Capabilities
Query what your partner can do today — enabled features, certification status, MCC scope.
/capabilitiesAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/capabilities"{ "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "certification_status": "PENDING", "enabled_features": [ "ach_payments" ], "rate_limit_tier": "STANDARD"}Webhooks
Manage webhook subscriptions — event types, delivery URLs, HMAC secret rotation. See `webhooks:` section for event schemas.
Config
Partner configuration — webhook URL, IP allowlist, HPP defaults, rate-limit tier, AVS decline policy. Read your own config; write via `PUT /config/partners/{partnerId}`. Rate-limit tier and AVS decline policy are Cresora-managed (admin-only); webhook URL, HPP settings, and IP allowlist are partner self-service.