Skip to main content

Set Up REST SDK Integration


This tutorial guides you through how to set up the REST Client SDK in order to begin sending and receiving REST API messages to . The SDK is the fastest setup option. It handles common integration tasks, including authentication, and request formatting.

Sign Up for a Test Account

To begin setting up your account, you must first sign up for a sandbox test account. A test account enables you to obtain your REST API keys and test your implementation.

Follow these steps to sign up for a sandbox test account:

  1. Go to the Developer Center test account sign-up page:

  2. Enter your information into the test account form, and click Create Account.

  3. Go to your email and find a message titled Merchant Registration Details and click Set up your username and password now.

    Your browser opens the New User Sign Up wizard.

  4. Enter the organization ID and contact email you submitted during account creation.

    Follow the wizard pages and on-screen instructions to enter your name, username, and password.

  5. Log in to the using your account credentials:

    The Verify your Identity page appears. When you log in for the first time, you must verify your identity through a system-generated email sent to your registered email account.

  6. Check your email inbox for a message titled Identification Code. A passcode is included in the message.

  7. Enter the passcode on the Verify your Identity page.

    You are directed to the dashboard page.

Create a REST API Key

Choose either a P12 certificate or a shared secret key pair, then follow the steps for that key type.

FeatureP12 CertificateShared Secret Key Pair
Best forServer-side integrations using certificate-based authenticationMost REST API integrations using HTTP Signature authentication
How it worksA .p12 certificate file and password authenticate each requestAn API key ID and shared secret key sign each request
Key benefitStrong certificate-based securityEasier to generate, store, and rotate

Decide which REST API key is best for your organization and click its corresponding option below. REST API keys are cryptographic keys that determine how the SDK constructs REST API messages.

Create a REST–API Response MLE Key

Before you can enable your system to support MLE, you must create or upload a REST—API response MLE certificate. After creating or uploading the certificate, you can extract the certificate's key to begin enabling MLE. If your organization is using meta keys, the shared secret key pair and REST – API response MLE key must be created by the same portfolio or merchant account.

Overview of MLE

Message-level encryption (MLE) enables you to store information or communicate with other parties while helping to prevent uninvolved parties from understanding the stored information. Enabling MLE requires you to create a P12 certificate or shared secret key pair for encrypting your requests and a REST – API Response MLE key for decrypting received responses. If your organization is using meta keys, your REST API keys must be created by the same portfolio or merchant account.

Follow these steps to create or submit an API Response MLE certificate in the :

Create or Submit a REST—API Response MLE Key

To enable MLE, you must first create a new REST—API response MLE certificate or upload an existing certificate. After creating or uploading the certificate, you can extract the certificate key to begin enabling MLE.

Follow these steps to create or submit an API Response MLE certificate in the :

  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. Log in to the :
    • Test site when setting up REST:
    • Production site when approved to go live:
  1. On the left navigation panel, choose Payment Configuration > Key Management.

  2. Click + Generate key on the Key Management page.

  3. Under REST APIs, choose REST – API Response MLE, and then click Generate key.

  4. Choose one of these options to download your key:

    To create a new API response MLE certificate, click Download key .

    To upload your own certificate, enter your public PEM-formatted certificate in the text box, and then click Download key . The .pem file downloads to your desktop. If prompted by your system, approve the location to which the file downloads.

  5. If you are creating a certificate, the Set a Password window appears. Create a password for the certificate by entering the password into the New Password and Confirm Password fields, and then click Generate key

    The .p12 file downloads to your desktop. If prompted by your system, approve the location to which the key downloads. To create or submit another key, click Generate another key. To view all of your created keys, go to the Key Management page.

  6. Click Cancel.

    The Key Management page appears.

  7. Click the Key Type filter and choose REST-API Response MLE.

  8. Click the Expires At filter and choose All Dates.

  9. Click Search.

  10. Find the REST–API Response key that you created in the Search Results table and save its key ID.

    The key ID is needed to test and configure your system to use MLE.


Test Your REST–API Response MLE Key

Follow these steps to verify that your REST-API response MLE key is working.

  1. Go to the REST API Reference page in the Developer Center:

  2. On the left navigation panel, choose an API that supports MLE. For testing purposes, you can choose Intelligent Commerce > Intelligent Commerce Product > Enroll a Card.

    MLE support is indicated by Request MLE and Response MLE at the top of the screen.

  3. Choose the MLE Configuration tab.

  4. In the Message Level Encryption Credentials section, enter your API response MLE key credentials:

    • Response encryption: Enter the key ID of your REST—API response MLE key.

      You saved this key ID in Step 11 in the Create or Submit a REST—API Response MLE Key section.

    • Response decryption: Click Browse to submit your own private decryption key from your local system. Only .p12 files are supported.

  5. Click Update Credentials.

  6. From the Send drop-down menu, choose Send Request with Message Level Encryption.

  7. Click Send.

Install the REST SDK

The REST Client SDK constructs JSON Web Token (JWT) messages for you to send to . These messages are also encrypted using message-level encryption (MLE) by the SDK. When you receive a response message from , the SDK decrypts it using MLE.

For more information about how to install the REST Client SDK into your system, see the REST API related products table in the GitHub.

SDK Version

This table lists the minimum SDK versions that support the updated JWT message construction and MLE requirements. Find your system's processing language and install the corresponding SDK version or a later version:

LanguageMinimum SDK Version RequiredMLE Enablement Instructions
.NET Frameworkv0.0.1.60cybersource-rest-client-dotnet/MLE.md
.NET Standard or .NET Corev0.0.1.52cybersource-rest-client-dotnetstandard/MLE.md
Javav0.0.85cybersource-rest-client-java/MLE.md
Nodev0.0.75cybersource-rest-client-node/MLE.md
PHPv0.0.69cybersource-rest-client-php/MLE.md
Pythonv0.0.73cybersource-rest-client-python/MLE.md
Rubyv0.0.81cybersource-rest-client-ruby/MLE.md

Table: Minimum Required SDK Versions

Test Your Setup

recommends that you test and verify that your system can securely send and receive REST API messages before transitioning to a production account. Use the test payment examples provided in this section to test your set up. You should also test any additional API requests that you will use in your live environment. For additional API examples, use the developer guide or the REST API Reference:

Complete a Test Transaction

After setting up your system to be REST compliant, you can send these test requests to verify that you can send and receive REST API messages.

Authorize a Payment

You send this POST request to the /pts/v2/payments endpoint:

{    "orderInformation": {        "billTo": {            "country": "US",            "lastName": "Kim",            "address1": "201 S. Division St.",            "postalCode": "48104-2201",            "locality": "Ann Arbor",            "administrativeArea": "MI",            "firstName": "Kyong-Jin",            "email": "[email protected]"        },        "amountDetails": {            "totalAmount": "100.00",            "currency": "USD"        }    },    "paymentInformation": {        "card": {            "expirationYear": "2031",            "number": "4111111111111111",            "expirationMonth": "12",            "type": "001"        }    }}

Capture an Authorized Payment

You send this POST request to the /pts/v2/payments/{id}/captures endpoint and include the authorization transaction ID as the {id}:

/pts/v2/payments/6461731521426399003473/captures
{    "clientReferenceInformation": {        "code": "ABC123"    },    "orderInformation": {        "amountDetails": {            "totalAmount": "100.00",            "currency": "USD"    }}

Refund a Captured Payment

You send this POST request to the /pts/v2/payments/{id}/refunds endpoint and include the capture transaction ID as the {id}:

/pts/v2/payments/6772994431376681303954/refunds
{    "orderInformation": {        "amountDetails": {            "totalAmount": "100.00",            "currency": "USD"        }    }}

Troubleshooting Errors

If you receive an error message during testing, use this table to determine the cause of the error. For additional error code descriptions, see the Transaction response codes page:

SymptomCauseWhat to do
Could not load PKCS12 fileWrong password, corrupted file, or wrong file formatTry opening the file with openssl pkcs12 -in file.p12 -info to verify it's well-formed. Confirm password is correct.
BAD_CERTIFICATE in responseCertificate expired or revokedTest certs expire in 90 days; regenerate. Check the Key Management page for the certificate's status.
Transaction approved in test, denied in productionTest merchant ID was used in a production-credential requestVerify runEnvironment and credentials match — test certs cannot authenticate to the production host.

Going Live

When you are ready to begin sending live API requests, you must request a production account. A production account sends API requests to the production endpoint, which routes your message to the applicable services, processors, or networks.


Sign Up for a Production Account

Follow these steps to create your production account:

  1. Log in to your test account:

  2. In the , go to Support Cases > MID Configuration Request.

    The MID Configuration Request appears.

  3. Click MID Activation.

  4. In the Description field, enter the merchant ID that you want to take live.

  5. Choose a processor configuration, and enter the name of your processor.

    If you are unsure of the processor name, contact your merchant service provider or your merchant acquiring bank.

  6. Choose the production environment to apply these change.

  7. Click Service Enablement and list the products and services that you intend to use.

  8. Click Submit.


Establish a Contract

Contact Sales to establish a contract with that enables you to process real transactions and receive support.

Contact Sales to establish a contract with that enables you to process real transactions and receive support.

Contact Sales to establish a contract with that enables you to process real transactions and receive support.


Activate Production Account

Submit a merchant ID (MID) activation request.

It can take up to three business days for the MID to become active.


Create Your Production Credentials

After your production account is created, log in and generate new production credentials. The credentials you created using your test account, such as your API keys, do not automatically transition to the production environment. You must also update your system configuration to now use your new credentials.

Credential Checklist

  • REST API key (P12 certificate or shared secret key pair)
  • REST—API Response MLE Key

Next Steps

Your integration is now ready. Choose which solutions to build with next:

Additional Solutions


Last published: September 29, 2026