Partners
Partner self-service reads. The `/partner/me` endpoint returns the partner record bound to the authenticated caller's API key — useful for portal "who am I" displays and federated-identity contracts. The cross-tenant listing (`GET /iam/partners`) lives in the admin-only surface. `GET /iam/partners/{id}` and `/{id}/transitions` are partner-callable under `partner:read`, but row-level security scopes them to the caller's own tenant — a foreign id resolves to `404`, never to another partner's record.
/partner/meAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/partner/me"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "name": "string", "contact_email": "user@example.com", "contact_name": "string", "business_address": { "address_line1": "string", "address_line2": "string", "city": "string", "state": "string", "zip": "string", "country": "US" }, "dba": "string", "partner_type": "ISV", "state": "PENDING", "commercial_model": "RESELLER", "rate_limit_tier": "STANDARD", "assigned_csm_name": "string", "assigned_csm_email": "string", "live_merchant_count": 0, "has_live_key": true, "created_at": "2019-08-24T14:15:22Z", "version": 0}/partner/me/certification/prepareAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Header Parameters
Client-generated unique key — a UUIDv4 is the recommended form. Cresora deduplicates within a 24-hour window scoped to the partner.
Format: 1–128 characters of letters, digits, . _ : -. Anything else is rejected with 400 validation_error. The character
set is narrower than base64: padded base64 (+ / =) is NOT
accepted, base64url is. The key is forwarded verbatim to the payment
gateway on transaction creates, so it must satisfy the gateway's key
contract too — rejecting locally gives you an actionable error instead
of an opaque upstream failure mid-request.
Reserved prefixes — rejected with 400 idempotency_key_reserved:
hpp:,recurring:— Cresora's own server-minted deterministic keys. A client key in these namespaces could collide with a platform-generated record.rb:,inv-charge:,inv-installment:— reserved by the payment gateway for its internally-minted keys.
Replay semantics:
- Same key + same request body → Cresora returns the cached
response from the original call. Response includes header
X-Idempotent-Replay: trueso the client can distinguish replays from fresh executions. Status code, body and side effects are identical to the original call. - Same key + different body →
422 idempotency_key_reused. Generate a new key and retry, or re-send the original body. - Key older than 24 hours → treated as a fresh key; no replay guarantee from beyond the window.
Retrying after an indeterminate failure. On 502 gateway_outcome_unknown the transaction is recorded as pending and
the outcome is not yet known — retry with the SAME key (a fresh key
risks a double charge) or poll the transaction. This is also what a
gateway-side "an earlier request with this key is still in flight"
response surfaces as.
Do NOT reuse keys across different partners. Scope is enforced
per partner_id so the same key in partner A and partner B
is independent.
^[A-Za-z0-9._:\-]+$1 <= length <= 128Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X POST "https://example.com/partner/me/certification/prepare" \ -H "Idempotency-Key: string"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "status": "ACTIVE", "features": [ "TERMINAL" ], "created_at": "2019-08-24T14:15:22Z", "completed_at": "2019-08-24T14:15:22Z", "run_started_at": "2019-08-24T14:15:22Z", "flow_type": "INITIAL", "recertification_reason": "string", "attempt_number": 1, "supersedes_flow_id": "dcfff01b-cccd-4474-a561-eed33701839b", "baseline": { "features": [ "string" ], "check_codes": [ "string" ], "steps": [ { "step": 0, "label": "string", "total": 0 } ] }, "progress": { "total": 0, "passed": 0, "failed": 0, "waived": 0, "skipped": 0, "pending": 0, "awaiting_admin_review": 0, "percent": 0, "steps": [ { "step": 1, "label": "string", "total": 0, "resolved": 0, "failed": 0, "awaiting_admin_review": 0, "unlocked": true, "complete": true } ] }, "checks": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "category": "string", "label": "string", "tier": "AUTOMATED", "state": "PENDING", "check_code": "string", "tier_level": 1, "step": 1, "flag_group": "string", "flag_group_label": "string", "description": "string", "pass_criteria": "string", "attestation_statement": "string", "result_notes": "string", "waiver_reason": "string", "submitted_by": "string", "submitted_at": "2019-08-24T14:15:22Z", "submittable": true, "checked_by": "string", "checked_at": "2019-08-24T14:15:22Z", "last_run_at": "2019-08-24T14:15:22Z", "failure_reason": "string", "execution_logs": "string", "request_payload": "string", "retry_history": [ { "attempt": 1, "trigger": "RUN_START", "verdict": "SATISFIED", "resulting_state": "PENDING", "failure_reason": "string", "execution_logs": "string", "evaluated_at": "2019-08-24T14:15:22Z", "duration_ms": 0 } ] } ]}/partner/system-statusAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/partner/system-status"{ "components": [ { "key": "string", "label": "string", "status": "operational" } ], "overall": "operational"}