Security Keys - Generating a SCMP Security Key in the Business Center
000002879
34
07/21/2026 17:16 PM
7.0
Introduction
This article provides step-by-step instructions for generating a Simple Commerce Message Protocol (SCMP) security key in the Business Center. Security keys are required to authenticate and secure transactions sent to either the Test or Production environment. A unique key must be generated and downloaded for each environment. Please note that SCMP security keys expire every two years and must be renewed to maintain uninterrupted transaction processing.
Requirements
You must generate and download a unique security key for each environment to which you will send transactions: Test or Production.
Simple Commerce Message Protocol (SCMP) security keys expire every two years.
Generating SCMP Security Keys from the Business Center
- Signing into the Business Center for the appropriate environment (Test or Production) where the key will be used.
- Selecting Payment Configurations > Key Management > Generate Key.
- Selecting SCMP under Legacy Key types.
- Selecting Generate Key.
- Selecting Download key, which will generate the certificate file (.crt).
- Specifying the location to save the file to.
All SCMP security keys use the filename format: <organization_id>.<extension>
As an example, if your Organization ID is "bills_bagels", the files you will generate and/or download will be the following:
bills_bagels.pvt (client-side private key)
bills_bagels.crt (client-side public key)
CyberSource_SJC_US.crt (server-side public key)
Please note the location into which you save these files. If you are unable to find them, you will have to generate a new set.
Note: As a secure best practice, remember to delete any copies of these encryption keys from your clipboard and/or system memory cache once you have completed these steps.
Common Questions
- How often do SCMP security keys need to be renewed?
- SCMP security keys expire every two years and must be regenerated before expiration to avoid transaction disruptions.
- Do I need separate keys for the Test and Production environments?
- Yes. A unique security key must be generated and downloaded for each environment where transactions will be sent.
- What files are generated when I create an SCMP security key?
- Three files are generated using the format <organization_id>.<extension>: a client-side private key (.pvt), a client-side public key (.crt), and a server-side public key (CyberSource_SJC_US.crt).
- What should I do if I cannot locate the downloaded key files?
- If the files cannot be found, you will need to generate a new set of keys. Always note the save location during download.
- Are there any security best practices I should follow after generating a key?
- Yes. As a secure best practice, delete any copies of these encryption keys from your clipboard and/or system memory cache once the process is complete.
Was this article helpful?
