Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Leaflet 10.4.13 — Minor update available for module leaflet (10.4.13). Release: Flag 5.1.1 — Minor update available for module flag (5.1.1). Release: Layout Paragraphs 3.0.0-beta5 — New beta version released for module layout_paragraphs (3.0.0-beta5). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

Cybersource REST

Security covered Drupal 10–11
View on drupal.org

This module integrates Cybersource's REST API with Drupal Commerce, using Flex Microform to securely process payments. It handles Strong Customer Authentication (SCA) and prioritizes security by keeping API credentials off your server and out of your code. The integration offers authorization, capture, void, and refund capabilities with a user-friendly card interface.

Cybersource payment gateway for Drupal Commerce using the REST API and Flex Microform v2. Card number and CVV are entered into Cybersource-hosted iframes and never reach your server; the browser produces a single-use transient token that is charged server-side. This typically qualifies for a reduced PCI scope (SAQ A / A-EP — confirm with your acquirer or QSA).

3-D Secure 2.x / Strong Customer Authentication

Built-in Payer Authentication (EMV 3DS 2.x, Cardinal Commerce built into Cybersource — no separate Cardinal account) for UK/EEA SCA: frictionless authentication carries the CAVV/ECI into the authorization; challenges open in a modal iframe and are validated server-to-server. The integration fails closed — with 3-D Secure enabled, a payment that skipped or tampered with the authentication steps is refused before any charge is attempted. The authentication result is session-bound, single-use, and never travels through the browser.

Security by design

  • API credentials live in a private file outside the web root and outside site configuration — they never enter config exports, the database, or git. Runtime status-report checks cover the private filesystem, the credentials file, test mode, and optional key-expiry monitoring.
  • The Microform client script is only injected over HTTPS from a Cybersource host and with the Subresource Integrity hash the capture context supplies — fail closed on either check.
  • The charged amount and currency always come from the order, never from the client; capture, void, and refund verify the Cybersource status before recording money movements, and every money movement is written to the order's activity log (never card data).
  • A payment request that gets no response is flagged for manual reconciliation rather than assumed failed; Decision Manager reviews are held as pending authorizations, never auto-completed.

Features

  • Authorization or sale, plus capture, void, and full/partial refund.
  • Polished card UI: live brand detection, accepted-brand enforcement, inline validation.
  • Test and live profiles resolved at runtime; sandbox-ready with the documented 3-D Secure test card matrix (see the README).
  • PHPStan level 6 and PHPCS clean; PHPUnit kernel coverage of the payment, decline, review, and 3-D Secure fail-closed paths with a mocked API client; Playwright end-to-end checkouts (frictionless and challenge) against the Cybersource sandbox.

Requirements

  • Drupal 10.3+ or 11, Commerce 3, and the official Cybersource PHP SDK (installed by Composer).
  • A Cybersource account with REST API keys; Payer Authentication must be enabled on the account to use 3-D Secure.

Roadmap

Saved cards via Token Management (TMS), SCA exemption flags (TRA / low value), and Level II/III data. See the README for the full roadmap and setup guide.

Related modules

For the hosted-form Secure Acceptance integration by the same maintainer, see Cybersource SOP. The existing Commerce CyberSource module also provides a Flex integration; this module differs mainly in keeping credentials out of site configuration, SRI-pinned script loading, 3-D Secure support, and its test coverage.

Depends on

Dependencies of the latest stable release

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
Jul 2026
Latest release
1 month ago
Releases (12 mo)
4 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.0.2 Stable 10–11 Sep 5, 2026
1.0.1 Stable 10–11 Aug 17, 2026
1.0.0 Stable 10–11 Jul 7, 2026
1.0.x-dev Dev 10–11 Jul 6, 2026