Release Notes {#rn-general}
===========================

These release notes cover all releases to the production server for the week ending October 17, 2025.

Announcements {#rn-announce}
============================

These are the announcements for October 17, 2025.

Webhooks Updates {#webhooks-validations-decommission}
=====================================================

We added new validations for version 1 of Webhooks:

* Only alpha-numeric data and spaces are allowed in the name field of newly created or updated subscriptions. Existing version 1 subscriptions are not affected unless they are updated.
* Most Webhooks fields for newly created or modified subscriptions do not accept HTML tags. Existing version 1 subscriptions are not affected unless they are updated.
* The securityType field in `Create` and `Patch` requests accepts only one of these values: `key`, `oAuth`, or` oAuth_JWT`.

{#webhooks-validations-decommission_ul_zrz_34c_qgc}  
Version 1 will be decommissioned in April 2026. See [Webhooks version 2 in the Developer Center](https://developer.cybersource.com/api-reference-assets/index.md#webhooks "").

Business Center Login Logo {#announcement-ebc-logo}
===================================================

**Products Included:** Business Center  
**Region/Country:** Global  
**Expected Release Date:** October 15, 2025  
The Business Center login page now displays the new Cybersource logo.

Features Introduced This Week {#rn-features}
============================================

**Acceptance Devices in the Business Center** \| RM-40211
---------------------------------------------------------

Description
:
The Terminal Details page in the Acceptance Devices section of the Business Center now has an Edit icon for all rows in the Installed Apps table. The Edit icon is disabled for the app BroadPOS P2PE.
:
When a user clicks the Edit icon, a dialog box appears, which shows this information:

    * App name
    * Current version
    * Push task status (only shown if the push task status is not `SUCCESS` or `FAILED`)
    * Available versions
    {#rn-features_ul_eqv_hzp_zgc}If the installed version and the version selected by the user are the same, no update notification is shown.

:
If the update is successful, a success notification is shown.
:
If there is an error, an error notification is shown.
:
The update functionality is disabled if the push task status is `STARTED`, `INITIALIZING`, `WAITING`, or `UNKNOWN`.

Audience
:
Users of Acceptance Devices.

Benefit
:
Users can directly edit the apps installed on terminal devices through the Business Center.

Technical Details
:
None.

Important Dates
:
Released to production October 16, 2025.

**Unified Checkout** \| RM-38015 and RM-39697
---------------------------------------------

Description
:
This release includes these features:
:
* Support for creating tokens using the Token Management Service.
* Support for payment industry fields such as Payer Authentication exceptions, client reference number, line items, and merchant defined data.
* Fixed device fingerprint integration to ensure consistent session ID when profiling and sending device information to the Token Management Service.
* Support for these alternative payments:
* Tink
* Bancontact, MyBank, Dragonpay, and P24
* Billing and shipping user interface for Afterpay
* Integration with Unified Checkout configuration transactional endpoint to obtain alternative payment configuration. Error handling for when the configuration is null.
{#rn-features_ul_w5y_2dw_zgc}
* Support for Jaywan cards.
* Fixes Microform JavaScript error when tabbing out from iframe.
* Additional support for Korean Cyber Payment and Universal Air Travel Plan.
* Updated payment details to return detected card types.
* Improved user interface to collect Pakistan address information.
* Removes confirmation screen for eCheck.
* Enables static assets version encryption for staticAssets URL (`toggle -ps.uc.hashed-assets-endpoint-enabled`).
* Flex Direct gateway agnostic: new (migrated) *gda-backend/flex/v2/sessions* for Flex-Direct product, as proxy to current FLEX */v2/sessions* endpoint.
* Identifies Saudi Payments Gateway merchants and passes information to Flex.
* Moves `transactionStatus` object from complete response to webhook.
* Extends CaptureContext response for UC with completeURL field.
{#rn-features_ul_v5y_2dw_zgc}

Audience
:
Users of Unified Checkout.

Technical Details
:
None.

Important Dates
:
Released to the testing environment October 15, 2025.

Fixed Issues {#rn-fixed-issues}
===============================

No customer-facing fixes were released this week.

Known Issues {#rn-known-issues}
===============================

**Security Keys** \| EPS-33083
------------------------------

Description
:
Users who have custom roles that include key management permissions might not be able to download an Apple Pay Certificate Signing Request, even though the Business Center says it was successfully downloaded.

Audience
:
Users of the Business Center.

Technical Details
:
None.

Workaround
:
None.

**Decision Manager Reports and Profile Statistics** \| EPS-33856
----------------------------------------------------------------

Description
:
When users of Decision Manager's Case Management page compare the cases for a particular time period with the cases showing in the Profile Statistics dashboard for the same time period, the numbers might not match. For example, Case Management might show 100 Accept and 50 Reject cases, while Profile Statistics might show 95 Accept and 60 Reject cases.

Audience
:
Merchants using Decision Manager and Profile Statistics.

Technical Details
:
None.

Workaround
:
None.

**Pay By Link** \| EPS-34132
----------------------------

Description
:
When the customer views the receipt URL link for a transaction processed using Pay by Link, they might see a blank page with the following message: *'Error: Unexpected server error'*.
:
Additionally, the merchant might also encounter a red banner error in the Business Center when attempting to view the Settings page for Pay by Link.

Audience
:
Merchants and customers using Pay by Link.

Technical Details
:
None.

Workaround
:
None.

**Unified Checkout** \| EPS-34183
---------------------------------

Description
:
When merchants use `billingType=NONE` in the capture context, in conjunction with Payer Authentication, the transaction sometimes fails with error message `DMISSINGFIELD RC 101`, related to the Billing Address Information.

Audience
:
Merchants using Unified Checkout.

Technical Details
:
None.

Workaround
:
None.

**Payment Processing** \| **EPS-34267**
---------------------------------------

Description
:
This defect occurs when merchants process authorization transactions through the Barclays processor during network connectivity issues. From the merchant's perspective, they receive a response saying "Request has timed out, transaction not sent to Processor" with reason code 150 (ESYSTEM), leading them to believe the transaction failed. However, the acquirer (Barclays) actually processes the authorization and issues an authorization code, resulting in customer funds being held.
:
The merchant experiences this issue through both API responses and the Business Center interface, where they see failed transactions that actually succeeded on the processor side. This creates a mismatch between what the merchant sees in their reports versus what actually happened with the customer's payment method, leading to customer complaints about unexpected holds on their funds.

Audience
:
Merchants in the EU and UK who use Barclays as an acquirer and processor.

Technical Details
:

Workaround
:
* Check directly with Barclays to confirm transaction status before retrying.
* For payouts specifically, verify status with Barclays before attempting retries.
* Use standalone transactions instead of retrying potentially successful ones.

**Decision Manager** \| EPS-34323
---------------------------------

Description
:
Missing response for Apple Pay when Decision Manager returns the review status.

Audience
:
Merchants who use Decision Manager and Apple Pay.

Technical Details
:
None.

Workaround
:
None.

**Portfolio Management** \| EPS-34345
-------------------------------------

Description
:
Portfolio users in India cannot trigger user registration email to the merchants.

Audience
:
Portfolio users in India.

Technical Details
:
None.

Workaround
:
Use an administrator account.
