, and Africa.  
`Cybersource` does not set a mark or indicator for the type of authorization in the request that is sent to the processor.
Your acquirer processes an unmarked authorization as a final authorization, a pre-authorization, or an undefined authorization. Contact your acquirer to learn how they process unmarked authorizations.

Requirements for Unmarked Authorizations {#payments-final-auth-indicator-unmarked-auth2}
========================================================================================

For an unmarked authorization:

* The authorization amount must be greater than zero.
* The authorization amount can be different from the final transaction amount.

Undefined Authorizations {#payments-final-auth-indicator-undef-auth}
====================================================================

An authorization is undefined when you set the default authorization type in your account to undefined and do not include the authIndicator field in the authorization request. To set the default authorization type in your account, contact customer support.  
Undefined authorizations are supported only in the U.S., Canada, Latin America, and Asia Pacific. They are not supported in Europe, Russia, Middle East, and Africa.  
Chargeback protection is in effect for seven days after the authorization.

Requirements for Undefined Authorizations {#payments-final-auth-indicator-undef-auth2}
======================================================================================

For an undefined authorization:

* The authorization amount must be greater than zero.
* The authorization amount can be different from the final transaction amount.
* The authorization should not be cancelled after it is approved except when a system failure occurs.
* The authorization must be submitted for capture within seven calendar days of its request.
* When you do not capture the authorization, you must reverse it; otherwise, Mastercard charges an additional fee for the transaction.

Required Fields for Final Authorizations {#payments-final-auth-indicator-required}
==================================================================================

authIndicator
:
Set the value to `0` for pre-authorizations, or to `1` for final authorizations. Do not include this field for unmarked or undefined authorizations.

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency

purchaseTotals_grandTotalAmount
:

Simple Order Example: Final Authorizations {#payments-final-auth-indicator-ex-so}
=================================================================================

Request

```keyword
&lt;requestMessage xmlns="urn:schemas-cybersource-com:transaction-data-1.{{WSDLVersion}}"&gt;
    &lt;merchantID&gt;testrest&lt;/merchantID&gt;
    &lt;billTo&gt;
        &lt;firstName&gt;John&lt;/firstName&gt;
        &lt;lastName&gt;Doe&lt;/lastName&gt;
        &lt;street1&gt;1295 Charleston Road&lt;/street1&gt;
        &lt;city&gt;Mountain View&lt;/city&gt;
        &lt;state&gt;CA&lt;/state&gt;
        &lt;postalCode&gt;94043&lt;/postalCode&gt;
        &lt;country&gt;US&lt;/country&gt;
        &lt;email&gt;test@cybs.com&lt;/email&gt;
    &lt;/billTo&gt;
    &lt;purchaseTotals&gt;
        &lt;currency&gt;USD&lt;/currency&gt;
        &lt;grandTotalAmount&gt;1.02&lt;/grandTotalAmount&gt;
    &lt;/purchaseTotals&gt;
    &lt;card&gt;
        &lt;accountNumber&gt;4111111111111111&lt;/accountNumber&gt;
        &lt;expirationMonth&gt;12&lt;/expirationMonth&gt;
        &lt;expirationYear&gt;2023&lt;/expirationYear&gt;
        &lt;cardType&gt;001&lt;/cardType&gt;
    &lt;/card&gt;
    &lt;ccAuthService run="true"/&gt;
    &lt;authIndicator&gt;1&lt;/authIndicator&gt;
&lt;/requestMessage&gt;                
```

Response to a Successful Request

```
&lt;c:replyMessage xmlns:c="urn:schemas-cybersource-com:transaction-data-1.142"&gt;
    &lt;c:merchantReferenceCode&gt;Postman-1691009216&lt;/c:merchantReferenceCode&gt;
    &lt;c:requestID&gt;6910092160816328603011&lt;/c:requestID&gt;
    &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:purchaseTotals&gt;
        &lt;c:currency&gt;USD&lt;/c:currency&gt;
    &lt;/c:purchaseTotals&gt;
    &lt;c:ccAuthReply&gt;
        &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
        &lt;c:amount&gt;1.02&lt;/c:amount&gt;
        &lt;c:authorizationCode&gt;888888&lt;/c:authorizationCode&gt;
        &lt;c:avsCode&gt;X&lt;/c:avsCode&gt;
        &lt;c:avsCodeRaw&gt;I1&lt;/c:avsCodeRaw&gt;
        &lt;c:authorizedDateTime&gt;2023-08-02T20:46:56Z&lt;/c:authorizedDateTime&gt;
        &lt;c:processorResponse&gt;100&lt;/c:processorResponse&gt;
        &lt;c:reconciliationID&gt;78194788VKQUQO9Q&lt;/c:reconciliationID&gt;
        &lt;c:paymentNetworkTransactionID&gt;123456789619999&lt;/c:paymentNetworkTransactionID&gt;
    &lt;/c:ccAuthReply&gt;
    &lt;c:card&gt;
        &lt;c:cardType&gt;001&lt;/c:cardType&gt;
    &lt;/c:card&gt;
    &lt;c:pos&gt;
        &lt;c:terminalID&gt;111111&lt;/c:terminalID&gt;
    &lt;/c:pos&gt;
&lt;/c:replyMessage&gt;                    
```

Authorization Reversal {#payments-processing-basic-auth-reversal-intro}
=======================================================================

This section provides the information about how to process an authorization reversal.  
Reversing an authorization releases the hold on the customer's payment card funds that the issuing bank placed when processing the authorization.  
For a debit card or prepaid card in which only a partial amount was approved, the amount of the reversal must be the amount that was authorized, not the amount that was requested.  
All supported card types can process authorization reversals.

Endpoint {#payments-processing-basic-auth-reversal-intro_d8e64}
---------------------------------------------------------------

Set the ccAuthReversalService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing an Authorization Reversal {#payments-processing-basic-auth-reversal-required-fields}
===================================================================================================================

ccAuthReversalService_authRequestID
:
Set the value to the request ID included in the authorization response message.

ccAuthReversalService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:
The amount of the reversal must be the same as the authorization amount that was included in the authorization response message. Do not use the amount that was requested in the authorization request message.

Simple Order Example: Processing an Authorization Reversal {#payments-processing-basic-auth-reversal-ex-so-nvp}
===============================================================================================================

Request

```
ccAuthReversalService_authRequestID=6522033834410167772169
ccAuthReversalService_run=true
merchantReferenceCode=482046C3A7E94F5BD1FE3C66C
merchantID=Napa Valley Vacations
purchaseTotals_currency=USD
purchaseTotals_grandTotalAmount=49.95
```

Response to a Successful Request

```
requestID=1019827520348290570293
merchantReferenceCode=482046C3A7E94F5BD1FE3C66C
decision=ACCEPT
reasonCode=100
ccAuthReversalReply_amount=49.95
purchaseTotals_currency=USD
ccAuthReversalReply_reasonCode=100
ccAuthReversalReply_reconciliationID=1094820975023470
```

Sale {#payments-processing-basic-sale-intro}
============================================

This section provides the information you need in order to process a sale transaction.  
A sale combines an authorization and a capture into a single transaction.

Endpoint {#payments-processing-basic-sale-intro_d8e161}
-------------------------------------------------------

Set the ccAuthService_run field to `true`, and the ccCaptureService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for a Sale {#payments-processing-basic-sale-reqfields}
======================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_cardType
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_commerceIndicator
:

ccAuthService_run
:
Set the value to `true`.

ccCaptureService_run
:
Set the value to `true`.

merchantID
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Sale {#payments-processing-basic-sale-ex-so-nvp}
======================================================================

Request

```
ccAuthService_run=true
ccCaptureService_run=true
merchantID=Napa Valley Vacations
merchantReferenceCode=482046C3A7E94F5
billTo_firstName=John
billTo_lastName=Doe
billTo_street1=1295 Charleston Rd.
billTo_city=Mountain View
billTo_state=CA
billTo_postalCode=94043
billTo_country=US
billTo_phoneNumber=650-965-6000
billTo_email=jdoe@example.com
item_0_unitPrice=49.95
item_0_quantity=1
purchaseTotals_currency=USD
card_expirationMonth=12
card_expirationYear=2031
card_accountNumber=4111111111111111
card_cardType=001
```

Response to a Successful Request

```
requestID=0305782650000167905080
decision=ACCEPT
reasonCode=100
merchantReferenceCode=482046C3A7E94F5
purchaseTotals_currency=USD
ccAuthReply_reconciliationID=ABCDE12345FGHIJ67890
ccAuthReply_cardCategory=F^
ccAuthReply_cardGroup=0
ccAuthReply_reasonCode=100
ccAuthReply_amount=49.95
ccAuthReply_accountBalance=50.05
ccAuthReply_authorizationCode=123456
ccAuthReply_avsCode=Y
ccAuthReply_avsCodeRaw=YYY
ccAuthReply_processorResponse=A
ccAuthReply_paymentNetworkTransactionID=3312345
ccCaptureReply_amount=49.95
ccCaptureReply_reasonCode=100
ccCaptureReply_reconciliationID=1094820975023470
```

Sale with Payment Network Tokens {#pnt-sale-intro}
==================================================

This section shows you how to successfully process a sale with payment network tokens.

> Due to mandates from the Reserve Bank of India, merchants based in India cannot store personal account numbers (PAN). Use network tokens instead. For more information on network tokens, see the Network Tokenization section of the [` Token Management Service ` Guide.](https://developer.cybersource.com/docs.md#TokenManagementService "")

Endpoint {#pnt-sale-intro_d12e16}
---------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Sales with Payment Network Tokens {#pnt-sale-req-fields}
============================================================================

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_street1
:

ccAuthService_networkTokenCryptogram
:

ccCaptureService_run
:
Set the value to `true`.

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

token_expirationMonth
:

token_expirationYear
:

Optional Fields for Sales with Payment Network Tokens {#pnt-sale-optional-fields}
=================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:
Required only for transactions in the U.S. and Canada.

billTo_state
:
Required only for transactions in the U.S. and Canada.

billTo_street1
:

card_accountNumber
:
Set to the token value that you received from the token service provider.

card_cardType
:
It is strongly recommended that you send the card type even if it is optional for your processor. Omitting the card type can cause the transaction to be processed with the wrong card type.

card_expirationMonth
:
Set to the token expiration month that you received from the token service provider.

card_expirationYear
:
Set to the token expiration year that you received from the token service provider.

ccAuthService_cavv
:
For 3-D Secure in-app transactions for Visa, set to the 3-D Secure cryptogram. Otherwise, set to the network token cryptogram.

ccAuthService_commerceIndicator
:

ccAuthService_networkTokenCryptogram
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount or item_#_unitPrice
:

paymentNetworkToken_transactionType
:

paymentNetworkToken_requestorID

ucaf_authenticationData
:
For Mastercard requests, set this field to the Identity Check cryptogram.

ucaf_collectionIndicator
:
For Mastercard requests, set the value to `2`.

Simple Order API Example: Authorizations with Payment Network Tokens {#pnt-sale-ex-so}
======================================================================================

Request

```keyword
&lt;requestMessage&gt;
    &lt;merchantID&gt;Foster_City_Flowers&lt;/merchantID&gt;
    &lt;merchantReferenceCode&gt;12345678&lt;/merchantReferenceCode&gt;
    &lt;billTo&gt;
        &lt;firstName&gt;Jane&lt;/firstName&gt;
        &lt;lastName&gt;Smith&lt;/lastName&gt;
        &lt;street1&gt;100 Main Street&lt;/street1&gt;
        &lt;street2&gt;Suite 1234&lt;/street2&gt;
        &lt;city&gt;Foster City&lt;/city&gt;
        &lt;state&gt;CA&lt;/state&gt;
        &lt;postalCode&gt;94404&lt;/postalCode&gt;
        &lt;country&gt;US&lt;/country&gt;
        &lt;email&gt;test@cybs.com&lt;/email&gt;
    &lt;/billTo&gt;
    &lt;purchaseTotals&gt;
        &lt;currency&gt;USD&lt;/currency&gt;
        &lt;grandTotalAmount&gt;16.00&lt;/grandTotalAmount&gt;
    &lt;/purchaseTotals&gt;
    &lt;card&gt;
        &lt;accountNumber&gt;4111111111111111&lt;/accountNumber&gt;
        &lt;expirationMonth&gt;12&lt;/expirationMonth&gt;
        &lt;expirationYear&gt;2031&lt;/expirationYear&gt;
    &lt;/card&gt;
    &lt;ccAuthService run="true"&gt;
        &lt;networkTokenCryptogram&gt;qE5juRwDzAUFBAkEHuWW9PiBkWv=&lt;/networkTokenCryptogram&gt;
    &lt;/ccAuthService&gt;
    &lt;paymentNetworkToken&gt;
        &lt;transactionType&gt;1&lt;/transactionType&gt;
    &lt;/paymentNetworkToken&gt;
&lt;/requestMessage&gt;
```

Successful Response

```
&lt;c:replyMessage&gt;
    &lt;c:merchantReferenceCode&gt;Postman-1684858432&lt;/c:merchantReferenceCode&gt;
    &lt;c:requestID&gt;6848584316126969103007&lt;/c:requestID&gt;
    &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:purchaseTotals&gt;
        &lt;c:currency&gt;USD&lt;/c:currency&gt;
    &lt;/c:purchaseTotals&gt;
    &lt;c:ccAuthReply&gt;
        &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
        &lt;c:amount&gt;16.00&lt;/c:amount&gt;
        &lt;c:authorizationCode&gt;888888&lt;/c:authorizationCode&gt;
        &lt;c:avsCode&gt;X&lt;/c:avsCode&gt;
        &lt;c:avsCodeRaw&gt;I1&lt;/c:avsCodeRaw&gt;
        &lt;c:authorizedDateTime&gt;2023-05-23T16:13:51Z&lt;/c:authorizedDateTime&gt;
        &lt;c:processorResponse&gt;100&lt;/c:processorResponse&gt;
        &lt;c:reconciliationID&gt;78849228NHPFQCKD&lt;/c:reconciliationID&gt;
        &lt;c:paymentNetworkTransactionID&gt;123456789619999&lt;/c:paymentNetworkTransactionID&gt;
     &lt;/c:ccAuthReply&gt;
     &lt;c:card&gt;
         &lt;c:cardType&gt;001&lt;/c:cardType&gt;
     &lt;/c:card&gt;
&lt;/c:replyMessage&gt;
```

Capture {#payments-processing-basic-capture-intro}
==================================================

This section describes how to capture an authorized transaction.

Endpoint {#payments-processing-basic-capture-intro_d8e88}
---------------------------------------------------------

Set the ccCaptureService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Capturing an Authorization {#payments-processing-basic-capture-required-fields}
===================================================================================================

ccCaptureService_authRequestID
:

ccCaptureService_run
:

merchantID
:

merchantReferenceCode
:
Set the value to `merchant_ref_number` value used in corresponding authorization request.

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Capturing an Authorization {#payments-processing-basic-capture-ex-so-nvp}
===============================================================================================

Request

```
ccCaptureService_authRequestID=6629978499572480812782
ccCaptureService_run=true
merchantID=npr_paymentech
merchantReferenceCode=TC42703-1
purchaseTotals_grandTotalAmount=100.00
```

Response to a Successful Request

```
ccCaptureReply_amount=100.00
ccCaptureReply_requestDateTime=2022-09-12T173947Z
decision=ACCEPT
merchantReferenceCode=TC42703-1
purchaseTotals_currency=USD
requestID=6630043878211258349460
```

Multiple Partial Capture {#payments-processing-capture-multi-intro}
===================================================================

This section shows you how to process multiple partial captures for an authorization.
This feature enables you to request multiple partial captures for one authorization. A multiple partial capture allows you to incrementally settle authorizations over time. Ensure that the total amount of all the captures does not exceed the authorized amount.

Prerequisite
------------

Contact customer support to have your account enabled for this feature.

Endpoint {#payments-processing-capture-multi-intro_d8e88}
---------------------------------------------------------

Set the ccCaptureService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing Multiple Partial Captures {#payments-processing-capture-multi-reqfields}
=======================================================================================================

ccCaptureService_authRequestID
:

ccCaptureService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:
Set the value to `merchantReferenceCode` value used in corresponding authorization request.

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:
{#payments-processing-capture-multi-reqfields_dl_yjr_glf_tgc}

Simple Order Example: Processing Multiple Partial Captures {#payments-processing-multi-capture-ex-so}
=====================================================================================================

Request

```
&lt;requestMessage
	xmlns="urn:schemas-cybersource-com:transaction-data-1.225"&gt;
	&lt;merchantID&gt;MERCHANT_ID&lt;/merchantID&gt;
	&lt;merchantReferenceCode&gt;TC_FE_MD-1&lt;/merchantReferenceCode&gt;
	&lt;purchaseTotals&gt;
		&lt;currency&gt;SAR&lt;/currency&gt;
		&lt;grandTotalAmount&gt;10&lt;/grandTotalAmount&gt;
	&lt;/purchaseTotals&gt;
	&lt;ccCaptureService run="true"&gt;
		&lt;authRequestID&gt;7429184781587007513700&lt;/authRequestID&gt;
		&lt;sequence&gt;1&lt;/sequence&gt;
		&lt;totalCount&gt;3&lt;/totalCount&gt;
	&lt;/ccCaptureService&gt;
&lt;/requestMessage&gt;
```

Response to a Successful Request

```
&lt;c:replyMessage
	xmlns:c="urn:schemas-cybersource-com:transaction-data-1.217"&gt;
	&lt;c:merchantReferenceCode&gt;TC_FE_MD-1&lt;/c:merchantReferenceCode&gt;
	&lt;c:requestID&gt;7067731204117000415775&lt;/c:requestID&gt;
	&lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
	&lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
	&lt;c:purchaseTotals&gt;
		&lt;c:currency&gt;SAR&lt;/c:currency&gt;
	&lt;/c:purchaseTotals&gt;
	&lt;c:ccCaptureReply&gt;
		&lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
		&lt;c:requestDateTime&gt;2024-02-01T07:38:40Z&lt;/c:requestDateTime&gt;
		&lt;c:amount&gt;100.00&lt;/c:amount&gt;
		&lt;c:reconciliationID&gt;7067730865997000315775&lt;/c:reconciliationID&gt;
		&lt;c:authorizationCode&gt;830SPG&lt;/c:authorizationCode&gt;
		&lt;c:processorResponse&gt;00&lt;/c:processorResponse&gt;
	&lt;/c:ccCaptureReply&gt;
&lt;/c:replyMessage&gt;
```

Follow-On Credit {#payments-processing-basic-refund-intro}
==========================================================

This section provides the information you need in order to process a follow-on credit, which is linked to a capture or sale. You must request a follow-on credit within 180 days of the authorization or sale.
When your account is enabled for credit authorizations, also known as purchase return authorizations, `Cybersource` authenticates the card and customer during a follow-on refund or stand-alone credit request. Every credit request is automatically authorized.  
Credit authorization results are returned in these response fields:

* ccCreditReply_authorizationCode
* ccCreditReply_paymentNetworkTransactionID
* ccCreditReply_processorResponse
  {#payments-processing-basic-refund-intro_d18e25}  
  When you request a void for a refund or credit before settlement, the refund or credit is voided. If your account is enabled for credit authorizations, the credit authorization is also reversed.

Endpoint {#payments-processing-basic-refund-intro_d8e137}
---------------------------------------------------------

Set the ccCreditService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing a Follow-On Credit {#payments-processing-basic-refund-required-fields}
=====================================================================================================

ccCreditService_captureRequestID
:

ccCreditService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:
Set the value merchantReferenceCode value used in corresponding capture or sale request.

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Processing a Follow-On Credit {#payments-processing-basic-refund-ex-so-nvp}
=================================================================================================

Request

```
&lt;requestMessage xmlns="urn:schemas-cybersource-com:transaction-data-1.86"&gt;
  &lt;merchantID&gt;merchantID&lt;/merchantID&gt;
  &lt;merchantReferenceCode&gt;merchantRefCode&lt;/merchantReferenceCode&gt;
  &lt;purchaseTotals&gt;
    &lt;currency&gt;USD&lt;/currency&gt;
    &lt;grandTotalAmount&gt;1.01&lt;/grandTotalAmount&gt;
  &lt;/purchaseTotals&gt;
  &lt;ccCreditService run="true"&gt;
    &lt;captureRequestID&gt;captureRequestID&lt;/captureRequestID&gt;
  &lt;/ccCreditService&gt;
&lt;/requestMessage&gt;
```

Response to a Successful Request

```
&lt;c:replyMessage xmlns:c="urn:schemas-cybersource-com:transaction-data-1.86"&gt;
  &lt;c:merchantReferenceCode&gt;Postman-1666641056&lt;/c:merchantReferenceCode&gt;
  &lt;c:requestID&gt;6666410568976150003010&lt;/c:requestID&gt;
  &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
  &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
  &lt;c:purchaseTotals&gt;
    &lt;c:currency&gt;USD&lt;/c:currency&gt;
  &lt;/c:purchaseTotals&gt;
  &lt;c:ccCreditReply&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:requestDateTime&gt;2022-10-24T19:50:57Z&lt;/c:requestDateTime&gt;
    &lt;c:amount&gt;1.01&lt;/c:amount&gt;
    &lt;c:reconciliationID&gt;6691571329CM5P99&lt;/c:reconciliationID&gt;
    &lt;c:authorizationCode&gt;831111&lt;/c:authorizationCode&gt;
    &lt;c:processorResponse&gt;00&lt;/c:processorResponse&gt;
    &lt;c:paymentNetworkTransactionID&gt;222222222222222&lt;/c:paymentNetwork&gt;
  &lt;/c:ccCreditReply&gt;
&lt;/c:replyMessage&gt;
```

Stand-Alone Credit {#payments-processing-basic-credit-intro}
============================================================

This section shows you how to process a stand-alone credit, which is not linked to a capture or sale. There is no time limit for requesting a stand-alone credit.
When your account is enabled for credit authorizations, also known as purchase return authorizations, `Cybersource` authenticates the card and customer during a follow-on refund or stand-alone credit request. Every credit request is automatically authorized.  
Credit authorization results are returned in these response fields:

* ccCreditReply_authorizationCode
* ccCreditReply_paymentNetworkTransactionID
* ccCreditReply_processorResponse
  {#payments-processing-basic-credit-intro_d18e25}  
  When you request a void for a refund or credit before settlement, the refund or credit is voided. If your account is enabled for credit authorizations, the credit authorization is also reversed.

Endpoint {#payments-processing-basic-credit-intro_d8e112}
---------------------------------------------------------

Set the ccCreditService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing a Stand-Alone Credit {#payments-processing-basic-credit-required-fields}
=======================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccCreditService
:
Set the value to `true`. For example `ccCreditService run="true"`.

merchantID
:

merchantReferenceCode
:
Set to merchantReferenceCode value used in corresponding capture request.

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Processing a Stand-Alone Credit {#payments-processing-basic-credit-ex-so}
===============================================================================================

Request

```keyword
&lt;requestMessage&gt;
    &lt;billTo&gt;
        &lt;firstName&gt;John&lt;/firstName&gt;
        &lt;lastName&gt;Doe&lt;/lastName&gt;
        &lt;street1&gt;1295 Charleston Road&lt;/street1&gt;
        &lt;city&gt;Mountain View&lt;/city&gt;
        &lt;state&gt;CA&lt;/state&gt;
        &lt;postalCode&gt;94043&lt;/postalCode&gt;
        &lt;country&gt;US&lt;/country&gt;
        &lt;email&gt;test@cybs.com&lt;/email&gt;
    &lt;/billTo&gt;
    &lt;card&gt;
        &lt;accountNumber&gt;CARD_NUMBER&lt;/accountNumber&gt;
        &lt;expirationMonth&gt;12&lt;/expirationMonth&gt;
        &lt;expirationYear&gt;2026&lt;/expirationYear&gt;
    &lt;/card&gt;
    &lt;merchantID&gt;lrsebctest&lt;/merchantID&gt;
    &lt;merchantReferenceCode&gt;Postman-1666381004&lt;/merchantReferenceCode&gt;
    &lt;purchaseTotals&gt;
        &lt;currency&gt;USD&lt;/currency&gt;
        &lt;grandTotalAmount&gt;1.01&lt;/grandTotalAmount&gt;
    &lt;/purchaseTotals&gt;
    &lt;ccCreditService run="true"/&gt;
&lt;/requestMessage&gt;
```

Response to a Successful Request

```
&lt;c:replyMessge&gt;
    &lt;c:merchantReferenceCode&gt;Postman-1666374834&lt;/c:merchantReferenceCode&gt;
    &lt;c:requestID&gt;6663748348516429203007&lt;/c:requestID&gt;
    &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:purchaseTotals&gt;
        &lt;c:currency&gt;USD&lt;/c:currency&gt;
    &lt;/c:purchaseTotals&gt;
    &lt;c:ccAuthReply&gt;
        &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
        &lt;c:amount&gt;1.01&lt;/c:amount&gt;
        &lt;c:authorizationCode&gt;888888&lt;/c:authorizationCode&gt;
        &lt;c:avsCode&gt;X&lt;/c:avsCode&gt;
        &lt;c:avsCodeRaw&gt;I1&lt;/c:avsCodeRaw&gt;
        &lt;c:authorizedDateTime&gt;2022-10-21T17:53:54Z&lt;/c:authorizedDateTime&gt;
        &lt;c:processorResponse&gt;100&lt;/c:processorResponse&gt;
        &lt;c:reconciliationID&gt;66737280B9CGUCCP&lt;/c:reconciliationID&gt;
        &lt;c:paymentNetworkTransactionID&gt;123456789619999&lt;/c:paymentNetworkTransactionID&gt;
    &lt;/c:ccAuthReply&gt;
    &lt;c:card&gt;
        &lt;c:cardType&gt;001&lt;/c:cardType&gt;
    &lt;/c:card&gt;
&lt;/c:replyMessge&gt;
```

Void a Payment {#payments-processing-sale-void-intro}
=====================================================

This section describes how to void a payment that was submitted but not yet processed by the processor. A payment is also known as a sale, which is an authorization and capture in one API request. Include the payment ID in the void request endpoint to cancel the payment.

Endpoint {#payments-processing-sale-void-intro_d8e241}
------------------------------------------------------

Required Fields for Voiding a Payment {#payments-processing-sale-void-required-fields}
======================================================================================

merchantID
:

merchantReferenceCode
:

voidService_voidRequestID
:
Set this field to the request ID that was included in the sale response message.

voidService_run
:
Set the value to `true`.

Simple Order Example: Void a Payment {#payments-processing-sale-void-ex-so}
===========================================================================

Request

```
&lt;requestMessage&gt;
    &lt;merchantID&gt;Napa Valley Vacations&lt;/merchantID&gt;
    &lt;merchantReferenceCode&gt;482046C3A7E94F5&lt;/merchantReferenceCode&gt;
    &lt;voidService run="true"&gt;
        &lt;voidRequestID&gt;098123456789&lt;/voidRequestID&gt;
    &lt;/voidService&gt;
&lt;/requestMessage&gt;
```

Response to a Successful Request

```
&lt;c:replyMessage&gt;
    &lt;c:requestID&gt;0305782650000167905080&lt;/c:requestID&gt;
    &lt;c:decision&gt;ACCEPT&lt;/c:decision&gt;
    &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
    &lt;c:merchantReferenceCode&gt;482046C3A7E94F5&lt;/c:merchantReferenceCode&gt;
    &lt;c:voidReply&gt;
        &lt;c:reconciliationID&gt;ABCDE12345FGHIJ67890&lt;/c:reconciliationID&gt;
        &lt;c:reasonCode&gt;100&lt;/c:reasonCode&gt;
        &lt;c:amount&gt;100.00&lt;/c:amount&gt;
        &lt;c:currency&gt;USD&lt;/c:currency&gt;
    &lt;/c:voidReply&gt;
&lt;/c:replyMessage&gt;
```

Void for a Capture or Credit {#payments-processing-basic-void-intro}
====================================================================

This section describes how to void a capture or credit that was submitted but not yet processed by the processor.

Endpoints {#payments-processing-basic-void-intro_d8e191}
--------------------------------------------------------

**Void a Capture**  
**Void a Credit**  
Set the VoidService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Voiding a Capture or Credit {#payments-processing-basic-void-required-fields}
=================================================================================================

merchantID
:

merchantReferenceCode
:

voidService_voidRequestID
:
Set the value to the request ID included in the authorization response message.

voidService_run
:
Set the value to `true`.

Simple Order API Example: Voiding a Capture or Credit {#payments-processing-basic-void-ex-so-nvp}
=================================================================================================

Request

```
merchantID=Napa Valley Vacations
merchantReferenceCode=482046C3A7E94F5
voidService_run
voidService_voidRequestID=6522033834410167772169
```

Response to a Successful Request

```
requestID=0305782650000167905080
decision=ACCEPT
reasonCode=100
merchantReferenceCode=482046C3A7E94F5
voidReply_reconciliationID=ABCDE12345FGHIJ67890
voidReply_reasonCode=100
voidReply_amount=49.95
voidReply_currency=USD
```

Debit and Prepaid Card Processing {#payments-debit-prepaid-process-intro}
=========================================================================

This section shows you how to process authorizations that use a debit or prepaid card.

Processing Debit and Prepaid Authorizations {#payments-debit-prepaid-auth-intro}
================================================================================

This section shows you how to process an authorization using debit and prepaid cards using credit card services.

Endpoint {#payments-debit-prepaid-auth-intro_d8e16}
---------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing Debit and Prepaid Authorizations {#payments-debit-prepaid-auth-required}
=======================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency

purchaseTotals_grandTotalAmount
:

Optional Field for Processing Debit and Prepaid Authorizations {#payments-debit-prepaid-auth-optional}
======================================================================================================

You can use this optional field to include additional information when processing debit and prepaid authorizations.

linkToRequest
:
Set this field to the request ID that was returned in the response message from the original authorization request.

Simple Order Example: Processing Debit and Prepaid Authorizations {#payments-debit-prepaid-auth-ex-so}
======================================================================================================

Request

```keyword
billTo_city=Foster City
billTo_country=US
billTo_email=null@cybersource.com
billTo_firstname=John
billTo_lastname=Smith
billTo_postalCode=40500
billTo_state=CA
billTo_street1=901 Metro Center Blvd
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2031
ccAuthService_run=true
merchant_id=pa_ctv_sg101
merchantReferenceCode=rts_6595481893301034778276
purchaseTotals_currency=usd
purchaseTotals_grandTotalAmount=100
```

Response to a Successful Request

```
additionalData=ABC
ccAuthReply_amount=100.00
ccAuthReply_avsCode=Y
ccAuthReply_authorizationCode=831000
ccAuthReply_processorResponse=00
ccAuthReply_authorizedDateTime=2022-08-30T165039Z
ccAuthReply_avsCodeRaw=Y
ccAuthReply_cavvResponseCode=2
ccAuthReply_cavvResponseCodeRaw=2
ccAuthReply_merchantAdviceCode=01
ccAuthReply_merchantAdviceCodeRaw=M001
ccAuthReply_paymentNetworkTransactionID=016153570198200
ccAuthReply_reconciliationReferenceNumber=224216876457
apAuthReply_reconciliationID=6618782389070178232890
card_cardType=001
payerAuthEnrollReply_cardTypeName=VISA
purchaseTotals_currency=usd
merchantReferenceCode=rts_6595481893301034778276
receiptNumber=876457
requestID=6618782389070178232890
```

Enabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-part-auth-intro}
===========================================================================================

Partial authorizations and balance responses are special features that are available for debit cards and prepaid cards. This section shows you how to enable partial authorizations for a specific transaction.  
You must use version 1.52 or later of the XML schema to implement partial authorizations or balance responses.

Field Specific to this Use Case
-------------------------------

Include this field in addition to the fields required for a standard authorization request:

* Indicate that this request is a partial authorization.  
  Set the `ccAuthService_partialAuthIndicator` to `true`.

Endpoint {#payments-debit-prepaid-part-auth-intro_d8e16}
--------------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Enabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-part-auth-required}
==================================================================================================================

Use these required fields for enabling debit and prepaid partial authorizations.

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_partialAuthIndicator
:
Set the value to `true`.

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency

purchaseTotals_grandTotalAmount
:

Optional Field for Enabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-part-auth-optional}
=================================================================================================================

You can use these optional fields to include additional information when enabling debit and prepaid partial authorizations.

linkToRequest
:
Set this field to the request ID that was returned in the response message from the original authorization request.

Simple Order Example: Enabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-part-auth-ex-so}
=================================================================================================================

Request

```keyword
billTo_street1=201 S. Division St
billTo_city=Ann Arbor
billTo_country=US
billTo_state=MI
billTo_postalCode=48104-2201
billTo_email=test@cybs.com
billTo_firstname=John
billTo_lastname=Deo
card_expirationMonth=12
card_expirationYear=2031
card_accountNumber=5555555555554444
ccAuthService_partialAuthIndicator=true
merchant_id=pa_ctv_sg101
merchantReferenceCode=TC50171_3
purchaseTotals_currency=usd
purchaseTotals_grandTotalAmount=1000.00
```

Response to a Successful Request

```
apCaptureService_authRequestID=6618807769750178232890
apAuthReply_reconciliationID=6618807769750178232890
card_cardType=002
ccAuthReply_amount=1000.00
ccAuthReply_avsCode=Y
ccAuthReply_authorizationCode=831000
ccAuthReply_authorizedDateTime=2022-08-30T173257Z
ccAuthReply_avsCodeRaw=Y
ccAuthReply_cavvResponseCode=2
ccAuthReply_cavvResponseCodeRaw=2
ccAuthReply_merchantAdviceCode=01
ccAuthReply_merchantAdviceCodeRaw=M001
ccAuthReply_processorResponse=00
ccAuthReply_reconciliationReferenceNumber=224217876503
ccCreditReply_paymentNetworkTransactionID=MCC9689130830
merchantReferenceCode=TC50171_3
payerAuthEnrollReply_cardTypeName=MASTERCARD
purchaseTotals_currency=usd
receiptNumber=876503
requestID=6618807769750178232890
```

Disabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-disable-part-auth-intro}
====================================================================================================

This topic shows you how to successfully disable partial authorizations for specific transactions.

Field Specific to this Use Case {#payments-debit-prepaid-disable-part-auth-intro_section_brd_jvn_sxb}
-----------------------------------------------------------------------------------------------------

Include this field in addition to the fields required for a standard authorization request:

* Indicate that this request is not a partial authorization.  
  Set the `ccAuthService_partialAuthIndicator` to `false`.
  {#payments-debit-prepaid-disable-part-auth-intro_ul_crd_jvn_sxb}

Endpoint {#payments-debit-prepaid-disable-part-auth-intro_d8e16}
----------------------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Field for Disabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-disable-part-auth-required}
==========================================================================================================================

Use these required fields for disabling debit and prepaid partial authorizations.

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_partialAuthIndicator
:
Set the value to `false`.

ccAuthService_run
:
Set the value to `true`.

merchantID
:

merchantReferenceCode
:

purchaseTotals_currency

purchaseTotals_grandTotalAmount
:

Optional Field for Disabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-disable-part-auth-optional}
==========================================================================================================================

You can use this optional field to include additional information when disabling debit and prepaid partial authorizations.

linkToRequest
:
Set this field to the request ID that was returned in the response message from the original authorization request.

Simple Order Example: Disabling Debit and Prepaid Partial Authorizations {#payments-debit-prepaid-disable-part-auth-ex-so}
==========================================================================================================================

Request

```keyword
billTo_street1=201 S. Division St
billTo_city=Ann Arbor
billTo_country=US
billTo_state=MI
billTo_postalCode=48104-2201
billTo_email=test@cybs.com
billTo_firstname=John
billTo_lastname=Deo
card_expirationMonth=12
card_expirationYear=2031
card_accountNumber=5555555555554444
ccAuthService_partialAuthIndicator=false
merchant_id=pa_ctv_sg101
merchantReferenceCode=TC50171_3
purchaseTotals_currency=usd
purchaseTotals_grandTotalAmount=1000.00
```

Response to a Successful Request

```
apCaptureService_authRequestID=6643889552520668668655
apAuthReply_reconciliationID=6643889552520668668655
card_cardType=002
ccAuthReply_amount=1000.00
ccAuthReply_avsCode=Y
ccAuthReply_authorizationCode=831000
ccAuthReply_authorizedDateTime=2022-09-28T173257Z
ccAuthReply_avsCodeRaw=Y
ccAuthReply_cavvResponseCode=2
ccAuthReply_cavvResponseCodeRaw=2
ccAuthReply_merchantAdviceCode=01
ccAuthReply_merchantAdviceCodeRaw=M001
ccAuthReply_processorResponse=00
ccAuthReply_reconciliationReferenceNumber=227118876340
ccCreditReply_paymentNetworkTransactionID=MCC8605090928
merchantReferenceCode=TC50171_3
payerAuthEnrollReply_cardTypeName=MASTERCARD
purchaseTotals_currency=usd
receiptNumber=876340
requestID=6618807769750178232890
```

Payer Authentication Processing {#payments-processing-pa-process-intro}
=======================================================================

This section shows you how to process authorizations with these payer authentication methods:

* **Mastercard**: Identity Check
* **Visa**: Visa Secure
  {#payments-processing-pa-process-intro_ul_dqz_xll_5xb}

Providing Payer Authentication Information for Authorization {#payments-processing-pa-eci}
==========================================================================================

The values that are returned from payer authentication must be provided when seeking authorization for the transaction. Authentication information that is not included when considering authorization may cause the transaction to be refused or downgraded and prevent the normal liability shift from occurring.  
The level of security in payer authentication is indicated by the two-digit e-commerce indicator (ECI) that is assigned to the transaction. These values have text equivalents that are assigned to the ccAuthService_commerceIndicator field. Visa card brands use `05`, `06`, and `07` digit values to express the authentication level for a `3-D Secure` transaction.

| ECI Value |                  Meaning                   | Visa                 |
|:----------|--------------------------------------------|:---------------------|
| `05`      | Authenticated                              | vbv                  |
| `06`      | Attempted authentication with a cryptogram | vbv_attempted        |
| `07`      | Internet, not authenticated                | vbv_failure/internet |
[Text Values for ECI Values]

Mastercard and Maestro cards use 00, 01, 02, 06, and 07 digit values to indicate the authentication level of the transaction.

| ECI Value | Meaning                                                           | Mastercard/Maestro |
|:----------|:------------------------------------------------------------------|:-------------------|
| `00`      | Internet, not authenticated                                       | spa/internet       |
| `01`      | Attempted authentication                                          | spa                |
| `02`      | Authenticated                                                     | spa                |
| `06`      | Exemption from authentication or network token without 3‑D Secure | spa                |
| `07`      | Authenticated merchant-initiated transaction                      | spa                |
[Mastercard/Maestro Text Values for ECI Values]

The payer authentication response contains other information that needs to be passed on for successful authorization. Be sure to include these fields when requesting a separate authorization:

* ccAuthService_directoryServerTransactionID (Mastercard, Maestro)
* ccAuthService_eciRaw
* ccAuthService_paresStatus
* ccAuthService_paSpecificationVersion
* payerAuthEnrollReply_ucafAuthenticationData (Mastercard/Maestro only)
* payerAuthValidateReply_ucafCollectionIndicator(Mastercard/Maestro only)
* ccAuthService_cavv
* ccAuthService_xid

Mastercard Identity Check {#payments-processing-pa-mc-intro}
============================================================

Mastercard Identity Check is the authentication service in the Mastercard card network that uses the 3-D Secure protocol in online transactions to authenticate customers at checkout.  
Mastercard Identity Check generates a unique, 32-character transaction token, called the account authentication value (AAV) each time a Mastercard Identity Check-enabled account holder makes an online purchase. The AAV binds the account holder to a specific transaction. Mastercard Identity Check transactions use the universal cardholder authentication field (UCAF) as a standard to collect and pass AAV data.  
Before implementing payer authentication for Mastercard Identity Check, contact customer support to have your account configured for this feature.

Fields Specific to the Mastercard Identity Check Use Case
---------------------------------------------------------

These API fields are required specifically for this use case.

:
Set this field to the transaction ID returned by Mastercard Identity Check during the authentication process.

:
Set this field to the Mastercard Identity Check version returned by Mastercard Identity Check during the authentication process.

ucaf_collectionIndicator
:
Set to the last digit of the raw ECI value returned from authentication. For example, if ECI=02, this value should be 2.

:
Set this field to one of these values:

    * `spa`: Successful authentication (3-D Secure value of `02`).
    * `spa`: Authentication was attempted (3-D Secure value of `01`).
    * `spa` or `internet`: Authentication failed or was not attempted (3-D Secure value of `00`)
    {#payments-processing-pa-mc-intro_ul_a2g_5lz_3xb}

Endpoint {#payments-processing-pa-mc-intro_d8e16}
-------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing an Authorization Using Mastercard Identity Check {#payments-processing-pa-mc-reqfields}
======================================================================================================================

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_run
:
Set the value to `true`.

ccAuthService_cavv
:

ccAuthService_commerceIndicator
:
Set this field to one of these values:

    * `spa`: Successful authentication (3-D Secure value of `02`).
    * `spa`: Authentication was attempted (3-D Secure value of `01`).
    * `spa` or `internet`: Authentication failed or was not attempted (3-D Secure value of `00`).
    {#payments-processing-pa-mc-reqfields_ul_a2g_5lz_3xb}

ccAuthService_directoryServerTransactionID
:

ccAuthService_paSpecificationVersion
:

mercahnt_id
:

merchant_referenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

ucaf_collectionIndicator
:
Set to the last digit of the raw ECI value returned from authentication. For example, if ECI=02, this value should be 2.
{#payments-processing-pa-mc-reqfields_dl_pcx_hzz_3xb}

Simple Order Example: Processing an Authorization Using Mastercard Identity Check {#payments-processing-pa-mc-ex-so}
====================================================================================================================

Request

```keyword
billTo_city=Sao Paulo
billTo_country=BR
billTo_email=null@cybersource.com
billTo_firstname=Julia
billTo_lastname=Fernandez
billTo_postalCode=01310-000
billTo_state=SP
billTo_street1=R. Augusta
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2023
ccAuthService_run=true
ccAuthService_cavv=ABCDEFabcdefABCDEFabcdef0987654321234567
ccAuthService_commerceIndicator=spa
ccAuthService_paSpecificationVersion=1
merchant_id=MID23
merchant_referenceCode=Merchant_REF
ucaf_collectionIndicator=1
purchaseTotals_currency=mxn
purchaseTotals_grandTotalAmount=100
```

Response to a Successful Request

```
merchantReferenceCode=Merchant_REF
request_id=6461515866500167772420
decision=ACCEPT
reasonCode=100
purchaseTotals_currency=mxn
ccAuthReply_cardCategory=F
ccAuthService_reconciliationID=ZUDCXJO8KZRFXQJJ
ccAuthReply_reasonCode=100
ccAuthReply_amount=100.00
ccAuthReply_avsCode=5
ccAuthReply_authorizationCode=570110
ccAuthReply_processorResponse=1
ccAuthReply_authorizedDateTime=2022-03-01T161947Z
ccAuthReply_paymentNetworkTransactionID=111222
```

Visa Secure {#payments-processing-pa-visa-intro}
================================================

Visa Secure is the authentication service in the Visa card network that uses the 3-D Secure protocol to authenticate customers at checkout. This authentication is a two-step process. First, the cardholder is authenticated by 3-D Secure. Then, the transaction is authorized based on the 3-D Secure evaluation. This section explains how to authorize a card payment based on the 3-D Secure evaluation.  
Before implementing Visa Secure, contact customer support to have your account configured for this feature.

Fields Specific to the Visa Secure Use Case
-------------------------------------------

These API fields are required specifically for this use case.

ccAuthService_commerceIndicator
:
Set the value to `vbv` for a successful authentication (3-D Secure value of `05`), `vbv_attempted` if authentication was attempted but did not succeed (3-D Secure value of `06`), or `vbv_failure` if authentication failed (3-D Secure value of `07`).

ccAuthService_cavv
:
Required when payer authentication is successful.

Endpoint {#payments-processing-pa-visa-intro_d8e16}
---------------------------------------------------

Set the ccAuthService_run field to `true`.  
Send the request to `https://ics2ws.ic3.com/commerce/1.x/transactionProcessor`.

Required Fields for Processing an Authorization Using Visa Secure {#payments-processing-pa-visa-reqfields}
==========================================================================================================

Required Fields
---------------

billTo_city
:

billTo_country
:

billTo_email
:

billTo_firstName
:

billTo_lastName
:

billTo_postalCode
:

billTo_state
:

billTo_street1
:

card_accountNumber
:

card_expirationMonth
:

card_expirationYear
:

ccAuthService_cavv
:
This field is required when payer authentication is successful. Otherwise, this field is optional.

ccAuthService_commerceIndicator
:
Set the value of this field to one of these values:

    * `vbv`: Successful authentication (EMV `3-D Secure` value of `05`).
    * `vbv_attempted`: Authentication was attempted (EMV `3-D Secure` value of `06`).
    * `vbv_failure`: or `internet`: Authentication failed or was not attempted (EMV `3-D Secure` value of `07`)
    {#payments-processing-pa-visa-reqfields_ul_kx5_plz_3xb}

ccAuthService_run
:
Set the value of this field to `true`.

ccAuthService_xid
:

merchant_referenceCode
:

purchaseTotals_currency
:

purchaseTotals_grandTotalAmount
:

Simple Order Example: Validating and Authorizing an Authorization {#payments-processing-pa-visa-ex-so}
======================================================================================================

Request

```
billTo_city=Sao Paulo
billTo_country=BR
billTo_email=julia@email.com
billTo_firstname=Julia
billTo_lastname=Fernandez
billTo_postalCode=01310-000
billTo_state=SP
billTo_street1=R. Augusta
card_accountNumber=41111111XXXXXXXX
card_expirationMonth=12
card_expirationYear=2023
ccAuthService_run=true
ccAuthService_cavv=ABCDEFabcdefABCDEFabcdef0987654321234567
ccAuthService_commerceIndicator=vbv
ccAuthService_xid=MID23
merchant_referenceCode=Merchant_REF
purchaseTotals_currency=mxn
purchaseTotals_grandTotalAmount=100
```

Response to a Successful Request

```
merchantReferenceCode=Merchant_REF
request_id=6461515866500167772420
decision=ACCEPT
reasonCode=100
purchaseTotals_currency=mxn
ccAuthReply_cardCategory=F
ccAuthService_reconciliationID=ZUDCXJO8KZRFXQJJ
ccAuthReply_reasonCode=100
ccAuthReply_amount=100.00
ccAuthReply_avsCode=5
ccAuthReply_authorizationCode=570110
ccAuthReply_processorResponse=1
ccAuthReply_authorizedDateTime=2022-03-01T161947Z
ccAuthReply_paymentNetworkTransactionID=111222
```

