How to Connect Cybersource to Twilio for Voice & IVR Payments

By Shuttle Team, June 23, 2026

Cybersource doesn't natively connect to Twilio for voice payments. If you want to process Cybersource transactions during a phone call (via IVR, agent-assisted, or AI voice agent), you need a Twilio Pay Connector that bridges the two platforms.

Shuttle's Pay Connector does exactly this. It connects Cybersource (and 30+ other gateways) to Twilio's <Pay> verb, so you can accept PCI-compliant card payments during any voice interaction.

This guide walks through how the integration works, how to set it up, and what to watch for.


Why Cybersource + Twilio Don't Connect Directly

Cybersource is Visa's enterprise payment gateway. It's built for large organisations that process at scale: airlines, telcos, utilities, insurers, and global retailers. Its platform handles payment processing, fraud management, and tokenisation across acquirer connections worldwide, which is why so many enterprises standardise on it.

Twilio is built for voice and messaging. Its <Pay> verb captures card details during phone calls via DTMF keypad input, so the digits never reach the agent or the call recording.

The problem: Twilio's <Pay> needs a Pay Connector to route captured card data to a payment gateway. Cybersource isn't one of Twilio's built-in connectors.

This is where Shuttle comes in. Shuttle provides a Pay Connector that accepts card data from Twilio's <Pay> verb and routes it to Cybersource's API for processing. One integration connects the two platforms.


How It Works

Caller → Twilio (DTMF capture) → Shuttle (Pay Connector) → Cybersource (processing) → Result
  1. Caller reaches payment step. Your Twilio call flow (IVR or custom TwiML) triggers the <Pay> verb.

  2. Card details captured via DTMF. The caller enters their card number, expiry, and CVV on the keypad. The digits never reach the agent or the call recording.

  3. Shuttle receives card data. The data passes from Twilio's PCI-compliant environment directly to Shuttle's connector. It never touches your servers.

  4. Shuttle charges the card via Cybersource. The connector creates a Cybersource payment request, processes the transaction through your Cybersource merchant account, and handles the response.

  5. Result returned to your call flow. Your webhook receives the Cybersource transaction reference, last four digits, card brand, and transaction status. The call continues.

The caller stays on the line. No redirects, no "please visit our website."


Step-by-Step Setup

Prerequisites

  • A Twilio account with voice capability

  • A Cybersource account with REST API credentials (merchant ID, API key ID, and shared secret key, created in the Cybersource Business Center)

  • A Shuttle account (see pricing)

Step 1: Install Shuttle's Pay Connector

Go to the Twilio Marketplace and install the Shuttle Pay Connector. This adds Shuttle as an available connector in your Twilio account's Pay configuration.

Step 2: Add Cybersource Credentials to Shuttle

Log into the Shuttle dashboard. Navigate to Payment Profiles and create a new profile:

  • Gateway: Cybersource

  • Merchant ID: Your Cybersource merchant ID

  • Key ID: The API key ID generated in the Business Center

  • Shared secret: The shared secret key paired with that key ID

  • Currency: Set your default (GBP, USD, EUR, etc.)

  • Environment: Live or Test

Save the profile. Shuttle now has a live connection to your Cybersource account.

Step 3: Configure Your Twilio Call Flow

Add the <Pay> verb to your TwiML:

<Response>
  <Say>Please enter your card number followed by the hash key.</Say>
  <Pay paymentConnector="shuttle-pay-connector"
       chargeAmount="49.99"
       currency="GBP"
       description="Invoice payment"
       action="/payment-complete">
  </Pay>
</Response>

Key parameters:

  • paymentConnector: set to shuttle-pay-connector

  • chargeAmount: the amount to charge

  • currency: ISO currency code

  • action: your webhook endpoint for the payment result

Step 4: Handle the Payment Result

Twilio sends a POST to your action URL with the payment result:

{
  "Result": "success",
  "PaymentCardNumber": "xxxx-xxxx-xxxx-1234",
  "PaymentCardType": "visa",
  "PaymentConfirmationCode": "CYBS-TXN-REF-123...",
  "ProfileId": "your-shuttle-profile-id"
}

Use the PaymentConfirmationCode to look up the transaction in the Cybersource Business Center if needed. Update your order, confirm to the caller, and continue the flow.

Step 5: Test

Cybersource's sandbox is completely separate from production and needs its own credentials, so create a test key pair in the sandbox Business Center first. Then run the flow end-to-end with Cybersource's sandbox test cards: 4111 1111 1111 1111 (Visa), 5555 5555 5555 4444 (Mastercard). Use any future expiry date.


What You Can Do With Cybersource + Twilio

Charge Immediately

Standard auth-and-capture. The caller pays, Cybersource processes, done. This is the typical pattern for bill payments in utility, telco, and insurance contact centres.

Authorise Now, Capture Later

Place a hold on the card during the call and capture the payment later through Cybersource. Useful for bookings, deposits, and variable-amount transactions, a common pattern for airlines and travel operators taking reservations over the phone.

Tokenise for Future Use

Capture card details once over the phone. Shuttle tokenises the card via Cybersource's Token Management Service (TMS) and returns a reusable token. Use it for future payments across any channel: web, mobile, voice, or payment links. The card data is never stored in your systems, which matters for insurers and utilities collecting recurring or instalment payments from the same customer.

Keep Your Acquirer Relationships

Cybersource is a gateway with acquirer connections around the world, and many enterprises route through negotiated acquiring agreements behind it. Voice payments taken through Shuttle flow into the same Cybersource merchant account as your web and in-app transactions, so reporting, reconciliation, and fraud screening stay in one place.


Multi-PSP: Beyond Cybersource

One of the key advantages of using Shuttle rather than a Cybersource-only connector is flexibility. Your Twilio integration stays the same even if you:

  • Add a second gateway: put the merchants in one region on Cybersource and another region on a local acquirer

  • Serve enterprise customers who mandate a specific PSP (Stripe, Worldpay, Checkout.com, etc.)

  • Want a backup gateway: if one gateway has an outage, you can move the affected payment types to another connected gateway. There is no automatic failover, and saved cards stay with the gateway that stored them, so repeat payments on stored cards will not run through the second one

  • Expand to new markets, with each merchant or entity there on its own gateway

You choose which connected provider handles each payment type in Shuttle’s dashboard. Your Twilio call flow doesn't change. The <Pay> verb always points to shuttle-pay-connector, and Shuttle sends the payment to the provider you configured.

This is particularly important for platforms and BPOs that serve multiple merchants. Each merchant can use their own Cybersource account (or any other compatible gateway) through the same Twilio integration.


PCI Compliance

The Cybersource + Twilio integration via Shuttle limits your PCI scope:

Layer

PCI handled by

Secure DTMF capture

Twilio

Card data processing

Shuttle (PCI DSS Level 1)

Payment processing

Cybersource (PCI DSS Level 1)

Your systems

No card data on your systems: SAQ-A for merchants, SAQ-D for platforms

Card data flows from Twilio to Shuttle to Cybersource. Your application only receives redacted data (last 4 digits, card brand, transaction reference). Merchants complete SAQ-A, the lightest PCI self-assessment; platforms complete SAQ-D. Everyone taking card payments has to be PCI compliant, and your acquirer confirms which form applies to you.

For the full picture on PCI compliance with Twilio, see Twilio PCI Compliance: Payments Without Handling Card Data.


FAQ

Can I connect Cybersource to Twilio without Shuttle? Cybersource isn't one of Twilio's built-in connectors. You'd need to build a custom connector using Twilio's Generic Pay Connector framework, which means handling PCI compliance for card data processing yourself. Shuttle provides a pre-built, PCI-certified connector.

Does this work with Cybersource's Token Management Service? Yes. Shuttle can tokenise cards captured over the phone via Cybersource TMS, so a card taken during a call can be reused for later web, mobile, or recurring payments.

What about Cybersource's test environment? Fully supported. Cybersource's sandbox is separate from production with its own credentials. Create a sandbox key pair, add it to a test payment profile in Shuttle, and run the full flow with Twilio before going live.

What does it cost? Shuttle charges $49 per live instance per month, plus from $0.20 per transaction, falling with volume, billed through your Twilio account. Cybersource's standard fees apply on top (your negotiated gateway and acquiring rates).

Can I switch from Cybersource to another gateway later? Yes. Change the gateway in your Shuttle payment profile. Your Twilio call flow stays exactly the same, with no code changes needed. Saved cards stay with the gateway that stored them, so repeat payments on stored cards will not move to the new gateway.



Connect Cybersource to Twilio with Shuttle's Pay Connector: PCI DSS Level 1, $49 per live instance per month, plus from $0.20 per transaction, falling with volume, billed through your Twilio account. Install on Twilio or book a discovery call.

Take payments over the phone

Card capture for contact centres, IVR flows and AI voice agents, connected to 30+ payment gateways including Stripe, Adyen, and Worldpay Access.

Book a Call