Certification
Request and track partner certification checks. Certification is the gate a partner clears before onboarding real merchants.
x-cresora-status: planned in the canonical contract: they have no route on any host and return 404 (or 501 for reserved discriminator variants) until released. There is no separate preview stream, no feature flag to enable one, and no enrollment — the badge on each operation tells you whether it is served. See the stable /api/v1 reference for what you can call today. Like the stable API, these operations are server-to-server: there is no interactive console here. Download the preview spec (YAML)./partner/me/certification/recertification-requests/currentAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/partner/me/certification/recertification-requests/current"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "requested_features": [ "TERMINAL" ], "message": "string", "state": "PENDING", "dismissed_reason": "string", "created_at": "2019-08-24T14:15:22Z"}/certification/flows/activeAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/certification/flows/active"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "status": "ACTIVE", "features": [ "TERMINAL" ], "created_at": "2019-08-24T14:15:22Z", "completed_at": "2019-08-24T14:15:22Z", "run_started_at": "2019-08-24T14:15:22Z", "flow_type": "INITIAL", "recertification_reason": "string", "attempt_number": 1, "supersedes_flow_id": "dcfff01b-cccd-4474-a561-eed33701839b", "baseline": { "features": [ "string" ], "check_codes": [ "string" ], "steps": [ { "step": 0, "label": "string", "total": 0 } ] }, "progress": { "total": 0, "passed": 0, "failed": 0, "waived": 0, "skipped": 0, "pending": 0, "awaiting_admin_review": 0, "percent": 0, "steps": [ { "step": 1, "label": "string", "total": 0, "resolved": 0, "failed": 0, "awaiting_admin_review": 0, "unlocked": true, "complete": true } ] }, "checks": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "category": "string", "label": "string", "tier": "AUTOMATED", "state": "PENDING", "check_code": "string", "tier_level": 1, "step": 1, "flag_group": "string", "flag_group_label": "string", "description": "string", "pass_criteria": "string", "attestation_statement": "string", "result_notes": "string", "waiver_reason": "string", "submitted_by": "string", "submitted_at": "2019-08-24T14:15:22Z", "submittable": true, "checked_by": "string", "checked_at": "2019-08-24T14:15:22Z", "last_run_at": "2019-08-24T14:15:22Z", "failure_reason": "string", "execution_logs": "string", "request_payload": "string", "retry_history": [ { "attempt": 1, "trigger": "RUN_START", "verdict": "SATISFIED", "resulting_state": "PENDING", "failure_reason": "string", "execution_logs": "string", "evaluated_at": "2019-08-24T14:15:22Z", "duration_ms": 0 } ] } ]}/certification/flows/latest-completedAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/certification/flows/latest-completed"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "status": "ACTIVE", "features": [ "TERMINAL" ], "created_at": "2019-08-24T14:15:22Z", "completed_at": "2019-08-24T14:15:22Z", "run_started_at": "2019-08-24T14:15:22Z", "flow_type": "INITIAL", "recertification_reason": "string", "attempt_number": 1, "supersedes_flow_id": "dcfff01b-cccd-4474-a561-eed33701839b", "baseline": { "features": [ "string" ], "check_codes": [ "string" ], "steps": [ { "step": 0, "label": "string", "total": 0 } ] }, "progress": { "total": 0, "passed": 0, "failed": 0, "waived": 0, "skipped": 0, "pending": 0, "awaiting_admin_review": 0, "percent": 0, "steps": [ { "step": 1, "label": "string", "total": 0, "resolved": 0, "failed": 0, "awaiting_admin_review": 0, "unlocked": true, "complete": true } ] }, "checks": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "category": "string", "label": "string", "tier": "AUTOMATED", "state": "PENDING", "check_code": "string", "tier_level": 1, "step": 1, "flag_group": "string", "flag_group_label": "string", "description": "string", "pass_criteria": "string", "attestation_statement": "string", "result_notes": "string", "waiver_reason": "string", "submitted_by": "string", "submitted_at": "2019-08-24T14:15:22Z", "submittable": true, "checked_by": "string", "checked_at": "2019-08-24T14:15:22Z", "last_run_at": "2019-08-24T14:15:22Z", "failure_reason": "string", "execution_logs": "string", "request_payload": "string", "retry_history": [ { "attempt": 1, "trigger": "RUN_START", "verdict": "SATISFIED", "resulting_state": "PENDING", "failure_reason": "string", "execution_logs": "string", "evaluated_at": "2019-08-24T14:15:22Z", "duration_ms": 0 } ] } ]}/certification/flows/{flowId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/certification/flows/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "status": "ACTIVE", "features": [ "TERMINAL" ], "created_at": "2019-08-24T14:15:22Z", "completed_at": "2019-08-24T14:15:22Z", "run_started_at": "2019-08-24T14:15:22Z", "flow_type": "INITIAL", "recertification_reason": "string", "attempt_number": 1, "supersedes_flow_id": "dcfff01b-cccd-4474-a561-eed33701839b", "baseline": { "features": [ "string" ], "check_codes": [ "string" ], "steps": [ { "step": 0, "label": "string", "total": 0 } ] }, "progress": { "total": 0, "passed": 0, "failed": 0, "waived": 0, "skipped": 0, "pending": 0, "awaiting_admin_review": 0, "percent": 0, "steps": [ { "step": 1, "label": "string", "total": 0, "resolved": 0, "failed": 0, "awaiting_admin_review": 0, "unlocked": true, "complete": true } ] }, "checks": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "category": "string", "label": "string", "tier": "AUTOMATED", "state": "PENDING", "check_code": "string", "tier_level": 1, "step": 1, "flag_group": "string", "flag_group_label": "string", "description": "string", "pass_criteria": "string", "attestation_statement": "string", "result_notes": "string", "waiver_reason": "string", "submitted_by": "string", "submitted_at": "2019-08-24T14:15:22Z", "submittable": true, "checked_by": "string", "checked_at": "2019-08-24T14:15:22Z", "last_run_at": "2019-08-24T14:15:22Z", "failure_reason": "string", "execution_logs": "string", "request_payload": "string", "retry_history": [ { "attempt": 1, "trigger": "RUN_START", "verdict": "SATISFIED", "resulting_state": "PENDING", "failure_reason": "string", "execution_logs": "string", "evaluated_at": "2019-08-24T14:15:22Z", "duration_ms": 0 } ] } ]}Terminals
Register, provision, suspend and reactivate POS terminals. Terminal runtime communication uses WebSocket — see the separate AsyncAPI spec for the terminal protocol.
Webhooks
Manage webhook subscriptions — event types, delivery URLs, HMAC secret rotation. See `webhooks:` section for event schemas.