In order to use the CyberSource payment processor, you will need input credentials into Soapbox that will be provided in your CyberSource account.
Important: CyberSource stops accepting Merchant ID and Transaction Security Key sign-in on October 7, 2026. Payments are signed with a P12 certificate from that date. If your site processes payments through CyberSource, see Upgrading your CyberSource connection to certificate authentication and contact Soapbox support. Your Transaction Security Key keeps working until your certificate is installed.
To obtain the proper credentials, follow these instructions from CyberSource for generating a security key for the SOAP Toolkit API. They are included here for your convenience as well:
These steps apply until your certificate is installed. They generate the credential CyberSource retires on October 7, 2026.
- Login to CyberSource
- Click Account Management
- Click Transaction Security Keys
- Click Security Keys for SOAP Toolkit API
- On the Security Keys for the SOAP Toolkit API page, click the Generate Key button
- Note the transaction key displayed in the text box. Per CyberSource:
"Because you will not see the key again after you leave the page, you must immediately copy or download the key to a safe location on your computer" - You may enter this transaction key into your Soapbox site to use CyberSource
How you enter these credentials in Soapbox is determined by the version of the Soapbox administrator your site has: Soapbox Lightning, Soapbox Engage Classic, or Soapbox CMS Classic.
| I have the Soapbox Lightning Administrator with... |
|---|
|
| I have the Soapbox Engage Administrator with... | I have the Soapbox CMS Administrator with... |
|---|---|
|
|
For Soapbox sites using the Soapbox Lightning administrator:
- Login to your Soapbox administrator
- In the right column, click Payment Processor Settings
- For Payment Gateway, select CyberSource
- For Merchant ID, enter the information from your CyberSource account
- For Transaction Security Key, enter the information from your CyberSource account
- For Test Mode, select No, if you are using a CyberSource production account, or Yes, if you are using a CyberSource sandbox account for testing purposes
- Click Save Payment Processor Settings
Note: The Certificate Status row in this panel is read-only. When Soapbox support has installed your certificate, it shows the expiration date, the certificate fingerprint, and when the certificate was last verified. Until then it reads "No certificate installed."
For Soapbox sites using the Soapbox Engage Classic administrator:
- Login to your Soapbox administrator
- In the right column, click Payment Processor Settings
- For Payment Gateway, select CyberSource
- For Merchant ID, enter the information from your CyberSource account
- For Transaction Security Key, enter the information from your CyberSource account
- For Test Mode, select No, if you are using a CyberSource production account, or Yes, if you are using a CyberSource sandbox account for testing purposes
- Click Save Payment Processor Settings
Note: The Certificate Status row in this panel is read-only. When Soapbox support has installed your certificate, it shows the expiration date, the certificate fingerprint, and when the certificate was last verified. Until then it reads "No certificate installed."
For Soapbox sites using the Soapbox CMS Classic administrator:
- Login to your Soapbox administrator
- In the main menu, go to Extensions > Plugin Manager
- In the Plugin Manager, in the upper right for the drop down that says "- Select Type -", choose "payment-gateway"
- In the filtered list of plugins, disable any except Payment Gateway - CyberSource by clicking the icon in the Enabled column
- Enable Payment Gateway - CyberSource by clicking the icon in the Enabled column
- Click Payment Gateway - CyberSource
- In the right column, for Merchant ID, enter the information from your CyberSource account
- For Transaction Security Key, enter the information from your CyberSource account
- For Test Mode, select No, if you are using a CyberSource production account, or Yes, if you are using a CyberSource sandbox account for testing purposes
- Click Save
Note: Certificate Fingerprint, Certificate Expires and Certificate Last Verified are read-only. They are populated when Soapbox support installs your certificate. See Upgrading your CyberSource connection to certificate authentication.
Related: Upgrading your CyberSource connection to certificate authentication