On This Page
Network Routing Architecture Update
Barclays
endpoints will be migrated from the current routing model to a new
architecture using updated IP subnet ranges.This enhancement improves the performance, resiliency, and reliability of
transaction delivery over the Internet. It will also enable seamless transaction routing
across multiple Visa data centers, supporting more consistent and reliable transaction
processing.
Barclays
Endpoints and IP Addresses IncludedCurrent Application and endpoints:
CAS/Test
: apitest.cybersource.com
(current IP address:
66.185.182.49
)Production
: api.cybersource.com
(current IP address:
66.185.182.149
)Potential Impact
Merchants who connect to the REST API endpoints (
apitest.cybersource.com
and
api.cybersource.com
) use a Domain Name System (DNS) should not be
affected. DNS records will be updated automatically to use the new routing
architecture.Merchants with networks configured to allowlist IP addresses or who have hardcoded IP addresses
will likely be impacted. These merchants should update proxy or firewall settings to
include the new Visa IP address ranges.
There are no changes to TLS/SSL certificates or supported ciphers as part of this
migration. However,
Barclays
continues to recommend trusting the root TLS
certificates for all secure endpoints.Migration Timeline
CAS/Test
: October 15, 2026Production
: January 31, 2027Now Available
This technology is now available in both the test and production environments through
these domains:
CAS/Test
: apitest.visaacceptance.com
Production
: api.visaacceptance.com
Deploying in the CAS/Test Environment provides a safe environment to test and validate access.
When testing is complete, you may migrate production processing.
How to Adopt This Change
To use the new routing architecture, your firewall or your commerce platform provider's
firewall must be configured to permit outbound traffic to the Visa cloud.
This large, dynamic IP address space represents a significant change from current access
configurations. Therefore, it is critically important to test firewall configurations
and confirm that connections are successful before migrating production traffic.
Merchants who require IP address allowlists can use one of these options:
Option 1
: Merchants can add these specific subnet ranges to IP address allowlists:- 198.217.128.0/17
- 198.241.128.0/17
- 66.185.176.0/20
Option 2
: Merchants can add these generic subnet ranges to IP address allowlists:- 198.241.206.0/24
- 198.241.207.0/24