Custom Fields
Per-merchant custom-field definitions — up to 10 fields per merchant (a Cresora product cap; the gateway documents none). Definitions are delivered onto the merchant's gateway record and the field VALUES ride transaction creates (Sale / Authorization / ACH debit + recurring contract create) and hosted-page checkouts. Partner self-service (`custom_fields:config:read` / `custom_fields:config:write`); the merchant is scoped from your API key, never a path/body param.
/config/custom-fields/merchants/{merchantId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
The merchant whose custom-field definitions are managed. Must belong to the authenticated partner.
uuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/config/custom-fields/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "fields": [ { "name": "string", "description": "string", "position": 0, "isRequired": false, "isEnabled": true, "isNumeric": false, "decimalPlaces": 0, "maxLength": 25, "isMultiValue": false, "maxValues": 1, "regEx": "string", "regExErrorMessage": "string", "numericMinValue": 0, "numericMaxValue": 1, "virtualTerminal": { "visible": false, "readOnly": false }, "hostedPaymentPage": { "visible": false, "readOnly": false }, "transactionReports": { "visible": false, "readOnly": false } } ], "version": 0, "provisioning": { "status": "UNPROVISIONED", "error": "string", "provisioned_version": 0 }}/config/custom-fields/merchants/{merchantId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
The merchant whose custom-field definitions are managed. Must belong to the authenticated partner.
uuidResponse Body
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X DELETE "https://example.com/config/custom-fields/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08"/config/custom-fields/merchants/{merchantId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
The merchant whose custom-field definitions are managed. Must belong to the authenticated partner.
uuidHeader Parameters
Client-generated unique key — a UUIDv4 is the recommended form. Cresora deduplicates within a 24-hour window scoped to the partner.
Format: 1–128 characters of letters, digits, . _ : -. Anything else is rejected with 400 validation_error. The character
set is narrower than base64: padded base64 (+ / =) is NOT
accepted, base64url is. The key is forwarded verbatim to the payment
gateway on transaction creates, so it must satisfy the gateway's key
contract too — rejecting locally gives you an actionable error instead
of an opaque upstream failure mid-request.
Reserved prefixes — rejected with 400 idempotency_key_reserved:
hpp:,recurring:— Cresora's own server-minted deterministic keys. A client key in these namespaces could collide with a platform-generated record.rb:,inv-charge:,inv-installment:— reserved by the payment gateway for its internally-minted keys.
Replay semantics:
- Same key + same request body → Cresora returns the cached
response from the original call. Response includes header
X-Idempotent-Replay: trueso the client can distinguish replays from fresh executions. Status code, body and side effects are identical to the original call. - Same key + different body →
422 idempotency_key_reused. Generate a new key and retry, or re-send the original body. - Key older than 24 hours → treated as a fresh key; no replay guarantee from beyond the window.
Retrying after an indeterminate failure. On 502 gateway_outcome_unknown the transaction is recorded as pending and
the outcome is not yet known — retry with the SAME key (a fresh key
risks a double charge) or poll the transaction. This is also what a
gateway-side "an earlier request with this key is still in flight"
response surfaces as.
Do NOT reuse keys across different partners. Scope is enforced
per partner_id so the same key in partner A and partner B
is independent.
^[A-Za-z0-9._:\-]+$1 <= length <= 128Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Create/replace a merchant's WHOLE custom-field set — add/edit/delete
compose into one PUT (the gateway has no per-field CRUD). An empty
or absent fields array clears the merchant's custom fields.
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X PUT "https://example.com/config/custom-fields/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08" \ -H "Idempotency-Key: string" \ -H "Content-Type: application/json" \ -d '{}'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "fields": [ { "name": "string", "description": "string", "position": 0, "isRequired": false, "isEnabled": true, "isNumeric": false, "decimalPlaces": 0, "maxLength": 25, "isMultiValue": false, "maxValues": 1, "regEx": "string", "regExErrorMessage": "string", "numericMinValue": 0, "numericMaxValue": 1, "virtualTerminal": { "visible": false, "readOnly": false }, "hostedPaymentPage": { "visible": false, "readOnly": false }, "transactionReports": { "visible": false, "readOnly": false } } ], "version": 0, "provisioning": { "status": "UNPROVISIONED", "error": "string", "provisioned_version": 0 }}/config/custom-fields/configsAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/config/custom-fields/configs"[ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "fields": [ { "name": "string", "description": "string", "position": 0, "isRequired": false, "isEnabled": true, "isNumeric": false, "decimalPlaces": 0, "maxLength": 25, "isMultiValue": false, "maxValues": 1, "regEx": "string", "regExErrorMessage": "string", "numericMinValue": 0, "numericMaxValue": 1, "virtualTerminal": { "visible": false, "readOnly": false }, "hostedPaymentPage": { "visible": false, "readOnly": false }, "transactionReports": { "visible": false, "readOnly": false } } ], "version": 0, "provisioning": { "status": "UNPROVISIONED", "error": "string", "provisioned_version": 0 } }]Health
Service health and liveness probes — for partner integration monitoring and uptime dashboards. Unauthenticated endpoint.
Customers
Payer customers under a merchant. A customer owns the merchant's stored payment methods (the tokenization vault). Partner self-service (`customer:read` / `customer:write`); the merchant is the path scope and the partner is scoped from your API key.