Settlement
Settlement batches and reconciliation exceptions — the read surface of the two-state settlement contract. A batch is `gateway_reported` while Cresora holds only the gateway's per-transaction settled webhooks, and `report_verified` once the processor's settlement report has been ingested and its control totals verified. Exceptions are the mismatches that verification (or the settlement-window sweep) raised. Read-only for partners; resolution is a Cresora Operations action.
x-cresora-status: planned in the canonical contract: they have no route on any host and return 404 (or 501 for reserved discriminator variants) until released. There is no separate preview stream, no feature flag to enable one, and no enrollment — the badge on each operation tells you whether it is served. See the stable /api/v1 reference for what you can call today. Like the stable API, these operations are server-to-server: there is no interactive console here. Download the preview spec (YAML)./settlement/batchesAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Query Parameters
Opaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Narrows to this merchant's batches. A malformed or blank value is rejected with 400 — never answered with the unfiltered list.
uuidUnknown values are rejected with 400 (typed binding).
Value in
- "PENDING"
- "RECONCILING"
- "RECONCILED"
- "EXCEPTION"
- "CLOSED_WITH_EXCEPTIONS"
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/batches"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "state": "PENDING", "reporting_basis": "gateway_reported", "processing_account": { "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "processor_key": "string" }, "vendor_status": "string", "gateway_batch_id": "string", "processor_batch_id": "string", "closed_settlement_batch_id": "string", "vendor_settlement_batch_id": "string", "transaction_count": 0, "total_amount": "string", "fees": "string", "net_amount": "string", "expected_settled_count": 0, "observed_member_count": 0, "observed_member_amount": "string", "run_date_utc": "2019-08-24T14:15:22Z", "completed_at_utc": "2019-08-24T14:15:22Z", "trigger_type": "string", "settlement_date": "2019-08-24", "expected_by": "2019-08-24T14:15:22Z", "held_reason": "string", "reconciled_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z" } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}/settlement/batches/{batchId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/batches/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "state": "PENDING", "reporting_basis": "gateway_reported", "processing_account": { "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "processor_key": "string" }, "vendor_status": "string", "gateway_batch_id": "string", "processor_batch_id": "string", "closed_settlement_batch_id": "string", "vendor_settlement_batch_id": "string", "transaction_count": 0, "total_amount": "string", "fees": "string", "net_amount": "string", "expected_settled_count": 0, "observed_member_count": 0, "observed_member_amount": "string", "run_date_utc": "2019-08-24T14:15:22Z", "completed_at_utc": "2019-08-24T14:15:22Z", "trigger_type": "string", "settlement_date": "2019-08-24", "expected_by": "2019-08-24T14:15:22Z", "held_reason": "string", "reconciled_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z"}/settlement/batches/{batchId}/transactionsAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuidQuery Parameters
Opaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/batches/497f6eca-6276-4993-bfeb-53cbbbba6f08/transactions"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "transaction_id": "0fec1e58-b197-4052-99cf-2218496c5482", "gateway_transaction_id": "string", "rail": "CARD", "amount": "string", "settled_at": "2019-08-24T14:15:22Z", "match_state": "RECORDED" } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}/settlement/exceptionsAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Query Parameters
Opaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Narrows to exceptions attributed to this merchant. A malformed or blank value is rejected with 400 — never answered with the unfiltered list.
uuidUnknown values are rejected with 400 (typed binding).
Value in
- "OPEN"
- "AUTO_RESOLVED"
- "MANUAL_RESOLVED"
- "WRITTEN_OFF"
- "ESCALATED"
Unknown values are rejected with 400 (typed binding).
Value in
- "MISSING_TRANSACTION"
- "EXTRA_TRANSACTION"
- "DUPLICATE_TRANSACTION"
- "AMOUNT_MISMATCH"
- "UNSETTLED_TRANSACTION"
- "FEE_MISMATCH"
- "BATCH_TOTAL_MISMATCH"
- "UNMATCHED_PLATFORM"
- "MISSING_BATCH"
- "LATE_PRESENTMENT"
- "CAPTURED_AMOUNT_MISMATCH"
- "ASSESSED_SURCHARGE_MISMATCH"
- "SURCHARGE_REVERSAL_MISMATCH"
Narrows to exceptions ranked at this severity. Unknown values are rejected with 400 (typed binding) — never answered with the unfiltered list. An exception with no severity (null) matches no value of this filter.
Value in
- "LOW"
- "MEDIUM"
- "HIGH"
- "CRITICAL"
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/exceptions"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "batch_id": "4da22c97-b7d5-4e31-8c3a-03870ebc7b20", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "transaction_id": "0fec1e58-b197-4052-99cf-2218496c5482", "type": "MISSING_TRANSACTION", "state": "OPEN", "severity": "LOW", "description": "string", "expected_by": "2019-08-24T14:15:22Z", "observed_at": "2019-08-24T14:15:22Z", "resolved_by": "operator", "resolved_at": "2019-08-24T14:15:22Z", "resolution": "string", "created_at": "2019-08-24T14:15:22Z" } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}Customers
Payer customers under a merchant. A customer owns the merchant's stored payment methods (the tokenization vault). Partner self-service (`customer:read` / `customer:write`); the merchant is the path scope and the partner is scoped from your API key.
Stored credentials
The tokenization vault — cards a merchant has stored for reuse. Entries are minted at a hosted-page (HPP) establishing completion, not created directly; ISVs list, inspect, and revoke them, and charge a stored card by passing its opaque vault token as the payment instrument on `POST /transactions` (`stored_credential:read` / `:revoke`). The stored-credential (MIT/COF) reuse program has been always-on since its 2026-07-18 de-gate — there is no dedicated charge endpoint and no feature gate on this surface.