Stored credentials
The tokenization vault — cards a merchant has stored for reuse. Entries are minted at a hosted-page (HPP) establishing completion, not created directly; ISVs list, inspect, and revoke them, and charge a stored card by passing its opaque vault token as the payment instrument on `POST /transactions` (`stored_credential:read` / `:revoke`). The stored-credential (MIT/COF) reuse program has been always-on since its 2026-07-18 de-gate — there is no dedicated charge endpoint and no feature gate on this surface.
/merchants/{merchantId}/stored-credentialsAuthorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuidQuery Parameters
Optional filter to one customer's stored credentials.
uuidOpaque pagination cursor from previous response. Do not parse.
length <= 256Items per page (1–100).
1 <= value <= 10025Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08/stored-credentials"{ "data": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "vault_token": "string", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e", "processor": "string", "rail": "CARD", "card": { "brand": "string", "last4": "string", "exp_month": 1, "exp_year": 0 }, "bank": { "account_type": "CHECKING", "account_last4": "string", "routing_last4": "string", "name_on_account": "string" }, "scope": [ "RECURRING" ], "enrollment_terms": { "amount": "string", "frequency": "string", "duration": "string" }, "consent_captured": true, "state": "ACTIVE", "created_at": "2019-08-24T14:15:22Z", "version": 0 } ], "pagination": { "next_cursor": "string", "has_more": true, "total_count": 0 }}/merchants/{merchantId}/stored-credentials/{storedCredentialId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuiduuidResponse Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08/stored-credentials/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "vault_token": "string", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06", "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e", "processor": "string", "rail": "CARD", "card": { "brand": "string", "last4": "string", "exp_month": 1, "exp_year": 0 }, "bank": { "account_type": "CHECKING", "account_last4": "string", "routing_last4": "string", "name_on_account": "string" }, "scope": [ "RECURRING" ], "enrollment_terms": { "amount": "string", "frequency": "string", "duration": "string" }, "consent_captured": true, "state": "ACTIVE", "created_at": "2019-08-24T14:15:22Z", "version": 0}/merchants/{merchantId}/stored-credentials/{storedCredentialId}Authorization
BearerAuth Cresora API key, sent as an opaque bearer token in the
Authorization header. Format:
csk_<prefix>_<random><prefix>— 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g.csk_Ab3kX9mQ…). UseApiKey.prefixto match.<random>— 24+ cryptographically random URL-safe chars.
Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.
In: header
Path Parameters
uuiduuidQuery Parameters
Optional free-text revocation reason (recorded in the audit trail).
length <= 500Response Body
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X DELETE "https://example.com/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08/stored-credentials/497f6eca-6276-4993-bfeb-53cbbbba6f08"