Skip to main content
Cresora Commerce

Stored credentials

The tokenization vault — cards a merchant has stored for reuse. Entries are minted at a hosted-page (HPP) establishing completion, not created directly; ISVs list, inspect, and revoke them, and charge a stored card by passing its opaque vault token as the payment instrument on `POST /transactions` (`stored_credential:read` / `:revoke`). The stored-credential (MIT/COF) reuse program has been always-on since its 2026-07-18 de-gate — there is no dedicated charge endpoint and no feature gate on this surface.

ℹServer-to-server API
Run the examples on this page from your backend against the sandbox host. The API sends no CORS headers, so browser JavaScript cannot read its responses, and an API key must never be exposed in a browser. There is no interactive console here. Generating a client instead? Download the OpenAPI spec (YAML).
GET/merchants/{merchantId}/stored-credentials

Authorization

BearerAuth
AuthorizationBearer <token>

Cresora API key, sent as an opaque bearer token in the Authorization header. Format:

csk_<prefix>_<random>
  • <prefix> — 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g. csk_Ab3kX9mQ…). Use ApiKey.prefix to match.
  • <random> — 24+ cryptographically random URL-safe chars.

Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.

In: header

Path Parameters

merchantId*string
Formatuuid

Query Parameters

customer_id?string

Optional filter to one customer's stored credentials.

Formatuuid
cursor?string

Opaque pagination cursor from previous response. Do not parse.

Lengthlength <= 256
page_size?integer

Items per page (1–100).

Range1 <= value <= 100
Default25

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X GET "https://example.com/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08/stored-credentials"
{  "data": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "vault_token": "string",      "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea",      "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06",      "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e",      "processor": "string",      "rail": "CARD",      "card": {        "brand": "string",        "last4": "string",        "exp_month": 1,        "exp_year": 0      },      "bank": {        "account_type": "CHECKING",        "account_last4": "string",        "routing_last4": "string",        "name_on_account": "string"      },      "scope": [        "RECURRING"      ],      "enrollment_terms": {        "amount": "string",        "frequency": "string",        "duration": "string"      },      "consent_captured": true,      "state": "ACTIVE",      "created_at": "2019-08-24T14:15:22Z",      "version": 0    }  ],  "pagination": {    "next_cursor": "string",    "has_more": true,    "total_count": 0  }}
GET/merchants/{merchantId}/stored-credentials/{storedCredentialId}

Authorization

BearerAuth
AuthorizationBearer <token>

Cresora API key, sent as an opaque bearer token in the Authorization header. Format:

csk_<prefix>_<random>
  • <prefix> — 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g. csk_Ab3kX9mQ…). Use ApiKey.prefix to match.
  • <random> — 24+ cryptographically random URL-safe chars.

Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.

In: header

Path Parameters

merchantId*string
Formatuuid
storedCredentialId*string
Formatuuid

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X GET "https://example.com/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08/stored-credentials/497f6eca-6276-4993-bfeb-53cbbbba6f08"
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "vault_token": "string",  "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea",  "partner_id": "6a3a39f6-861b-4a48-b868-5de838400e06",  "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e",  "processor": "string",  "rail": "CARD",  "card": {    "brand": "string",    "last4": "string",    "exp_month": 1,    "exp_year": 0  },  "bank": {    "account_type": "CHECKING",    "account_last4": "string",    "routing_last4": "string",    "name_on_account": "string"  },  "scope": [    "RECURRING"  ],  "enrollment_terms": {    "amount": "string",    "frequency": "string",    "duration": "string"  },  "consent_captured": true,  "state": "ACTIVE",  "created_at": "2019-08-24T14:15:22Z",  "version": 0}
DELETE/merchants/{merchantId}/stored-credentials/{storedCredentialId}

Authorization

BearerAuth
AuthorizationBearer <token>

Cresora API key, sent as an opaque bearer token in the Authorization header. Format:

csk_<prefix>_<random>
  • <prefix> — 8 URL-safe chars, shown in UI and logs for identification without revealing the full key (e.g. csk_Ab3kX9mQ…). Use ApiKey.prefix to match.
  • <random> — 24+ cryptographically random URL-safe chars.

Obtain via Partner Portal → Settings → API keys. Keys are only shown in full at creation/rotation time — Cresora does not retain the full value in retrievable form. Rotate any key that may have been exposed via logs, client code, or source control.

In: header

Path Parameters

merchantId*string
Formatuuid
storedCredentialId*string
Formatuuid

Query Parameters

reason?string

Optional free-text revocation reason (recorded in the audit trail).

Lengthlength <= 500

Response Body

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X DELETE "https://example.com/merchants/497f6eca-6276-4993-bfeb-53cbbbba6f08/stored-credentials/497f6eca-6276-4993-bfeb-53cbbbba6f08"
Empty