FILTER BY TAG

Network Routing Architecture Update

Barclays
endpoints will be migrated from the current routing model to a new architecture using updated IP subnet ranges.
This enhancement improves the performance, resiliency, and reliability of transaction delivery over the Internet. It will also enable seamless transaction routing across multiple Visa data centers, supporting more consistent and reliable transaction processing.
Barclays
Endpoints and IP Addresses Included
Current Application and endpoints:
CAS/Test
:
apitest.cybersource.com
(current IP address:
66.185.182.49
)
Production
:
api.cybersource.com
(current IP address:
66.185.182.149
)
Potential Impact
Merchants who connect to the REST API endpoints (
apitest.cybersource.com
and
api.cybersource.com
) use a Domain Name System (DNS) should not be affected. DNS records will be updated automatically to use the new routing architecture.
Merchants with networks configured to allowlist IP addresses or who have hardcoded IP addresses will likely be impacted. These merchants should update proxy or firewall settings to include the new Visa IP address ranges.
There are no changes to TLS/SSL certificates or supported ciphers as part of this migration. However,
Barclays
continues to recommend trusting the root TLS certificates for all secure endpoints.
Migration Timeline
CAS/Test
: October 15, 2026
Production
: January 31, 2027
Now Available
This technology is now available in both the test and production environments through these domains:
CAS/Test
:
apitest.visaacceptance.com
Production
:
api.visaacceptance.com
Deploying in the CAS/Test Environment provides a safe environment to test and validate access. When testing is complete, you may migrate production processing.
How to Adopt This Change
To use the new routing architecture, your firewall or your commerce platform provider's firewall must be configured to permit outbound traffic to the Visa cloud.
This large, dynamic IP address space represents a significant change from current access configurations. Therefore, it is critically important to test firewall configurations and confirm that connections are successful before migrating production traffic.
Merchants who require IP address allowlists can use one of these options:
Option 1
: Merchants can add these specific subnet ranges to IP address allowlists:
  • 198.217.128.0/17
  • 198.241.128.0/17
  • 66.185.176.0/20
Option 2
: Merchants can add these generic subnet ranges to IP address allowlists:
  • 198.241.206.0/24
  • 198.241.207.0/24