Settlement
Settlement batches and reconciliation exceptions — the read surface of the two-state settlement contract. A batch is `gateway_reported` while Cresora holds only the gateway's per-transaction settled webhooks, and `report_verified` once the processor's settlement report has been ingested and its control totals verified. Exceptions are the mismatches that verification (or the settlement-window sweep) raised. Read-only for partners; resolution is a Cresora Operations action.
/settlement/batchesAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Query Parameters
Opaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Narrows to this merchant's batches. A malformed or blank value is rejected with 400 — never answered with the unfiltered list.
uuidUnknown values are rejected with 400 (typed binding).
Value in
- "PENDING"
- "RECONCILING"
- "RECONCILED"
- "EXCEPTION"
- "CLOSED_WITH_EXCEPTIONS"
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/batches"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "state": "PENDING", "reporting_basis": "gateway_reported", "processing_account": { "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "processor_key": "string" }, "vendor_status": "string", "gateway_batch_id": "string", "processor_batch_id": "string", "closed_settlement_batch_id": "string", "vendor_settlement_batch_id": "string", "transaction_count": 0, "total_amount": "string", "fees": "string", "net_amount": "string", "expected_settled_count": 0, "observed_member_count": 0, "observed_member_amount": "string", "run_date_utc": "2019-08-24T14:15:22Z", "completed_at_utc": "2019-08-24T14:15:22Z", "trigger_type": "string", "settlement_date": "2019-08-24", "expected_by": "2019-08-24T14:15:22Z", "held_reason": "string", "reconciled_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z" } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}/settlement/batches/{batchId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/batches/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "state": "PENDING", "reporting_basis": "gateway_reported", "processing_account": { "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "processor_key": "string" }, "vendor_status": "string", "gateway_batch_id": "string", "processor_batch_id": "string", "closed_settlement_batch_id": "string", "vendor_settlement_batch_id": "string", "transaction_count": 0, "total_amount": "string", "fees": "string", "net_amount": "string", "expected_settled_count": 0, "observed_member_count": 0, "observed_member_amount": "string", "run_date_utc": "2019-08-24T14:15:22Z", "completed_at_utc": "2019-08-24T14:15:22Z", "trigger_type": "string", "settlement_date": "2019-08-24", "expected_by": "2019-08-24T14:15:22Z", "held_reason": "string", "reconciled_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z"}/settlement/batches/{batchId}/transactionsAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuidQuery Parameters
Opaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/batches/497f6eca-6276-4993-bfeb-53cbbbba6f08/transactions"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "transaction_id": "0fec1e58-b197-4052-99cf-2218496c5482", "gateway_transaction_id": "string", "rail": "CARD", "amount": "string", "settled_at": "2019-08-24T14:15:22Z", "match_state": "RECORDED" } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}/settlement/exceptionsAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Query Parameters
Opaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Narrows to exceptions attributed to this merchant. A malformed or blank value is rejected with 400 — never answered with the unfiltered list.
uuidUnknown values are rejected with 400 (typed binding).
Value in
- "OPEN"
- "AUTO_RESOLVED"
- "MANUAL_RESOLVED"
- "WRITTEN_OFF"
- "ESCALATED"
Unknown values are rejected with 400 (typed binding).
Value in
- "MISSING_TRANSACTION"
- "EXTRA_TRANSACTION"
- "DUPLICATE_TRANSACTION"
- "AMOUNT_MISMATCH"
- "UNSETTLED_TRANSACTION"
- "FEE_MISMATCH"
- "BATCH_TOTAL_MISMATCH"
- "UNMATCHED_PLATFORM"
- "MISSING_BATCH"
- "LATE_PRESENTMENT"
- "CAPTURED_AMOUNT_MISMATCH"
- "ASSESSED_SURCHARGE_MISMATCH"
- "SURCHARGE_REVERSAL_MISMATCH"
Narrows to exceptions ranked at this severity. Unknown values are rejected with 400 (typed binding) — never answered with the unfiltered list. An exception with no severity (null) matches no value of this filter.
Value in
- "LOW"
- "MEDIUM"
- "HIGH"
- "CRITICAL"
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/settlement/exceptions"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "batch_id": "4da22c97-b7d5-4e31-8c3a-03870ebc7b20", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "transaction_id": "0fec1e58-b197-4052-99cf-2218496c5482", "type": "MISSING_TRANSACTION", "state": "OPEN", "severity": "LOW", "description": "string", "expected_by": "2019-08-24T14:15:22Z", "observed_at": "2019-08-24T14:15:22Z", "resolved_by": "operator", "resolved_at": "2019-08-24T14:15:22Z", "resolution": "string", "created_at": "2019-08-24T14:15:22Z" } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}Customers
Payer customers under a merchant. A customer owns the merchant's stored payment methods (the tokenization vault). Partner self-service (`customer:read` / `customer:write`); the merchant is the path scope and the partner is scoped from your API key.
Stored credentials
The tokenization vault — cards a merchant has stored for reuse. Entries are minted at a hosted-page (HPP) establishing completion, not created directly; ISVs list, inspect, and revoke them, and charge a stored card by passing its opaque vault token as the payment instrument on `POST /transactions` (`stored_credential:read` / `:revoke`). The stored-credential (MIT/COF) reuse program has been always-on since its 2026-07-18 de-gate — there is no dedicated charge endpoint and no feature gate on this surface.