Changelog
Changelog
Release notes for the Cresora Commerce platform — API changes, breaking changes, and deprecations.
All notable changes to the Cresora Commerce platform are documented here. Breaking changes are flagged with a Breaking Change badge. Entries are grouped by month. Dated days are generated automatically from the API contract on the day a change reached it, with the endpoint's API area in bold and the contract's own summary; they list what changed, not why — there is no hand-written narrative. The three launch-era days (v1.0.0–v1.2.0) keep their original hand-written text.
September 2026
2026-09-29
- 7 × response property max length increased Breaking Change
2026-09-28
- Merchants — Added
GET /api/v1/merchants/{merchantId}/fee-eligibility— Get the merchant's fee eligibility - Merchants — Added
PUT /api/v1/merchants/{merchantId}/fee-profile— Create or update the merchant's fee profile - Transactions — Removed
GET/api/v1/surcharge/rules— Preview surcharge rules Breaking Change - 2 × new required request property Breaking Change
- 1 × response property one of added Breaking Change
- 6 × response required property removed Breaking Change
2026-09-20
- Settlement — Added
GET /api/v1/settlement/batches/{batchId}/transactions— List a settlement batch's transactions
2026-09-16
- 1 × response property became nullable Breaking Change
2026-09-04
- Settlement — Added
GET /api/v1/settlement/batches— List settlement batches - Settlement — Added
GET /api/v1/settlement/batches/{batchId}— Get settlement batch - Settlement — Added
GET /api/v1/settlement/exceptions— List reconciliation exceptions
2026-09-03
- ApiKeys — Removed
GET/api/v1/iam/api-key-scopes— List assignable API-key scopes Breaking Change - ApiKeys — Removed
GET/api/v1/iam/api-keys— List API keys Breaking Change - ApiKeys — Removed
POST/api/v1/iam/api-keys— Create API key Breaking Change - ApiKeys — Removed
DELETE/api/v1/iam/api-keys/{keyId}— Revoke API key Breaking Change - ApiKeys — Removed
GET/api/v1/iam/api-keys/{keyId}— Get API key Breaking Change - ApiKeys — Removed
PATCH/api/v1/iam/api-keys/{keyId}— Update API key scopes Breaking Change - ApiKeys — Removed
POST/api/v1/iam/api-keys/{keyId}/rotate— Rotate API key Breaking Change - Certification — Removed
POST/api/v1/certification/checks/{checkId}/fail— Mark certification check failed Breaking Change - Certification — Removed
POST/api/v1/certification/checks/{checkId}/pass— Mark certification check passed Breaking Change - Certification — Removed
POST/api/v1/certification/checks/{checkId}/waive— Waive certification check Breaking Change - Certification — Removed
POST/api/v1/certification/flows— Begin certification flow Breaking Change - Certification — Removed
POST/api/v1/partner/me/certification/recertification-requests— Request a delta re-certification of the certified scope Breaking Change - Notifications — Removed
GET/api/v1/notifications— List the calling user's notification feed Breaking Change - Notifications — Removed
POST/api/v1/notifications/{notificationId}/read— Mark one notification as read Breaking Change - Notifications — Removed
GET/api/v1/notifications/categories— List notification categories Breaking Change - Notifications — Removed
POST/api/v1/notifications/read-all— Mark every notification in the calling user's feed as read Breaking Change - Partners — Removed
GET/api/v1/partner/action-items— Get the authenticated partner's action-required items Breaking Change - Partners — Removed
GET/api/v1/partner/audit-log— List the authenticated partner's audit-log entries Breaking Change - Partners — Removed
GET/api/v1/partner/dashboard/summary— Get the authenticated partner's dashboard summary Breaking Change - Partners — Removed
POST/api/v1/partner/me/certification/checks/{checkId}/submit— Submit a manual or attestation check for Cresora review Breaking Change - Partners — Removed
POST/api/v1/partner/me/certification/start— Start the caller's prepared certification run Breaking Change - Partners — Removed
POST/api/v1/partner/me/certification/steps/{step}/rerun— Re-run the automated checks of a certification step Breaking Change - Partners — Removed
GET/api/v1/partner/onboarding-state— Get the authenticated partner's onboarding-checklist state Breaking Change - Partners — Removed
GET/api/v1/partner/status— Get the authenticated partner's status badge inputs Breaking Change
August 2026
2026-08-27
- 2 × request property became required Breaking Change
2026-08-25
- 6 × request property max length decreased Breaking Change
- 1 × request property min length increased Breaking Change
2026-08-20
- 10 × response property max length increased Breaking Change
2026-08-17
- Certification — Added
GET /api/v1/certification/flows/latest-completed— Get the latest completed certification flow - Certification — Added
POST/api/v1/partner/me/certification/recertification-requests— Request a delta re-certification of the certified scope - Certification — Added
GET /api/v1/partner/me/certification/recertification-requests/current— Get the caller's current re-certification request
2026-08-11
- Merchants — Added
POST /api/v1/merchants/{merchantId}/envelope/resend— Resend the merchant's MPA signature envelope - 2 × request parameter enum value removed Breaking Change
2026-08-10
- HPP — Added
POST /api/v1/hpp/sessions/{sessionId}/cancel— Cancel HPP session - 5 × response property became nullable Breaking Change
- 1 × response property became optional Breaking Change
- 1 × response success status removed Breaking Change
July 2026
2026-07-30
- 2 × request property max length decreased Breaking Change
- 1 × request property min increased Breaking Change
- 2 × request property min length increased Breaking Change
2026-07-26
- Partners — Added
POST/api/v1/partner/me/certification/checks/{checkId}/submit— Submit a manual or attestation check for Cresora review - Partners — Added
POST/api/v1/partner/me/certification/start— Start the caller's prepared certification run - Partners — Added
POST/api/v1/partner/me/certification/steps/{step}/rerun— Re-run the automated checks of a certification step - 2 × request body became required Breaking Change
- 35 × request parameter min length increased Breaking Change
- 35 × request parameter pattern added Breaking Change
- 2 × request property became required Breaking Change
- 2 × request property min length increased Breaking Change
- 2 × request property pattern added Breaking Change
- 3 × response property min decreased Breaking Change
2026-07-24
- Stored credentials — Removed
POST/api/v1/merchants/{merchantId}/stored-credentials/{vaultToken}/charges— Charge a stored credential Breaking Change - 2 × new required request property Breaking Change
- 1 × request body one of removed Breaking Change
2026-07-22
- 1 × request property pattern added Breaking Change
2026-07-21
- Partners — Added
GET/api/v1/partner/action-items— Get the authenticated partner's action-required items
2026-07-18
- Customers — Added
GET /api/v1/merchants/{merchantId}/customers— List merchant customers - Customers — Added
POST /api/v1/merchants/{merchantId}/customers— Create a customer under a merchant - Customers — Added
DELETE /api/v1/merchants/{merchantId}/customers/{customerId}— Soft-delete a customer - Customers — Added
GET /api/v1/merchants/{merchantId}/customers/{customerId}— Get a customer by id - Customers — Added
PATCH /api/v1/merchants/{merchantId}/customers/{customerId}— Update mutable customer fields - Stored credentials — Added
GET /api/v1/merchants/{merchantId}/stored-credentials— List stored credentials under a merchant - Stored credentials — Added
DELETE /api/v1/merchants/{merchantId}/stored-credentials/{storedCredentialId}— Revoke a stored credential - Stored credentials — Added
GET /api/v1/merchants/{merchantId}/stored-credentials/{storedCredentialId}— Get a stored credential by id - Stored credentials — Added
POST/api/v1/merchants/{merchantId}/stored-credentials/{vaultToken}/charges(removed 2026-07-24) — Charge a stored credential - 86 × request property enum value removed Breaking Change
- 2 × request property pattern added Breaking Change
2026-07-15
- 8 × request property min length increased Breaking Change
2026-07-13
- Custom Fields — Added
GET /api/v1/config/custom-fields/configs— List the partner's merchant custom-field configs - Custom Fields — Added
DELETE /api/v1/config/custom-fields/merchants/{merchantId}— Delete a merchant's custom-field definitions - Custom Fields — Added
GET /api/v1/config/custom-fields/merchants/{merchantId}— Get a merchant's custom-field definitions - Custom Fields — Added
PUT /api/v1/config/custom-fields/merchants/{merchantId}— Create or replace a merchant's custom-field definitions
2026-07-09
- Config — Added
GET /api/v1/config/feature-flags/me— List the features granted to the calling partner - Config — Added
PUT /api/v1/config/feature-flags/me/{flagName}— Set the calling partner's on/off for a granted feature
2026-07-08
- Merchants — Added
GET /api/v1/merchants/{merchantId}/fee-settings— Get merchant fee settings - Merchants — Added
PUT /api/v1/merchants/{merchantId}/fee-settings/convenience-fee— Create or update the merchant's convenience-fee program - Merchants — Added
PUT /api/v1/merchants/{merchantId}/fee-settings/surcharge— Create or update the merchant's surcharge program
2026-07-06
- 19 × response required property removed Breaking Change
2026-07-04
- Config — Removed
DELETE/api/v1/config/feature-flags/{flagName}/partners/{partnerId}— Remove a partner-level feature flag override Breaking Change - Config — Removed
PUT/api/v1/config/feature-flags/{flagName}/partners/{partnerId}— Set a partner-level feature flag override Breaking Change - Partners — Added
POST /api/v1/partner/me/certification/prepare— Prepare the caller's certification flow - Partners — Removed
PATCH/api/v1/partner/me/feature-selection— Save the authenticated partner's feature selection Breaking Change - 1 × response required property removed Breaking Change
June 2026
2026-06-30
- 1 × request property became enum Breaking Change
2026-06-26
- Config — Added
PUT /api/v1/config/hpp-page/merchants/{merchantId}/embedding-domains— Replace a merchant's HPP iframe embedding allow-list - Config — Added
POST /api/v1/config/hpp-page/merchants/{merchantId}/embedding-domains/add— Add to a merchant's HPP iframe embedding allow-list (additive) - HPP — Removed
PUT/api/v1/hpp/embedding-domains— Register HPP embedding domains Breaking Change - Partners — Added
GET/api/v1/partner/audit-log— List the authenticated partner's audit-log entries
2026-06-24
- ApiKeys — Added
PATCH/api/v1/iam/api-keys/{keyId}— Update API key scopes - 1 × response required property removed Breaking Change
2026-06-23
- Webhooks — Added
GET /api/v1/webhook-metadata— Webhook metadata — retry policy + per-event-type limit
2026-06-21
- ApiKeys — Added
GET/api/v1/iam/api-key-scopes— List assignable API-key scopes - Config — Added
GET /api/v1/config/us-states— List US states - Merchants — Added
GET /api/v1/onboarding/saq-types— List PCI SAQ types - Notifications — Added
GET/api/v1/notifications/categories— List notification categories - Partners — Added
GET /api/v1/partner/system-status— Get platform system status - Webhooks — Added
GET /api/v1/webhook-event-types— List subscribable webhook event types
2026-06-19
- Config — Added
GET /api/v1/config/mcc-catalog— List the curated MCC catalog - 24 × request property enum value removed Breaking Change
- 2 × webhook removed Breaking Change
2026-06-16
- Config — Added
GET /api/v1/config/hpp-page— Get the effective hosted-payment-page appearance config - Config — Added
PUT /api/v1/config/hpp-page— Create or replace the partner-level HPP template - Config — Added
GET /api/v1/config/hpp-page/configs— List the partner's HPP configs - Config — Added
DELETE /api/v1/config/hpp-page/merchants/{merchantId}— Delete a per-merchant HPP override - Config — Added
PUT /api/v1/config/hpp-page/merchants/{merchantId}— Create or replace a per-merchant HPP override - Merchants — Added
GET /api/v1/merchants/{merchantId}/bank-verification— Get the settlement bank-account verification status - Merchants — Added
POST /api/v1/merchants/{merchantId}/bank-verification/check— Poll the provider and refresh the bank-verification status
2026-06-15
- Merchants — Added
GET /api/v1/merchants/{merchantId}/application— Get a merchant's application sections 2–5 (PII masked) - Merchants — Added
GET /api/v1/merchants/{merchantId}/compliance-documents— List own merchant's compliance documents (metadata only) - Merchants — Added
POST /api/v1/merchants/{merchantId}/compliance-documents— Upload a compliance document (encrypted at rest) - Merchants — Added
GET /api/v1/merchants/{merchantId}/compliance/baa-template— Download the HIPAA BAA template to sign - Merchants — Added
POST /api/v1/merchants/{merchantId}/compliance/saq-type— Record the SAQ type determined by the SAQ wizard - Merchants — Added
GET /api/v1/merchants/{merchantId}/go-live-gate— Get a merchant's go-live gate status - Merchants — Added
POST /api/v1/merchants/{merchantId}/respond-clarification— Respond to a clarification request - Merchants — Added
POST /api/v1/merchants/{merchantId}/resubmit— Resubmit a rejected merchant for review
2026-06-13
- Transactions — Added
GET /api/v1/transactions/export— Export transactions as CSV - Transactions — Added
GET /api/v1/transactions/summary— Transaction KPI summary - 2 × response property type changed Breaking Change
- 1 × response required property removed Breaking Change
2026-06-12
- 3 × response property became nullable Breaking Change
2026-06-11
- ApiKeys — Moved
GET/api/v1/api-keys→GET/api/v1/iam/api-keys— List API keys Breaking Change - ApiKeys — Moved
POST/api/v1/api-keys→POST/api/v1/iam/api-keys— Create API key Breaking Change - ApiKeys — Added
GET/api/v1/iam/api-keys/{keyId}— Get API key - ApiKeys — Moved
DELETE/api/v1/api-keys/{keyId}→DELETE/api/v1/iam/api-keys/{keyId}— Revoke API key Breaking Change - ApiKeys — Added
POST/api/v1/iam/api-keys/{keyId}/rotate— Rotate API key - Certification — Removed
GET/api/v1/certification/checks— List certification checks Breaking Change - Certification — Removed
POST/api/v1/certification/checks— Request certification check Breaking Change - Certification — Removed
GET/api/v1/certification/checks/{checkId}— Get certification check Breaking Change - Certification — Added
POST/api/v1/certification/checks/{checkId}/fail— Mark certification check failed - Certification — Added
POST/api/v1/certification/checks/{checkId}/pass— Mark certification check passed - Certification — Added
POST/api/v1/certification/checks/{checkId}/waive— Waive certification check - Certification — Added
POST/api/v1/certification/flows— Begin certification flow - Certification — Added
GET /api/v1/certification/flows/{flowId}— Get certification flow - Certification — Added
GET /api/v1/certification/flows/active— Get the active certification flow - Merchants — Added
PATCH /api/v1/merchants/{merchantId}— Update merchant (DRAFT only) - Merchants — Removed
PUT/api/v1/merchants/{merchantId}— Update merchant (DRAFT only) Breaking Change - Merchants — Removed
POST/api/v1/merchants/{merchantId}/close— Close merchant Breaking Change - Merchants — Added
GET /api/v1/merchants/{merchantId}/locations— List merchant locations - Merchants — Added
POST /api/v1/merchants/{merchantId}/locations— Create merchant location - Merchants — Added
DELETE /api/v1/merchants/{merchantId}/locations/{locationId}— Delete merchant location - Merchants — Added
GET /api/v1/merchants/{merchantId}/locations/{locationId}— Get merchant location - Merchants — Added
PATCH /api/v1/merchants/{merchantId}/locations/{locationId}— Update merchant location - Merchants — Added
GET /api/v1/merchants/{merchantId}/transitions— Get merchant state-transition history - Notifications — Added
GET/api/v1/notifications— List the calling user's notification feed - Notifications — Added
POST/api/v1/notifications/{notificationId}/read— Mark one notification as read - Notifications — Added
POST/api/v1/notifications/read-all— Mark every notification in the calling user's feed as read - Partners — Added
PATCH/api/v1/partner/me/feature-selection(removed 2026-07-04) — Save the authenticated partner's feature selection - Recurring — Added
GET /api/v1/contracts— List recurring contracts - Recurring — Added
POST /api/v1/contracts— Create recurring contract - Recurring — Added
GET /api/v1/contracts/{contractId}— Get recurring contract - Recurring — Added
PATCH /api/v1/contracts/{contractId}— Update recurring contract (limited fields) - Recurring — Added
POST /api/v1/contracts/{contractId}/cancel— Cancel recurring contract - Recurring — Added
POST /api/v1/contracts/{contractId}/retry— Retry failed recurring charge - Recurring — Removed
GET/api/v1/recurring/plans— List recurring plans Breaking Change - Recurring — Removed
POST/api/v1/recurring/plans— Enroll recurring plan Breaking Change - Recurring — Removed
DELETE/api/v1/recurring/plans/{planId}— Cancel recurring plan Breaking Change - Recurring — Removed
GET/api/v1/recurring/plans/{planId}— Get recurring plan Breaking Change - Recurring — Removed
PATCH/api/v1/recurring/plans/{planId}— Update recurring plan Breaking Change - Recurring — Removed
POST/api/v1/recurring/plans/{planId}/retry— Retry failed recurring charge manually Breaking Change - Terminals — Removed
GET/api/v1/terminals— List terminals Breaking Change - Terminals — Removed
POST/api/v1/terminals— Register terminal Breaking Change - Terminals — Removed
GET/api/v1/terminals/{terminalId}— Get terminal Breaking Change - Terminals — Removed
POST/api/v1/terminals/{terminalId}/provision— Provision terminal Breaking Change - Terminals — Removed
POST/api/v1/terminals/{terminalId}/reactivate— Reactivate suspended terminal Breaking Change - Terminals — Removed
POST/api/v1/terminals/{terminalId}/rotate-api-key— Rotate terminal API key Breaking Change - Terminals — Removed
POST/api/v1/terminals/{terminalId}/suspend— Suspend terminal Breaking Change - Transactions — Added
POST /api/v1/transactions— Create transaction (polymorphic — all card + ACH operations) - Transactions — Removed
POST/api/v1/transactions/{transactionId}/ach-reverse— Reverse ACH transaction (NACHA 5-day window) Breaking Change - Transactions — Removed
POST/api/v1/transactions/{transactionId}/capture— Capture authorized transaction Breaking Change - Transactions — Removed
POST/api/v1/transactions/{transactionId}/refund— Refund transaction (full or partial) Breaking Change - Transactions — Removed
POST/api/v1/transactions/{transactionId}/reverse— Reverse authorization Breaking Change - Transactions — Removed
POST/api/v1/transactions/{transactionId}/void— Void transaction Breaking Change - Transactions — Removed
POST/api/v1/transactions/batch-close— Close current settlement batch Breaking Change - Transactions — Removed
POST/api/v1/transactions/sale— Process sale Breaking Change - Transactions — Removed
POST/api/v1/transactions/verify— Verify card ($0 auth) Breaking Change - 1 × response property became nullable Breaking Change
- 1 × response property type changed Breaking Change
- 6 × response required property removed Breaking Change
- 1 × response success status removed Breaking Change
2026-06-08
- HPP — Added
PUT/api/v1/hpp/embedding-domains(removed 2026-06-26) — Register HPP embedding domains
2026-06-07
- 1 × new required request property Breaking Change
- 1 × request property max length decreased Breaking Change
May 2026
2026-05-27
- 6 × response property max length increased Breaking Change
2026-05-26
- Partners — Added
GET/api/v1/partner/dashboard/summary— Get the authenticated partner's dashboard summary - Partners — Added
GET /api/v1/partner/me— Get the authenticated caller's partner - Partners — Added
GET/api/v1/partner/onboarding-state— Get the authenticated partner's onboarding-checklist state - Partners — Added
GET/api/v1/partner/status— Get the authenticated partner's status badge inputs - Webhooks — Added
POST /api/v1/webhook-subscriptions/{subscriptionId}/test-delivery— Send a synchronous test event to the subscription URL
2026-05-25
- Config — Added
DELETE/api/v1/config/feature-flags/{flagName}/partners/{partnerId}(removed 2026-07-04) — Remove a partner-level feature flag override - Config — Added
PUT/api/v1/config/feature-flags/{flagName}/partners/{partnerId}(removed 2026-07-04) — Set a partner-level feature flag override - Config — Added
GET /api/v1/config/partners/{partnerId}— Get partner configuration - Config — Added
PUT /api/v1/config/partners/{partnerId}— Create or replace partner configuration - 3 × new required request default parameter to existing path Breaking Change
- 4 × new required request parameter Breaking Change
- 269 × response property became optional Breaking Change
- 538 × response required property removed Breaking Change
- 1 × webhook removed Breaking Change
2026-05-24
- Webhooks — Moved
GET/api/v1/webhooks/subscriptions→GET /api/v1/webhook-subscriptions— List webhook subscriptions Breaking Change - Webhooks — Moved
POST/api/v1/webhooks/subscriptions→POST /api/v1/webhook-subscriptions— Create webhook subscription Breaking Change - Webhooks — Moved
DELETE/api/v1/webhooks/subscriptions/{subscriptionId}→DELETE /api/v1/webhook-subscriptions/{subscriptionId}— Delete webhook subscription Breaking Change - Webhooks — Moved
GET/api/v1/webhooks/subscriptions/{subscriptionId}→GET /api/v1/webhook-subscriptions/{subscriptionId}— Get webhook subscription Breaking Change - Webhooks — Moved
PATCH/api/v1/webhooks/subscriptions/{subscriptionId}→PATCH /api/v1/webhook-subscriptions/{subscriptionId}— Update webhook subscription Breaking Change - Webhooks — Added
GET /api/v1/webhook-subscriptions/{subscriptionId}/deliveries— List webhook delivery history - Webhooks — Added
POST /api/v1/webhook-subscriptions/{subscriptionId}/deliveries/{eventId}/redeliver— Redeliver a historical webhook event - Webhooks — Moved
POST/api/v1/webhooks/subscriptions/{subscriptionId}/rotate-secret→POST /api/v1/webhook-subscriptions/{subscriptionId}/rotate-secret— Rotate HMAC secret Breaking Change
2026-05-21
- Transactions — Added
POST/api/v1/transactions/verify(removed 2026-06-11) — Verify card ($0 auth) - 1 × new required request property Breaking Change
- 9 × response property one of added Breaking Change
2026-05-20
- 1 × request parameter enum value removed Breaking Change
- 6 × request property enum value removed Breaking Change
2026-05-15 — v1.2.0: ACH recurring billing — Reg E re-notification support (never shipped)
ACH recurring billing — Reg E re-notification support Planned
- This entry announced a capability that never shipped. No re-notification webhook exists and none is sent. Sending the Reg E re-notification is the integrator's responsibility. See NACHA compliance and Recurring billing.
- Added NACHA Regulation E re-notification support for recurring ACH plans. Cresora now sends re-notification webhooks at the required intervals before charging a recurring ACH plan where the original authorization was not date-specific. (No such support was ever added and no re-notification is sent — corrected 2026-09-07.)
- New webhook event:
ach.renotification_required— fires when Cresora determines that re-notification is required before the next recurring charge. (No such event exists and nothing emits it — corrected 2026-09-07.) - No breaking changes. Existing recurring ACH integrations will begin receiving the new event automatically. (No event is delivered — corrected 2026-09-07.)
2026-05-04
- Compliance — Removed
GET/api/v1/compliance/documents— List compliance documents Breaking Change - Compliance — Removed
POST/api/v1/compliance/documents— Upload compliance document Breaking Change - Migration — Removed
GET/api/v1/migration/jobs— List migration jobs Breaking Change - Migration — Removed
POST/api/v1/migration/jobs— Start migration job Breaking Change - Migration — Removed
GET/api/v1/migration/jobs/{jobId}— Get migration job status Breaking Change - Migration — Removed
POST/api/v1/migration/jobs/{jobId}/pause— Pause migration job Breaking Change - Migration — Removed
POST/api/v1/migration/jobs/{jobId}/resume— Resume migration job Breaking Change - Settlement — Removed
GET/api/v1/settlement/batches— List settlement batches Breaking Change - Settlement — Removed
GET/api/v1/settlement/batches/{batchId}— Get batch details Breaking Change - Settlement — Removed
GET/api/v1/settlement/exceptions— List reconciliation exceptions Breaking Change - 1 × request parameter enum value removed Breaking Change
April 2026
2026-04-24
- ApiKeys — Added
GET/api/v1/api-keys(removed 2026-06-11) — List API keys - ApiKeys — Added
POST/api/v1/api-keys(removed 2026-06-11) — Create API key - ApiKeys — Added
DELETE/api/v1/api-keys/{keyId}(removed 2026-06-11) — Revoke API key - Capabilities — Added
GET /api/v1/capabilities— Get partner capabilities - Certification — Added
GET/api/v1/certification/checks(removed 2026-06-11) — List certification checks - Certification — Added
POST/api/v1/certification/checks(removed 2026-06-11) — Request certification check - Certification — Added
GET/api/v1/certification/checks/{checkId}(removed 2026-06-11) — Get certification check - Compliance — Added
GET/api/v1/compliance/documents(removed 2026-05-04) — List compliance documents - Compliance — Added
POST/api/v1/compliance/documents(removed 2026-05-04) — Upload compliance document - Health — Added
GET /api/v1/health— Health probe - HPP — Added
POST /api/v1/hpp/sessions— Create HPP session - HPP — Added
GET /api/v1/hpp/sessions/{sessionId}— Get HPP session status - Merchants — Added
GET /api/v1/merchants— List merchants - Merchants — Added
POST /api/v1/merchants— Create merchant (DRAFT) - Merchants — Added
GET /api/v1/merchants/{merchantId}— Get merchant - Merchants — Added
PUT/api/v1/merchants/{merchantId}(removed 2026-06-11) — Update merchant (DRAFT only) - Merchants — Added
POST/api/v1/merchants/{merchantId}/close(removed 2026-06-11) — Close merchant - Merchants — Added
POST /api/v1/merchants/{merchantId}/submit— Submit merchant for review - Migration — Added
GET/api/v1/migration/jobs(removed 2026-05-04) — List migration jobs - Migration — Added
POST/api/v1/migration/jobs(removed 2026-05-04) — Start migration job - Migration — Added
GET/api/v1/migration/jobs/{jobId}(removed 2026-05-04) — Get migration job status - Migration — Added
POST/api/v1/migration/jobs/{jobId}/pause(removed 2026-05-04) — Pause migration job - Migration — Added
POST/api/v1/migration/jobs/{jobId}/resume(removed 2026-05-04) — Resume migration job - Recurring — Added
GET/api/v1/recurring/plans(removed 2026-06-11) — List recurring plans - Recurring — Added
POST/api/v1/recurring/plans(removed 2026-06-11) — Enroll recurring plan - Recurring — Added
DELETE/api/v1/recurring/plans/{planId}(removed 2026-06-11) — Cancel recurring plan - Recurring — Added
GET/api/v1/recurring/plans/{planId}(removed 2026-06-11) — Get recurring plan - Recurring — Added
PATCH/api/v1/recurring/plans/{planId}(removed 2026-06-11) — Update recurring plan - Recurring — Added
POST/api/v1/recurring/plans/{planId}/retry(removed 2026-06-11) — Retry failed recurring charge manually - Settlement — Added
GET/api/v1/settlement/batches(removed 2026-05-04) — List settlement batches - Settlement — Added
GET/api/v1/settlement/batches/{batchId}(removed 2026-05-04) — Get batch details - Settlement — Added
GET/api/v1/settlement/exceptions(removed 2026-05-04) — List reconciliation exceptions - Terminals — Added
GET/api/v1/terminals(removed 2026-06-11) — List terminals - Terminals — Added
POST/api/v1/terminals(removed 2026-06-11) — Register terminal - Terminals — Added
GET/api/v1/terminals/{terminalId}(removed 2026-06-11) — Get terminal - Terminals — Added
POST/api/v1/terminals/{terminalId}/provision(removed 2026-06-11) — Provision terminal - Terminals — Added
POST/api/v1/terminals/{terminalId}/reactivate(removed 2026-06-11) — Reactivate suspended terminal - Terminals — Added
POST/api/v1/terminals/{terminalId}/rotate-api-key(removed 2026-06-11) — Rotate terminal API key - Terminals — Added
POST/api/v1/terminals/{terminalId}/suspend(removed 2026-06-11) — Suspend terminal - Transactions — Added
GET/api/v1/surcharge/rules(removed 2026-09-28) — Preview surcharge rules - Transactions — Added
GET /api/v1/transactions— List transactions - Transactions — Added
GET /api/v1/transactions/{transactionId}— Get transaction - Transactions — Added
POST/api/v1/transactions/{transactionId}/ach-reverse(removed 2026-06-11) — Reverse ACH transaction (NACHA 5-day window) - Transactions — Added
POST/api/v1/transactions/{transactionId}/capture(removed 2026-06-11) — Capture authorized transaction - Transactions — Added
POST/api/v1/transactions/{transactionId}/refund(removed 2026-06-11) — Refund transaction (full or partial) - Transactions — Added
POST/api/v1/transactions/{transactionId}/reverse(removed 2026-06-11) — Reverse authorization - Transactions — Added
POST /api/v1/transactions/{transactionId}/three-ds/complete— Complete 3DS2 challenge - Transactions — Added
POST/api/v1/transactions/{transactionId}/void(removed 2026-06-11) — Void transaction - Transactions — Added
POST/api/v1/transactions/batch-close(removed 2026-06-11) — Close current settlement batch - Transactions — Added
POST/api/v1/transactions/sale(removed 2026-06-11) — Process sale - Webhooks — Added
GET/api/v1/webhooks/subscriptions(removed 2026-05-24) — List webhook subscriptions - Webhooks — Added
POST/api/v1/webhooks/subscriptions(removed 2026-05-24) — Create webhook subscription - Webhooks — Added
DELETE/api/v1/webhooks/subscriptions/{subscriptionId}(removed 2026-05-24) — Delete webhook subscription - Webhooks — Added
GET/api/v1/webhooks/subscriptions/{subscriptionId}(removed 2026-05-24) — Get webhook subscription - Webhooks — Added
PATCH/api/v1/webhooks/subscriptions/{subscriptionId}(removed 2026-05-24) — Update webhook subscription - Webhooks — Added
POST/api/v1/webhooks/subscriptions/{subscriptionId}/rotate-secret(removed 2026-05-24) — Rotate HMAC secret
2026-04-10 — v1.1.0: HPP white-label branding (Preview)
HPP white-label branding (Preview) Preview
- Hosted Payment Page branding — logo, custom CSS and button text — is configured per hosted page in the Partner Portal. (This entry originally described the capability as gated by an
hpp_whitelabelfeature flag; no such flag exists — corrected 2026-08-31.) - New endpoint:
POST /api/v1/hpp/sessions— see API Reference. (This entry originally announced a/v1/payments/…path that never existed — corrected 2026-08-12.)
March 2026
2026-03-01 — v1.0.0: Platform launch
Platform launch Stable
Initial release of the Cresora Commerce platform:
- Card payments (authorization, capture, void, refund)
- ACH debit payments and returns
- Hosted Payment Page (HPP) integration
- Recurring billing plans
- Webhooks with HMAC-SHA256 verification
- 3DS2 support
- Partner Portal (merchant management, payments operations, reporting)