Skip to main content
Cresora Commerce
Changelog

Changelog

Release notes for the Cresora Commerce platform — API changes, breaking changes, and deprecations.

All notable changes to the Cresora Commerce platform are documented here. Breaking changes are flagged with a Breaking Change badge. Entries are grouped by month. Dated days are generated automatically from the API contract on the day a change reached it, with the endpoint's API area in bold and the contract's own summary; they list what changed, not why — there is no hand-written narrative. The three launch-era days (v1.0.0–v1.2.0) keep their original hand-written text.


September 2026

2026-09-29

  • 7 × response property max length increased Breaking Change

2026-09-28

  • Merchants — Added GET /api/v1/merchants/{merchantId}/fee-eligibility — Get the merchant's fee eligibility
  • Merchants — Added PUT /api/v1/merchants/{merchantId}/fee-profile — Create or update the merchant's fee profile
  • Transactions — Removed GET /api/v1/surcharge/rules — Preview surcharge rules Breaking Change
  • 2 × new required request property Breaking Change
  • 1 × response property one of added Breaking Change
  • 6 × response required property removed Breaking Change

2026-09-20

  • Settlement — Added GET /api/v1/settlement/batches/{batchId}/transactions — List a settlement batch's transactions

2026-09-16

  • 1 × response property became nullable Breaking Change

2026-09-04

  • Settlement — Added GET /api/v1/settlement/batches — List settlement batches
  • Settlement — Added GET /api/v1/settlement/batches/{batchId} — Get settlement batch
  • Settlement — Added GET /api/v1/settlement/exceptions — List reconciliation exceptions

2026-09-03

  • ApiKeys — Removed GET /api/v1/iam/api-key-scopes — List assignable API-key scopes Breaking Change
  • ApiKeys — Removed GET /api/v1/iam/api-keys — List API keys Breaking Change
  • ApiKeys — Removed POST /api/v1/iam/api-keys — Create API key Breaking Change
  • ApiKeys — Removed DELETE /api/v1/iam/api-keys/{keyId} — Revoke API key Breaking Change
  • ApiKeys — Removed GET /api/v1/iam/api-keys/{keyId} — Get API key Breaking Change
  • ApiKeys — Removed PATCH /api/v1/iam/api-keys/{keyId} — Update API key scopes Breaking Change
  • ApiKeys — Removed POST /api/v1/iam/api-keys/{keyId}/rotate — Rotate API key Breaking Change
  • Certification — Removed POST /api/v1/certification/checks/{checkId}/fail — Mark certification check failed Breaking Change
  • Certification — Removed POST /api/v1/certification/checks/{checkId}/pass — Mark certification check passed Breaking Change
  • Certification — Removed POST /api/v1/certification/checks/{checkId}/waive — Waive certification check Breaking Change
  • Certification — Removed POST /api/v1/certification/flows — Begin certification flow Breaking Change
  • Certification — Removed POST /api/v1/partner/me/certification/recertification-requests — Request a delta re-certification of the certified scope Breaking Change
  • Notifications — Removed GET /api/v1/notifications — List the calling user's notification feed Breaking Change
  • Notifications — Removed POST /api/v1/notifications/{notificationId}/read — Mark one notification as read Breaking Change
  • Notifications — Removed GET /api/v1/notifications/categories — List notification categories Breaking Change
  • Notifications — Removed POST /api/v1/notifications/read-all — Mark every notification in the calling user's feed as read Breaking Change
  • Partners — Removed GET /api/v1/partner/action-items — Get the authenticated partner's action-required items Breaking Change
  • Partners — Removed GET /api/v1/partner/audit-log — List the authenticated partner's audit-log entries Breaking Change
  • Partners — Removed GET /api/v1/partner/dashboard/summary — Get the authenticated partner's dashboard summary Breaking Change
  • Partners — Removed POST /api/v1/partner/me/certification/checks/{checkId}/submit — Submit a manual or attestation check for Cresora review Breaking Change
  • Partners — Removed POST /api/v1/partner/me/certification/start — Start the caller's prepared certification run Breaking Change
  • Partners — Removed POST /api/v1/partner/me/certification/steps/{step}/rerun — Re-run the automated checks of a certification step Breaking Change
  • Partners — Removed GET /api/v1/partner/onboarding-state — Get the authenticated partner's onboarding-checklist state Breaking Change
  • Partners — Removed GET /api/v1/partner/status — Get the authenticated partner's status badge inputs Breaking Change

August 2026

2026-08-27

  • 2 × request property became required Breaking Change

2026-08-25

  • 6 × request property max length decreased Breaking Change
  • 1 × request property min length increased Breaking Change

2026-08-20

  • 10 × response property max length increased Breaking Change

2026-08-17

  • Certification — Added GET /api/v1/certification/flows/latest-completed — Get the latest completed certification flow
  • Certification — Added POST /api/v1/partner/me/certification/recertification-requests — Request a delta re-certification of the certified scope
  • Certification — Added GET /api/v1/partner/me/certification/recertification-requests/current — Get the caller's current re-certification request

2026-08-11

  • Merchants — Added POST /api/v1/merchants/{merchantId}/envelope/resend — Resend the merchant's MPA signature envelope
  • 2 × request parameter enum value removed Breaking Change

2026-08-10

  • HPP — Added POST /api/v1/hpp/sessions/{sessionId}/cancel — Cancel HPP session
  • 5 × response property became nullable Breaking Change
  • 1 × response property became optional Breaking Change
  • 1 × response success status removed Breaking Change

July 2026

2026-07-30

  • 2 × request property max length decreased Breaking Change
  • 1 × request property min increased Breaking Change
  • 2 × request property min length increased Breaking Change

2026-07-26

  • Partners — Added POST /api/v1/partner/me/certification/checks/{checkId}/submit — Submit a manual or attestation check for Cresora review
  • Partners — Added POST /api/v1/partner/me/certification/start — Start the caller's prepared certification run
  • Partners — Added POST /api/v1/partner/me/certification/steps/{step}/rerun — Re-run the automated checks of a certification step
  • 2 × request body became required Breaking Change
  • 35 × request parameter min length increased Breaking Change
  • 35 × request parameter pattern added Breaking Change
  • 2 × request property became required Breaking Change
  • 2 × request property min length increased Breaking Change
  • 2 × request property pattern added Breaking Change
  • 3 × response property min decreased Breaking Change

2026-07-24

  • Stored credentials — Removed POST /api/v1/merchants/{merchantId}/stored-credentials/{vaultToken}/charges — Charge a stored credential Breaking Change
  • 2 × new required request property Breaking Change
  • 1 × request body one of removed Breaking Change

2026-07-22

  • 1 × request property pattern added Breaking Change

2026-07-21

  • Partners — Added GET /api/v1/partner/action-items — Get the authenticated partner's action-required items

2026-07-18

  • Customers — Added GET /api/v1/merchants/{merchantId}/customers — List merchant customers
  • Customers — Added POST /api/v1/merchants/{merchantId}/customers — Create a customer under a merchant
  • Customers — Added DELETE /api/v1/merchants/{merchantId}/customers/{customerId} — Soft-delete a customer
  • Customers — Added GET /api/v1/merchants/{merchantId}/customers/{customerId} — Get a customer by id
  • Customers — Added PATCH /api/v1/merchants/{merchantId}/customers/{customerId} — Update mutable customer fields
  • Stored credentials — Added GET /api/v1/merchants/{merchantId}/stored-credentials — List stored credentials under a merchant
  • Stored credentials — Added DELETE /api/v1/merchants/{merchantId}/stored-credentials/{storedCredentialId} — Revoke a stored credential
  • Stored credentials — Added GET /api/v1/merchants/{merchantId}/stored-credentials/{storedCredentialId} — Get a stored credential by id
  • Stored credentials — Added POST /api/v1/merchants/{merchantId}/stored-credentials/{vaultToken}/charges (removed 2026-07-24) — Charge a stored credential
  • 86 × request property enum value removed Breaking Change
  • 2 × request property pattern added Breaking Change

2026-07-15

  • 8 × request property min length increased Breaking Change

2026-07-13

  • Custom Fields — Added GET /api/v1/config/custom-fields/configs — List the partner's merchant custom-field configs
  • Custom Fields — Added DELETE /api/v1/config/custom-fields/merchants/{merchantId} — Delete a merchant's custom-field definitions
  • Custom Fields — Added GET /api/v1/config/custom-fields/merchants/{merchantId} — Get a merchant's custom-field definitions
  • Custom Fields — Added PUT /api/v1/config/custom-fields/merchants/{merchantId} — Create or replace a merchant's custom-field definitions

2026-07-09

  • Config — Added GET /api/v1/config/feature-flags/me — List the features granted to the calling partner
  • Config — Added PUT /api/v1/config/feature-flags/me/{flagName} — Set the calling partner's on/off for a granted feature

2026-07-08

  • Merchants — Added GET /api/v1/merchants/{merchantId}/fee-settings — Get merchant fee settings
  • Merchants — Added PUT /api/v1/merchants/{merchantId}/fee-settings/convenience-fee — Create or update the merchant's convenience-fee program
  • Merchants — Added PUT /api/v1/merchants/{merchantId}/fee-settings/surcharge — Create or update the merchant's surcharge program

2026-07-06

  • 19 × response required property removed Breaking Change

2026-07-04

  • Config — Removed DELETE /api/v1/config/feature-flags/{flagName}/partners/{partnerId} — Remove a partner-level feature flag override Breaking Change
  • Config — Removed PUT /api/v1/config/feature-flags/{flagName}/partners/{partnerId} — Set a partner-level feature flag override Breaking Change
  • Partners — Added POST /api/v1/partner/me/certification/prepare — Prepare the caller's certification flow
  • Partners — Removed PATCH /api/v1/partner/me/feature-selection — Save the authenticated partner's feature selection Breaking Change
  • 1 × response required property removed Breaking Change

June 2026

2026-06-30

  • 1 × request property became enum Breaking Change

2026-06-26

  • Config — Added PUT /api/v1/config/hpp-page/merchants/{merchantId}/embedding-domains — Replace a merchant's HPP iframe embedding allow-list
  • Config — Added POST /api/v1/config/hpp-page/merchants/{merchantId}/embedding-domains/add — Add to a merchant's HPP iframe embedding allow-list (additive)
  • HPP — Removed PUT /api/v1/hpp/embedding-domains — Register HPP embedding domains Breaking Change
  • Partners — Added GET /api/v1/partner/audit-log — List the authenticated partner's audit-log entries

2026-06-24

  • ApiKeys — Added PATCH /api/v1/iam/api-keys/{keyId} — Update API key scopes
  • 1 × response required property removed Breaking Change

2026-06-23

  • Webhooks — Added GET /api/v1/webhook-metadata — Webhook metadata — retry policy + per-event-type limit

2026-06-21

  • ApiKeys — Added GET /api/v1/iam/api-key-scopes — List assignable API-key scopes
  • Config — Added GET /api/v1/config/us-states — List US states
  • Merchants — Added GET /api/v1/onboarding/saq-types — List PCI SAQ types
  • Notifications — Added GET /api/v1/notifications/categories — List notification categories
  • Partners — Added GET /api/v1/partner/system-status — Get platform system status
  • Webhooks — Added GET /api/v1/webhook-event-types — List subscribable webhook event types

2026-06-19

  • Config — Added GET /api/v1/config/mcc-catalog — List the curated MCC catalog
  • 24 × request property enum value removed Breaking Change
  • 2 × webhook removed Breaking Change

2026-06-16

  • Config — Added GET /api/v1/config/hpp-page — Get the effective hosted-payment-page appearance config
  • Config — Added PUT /api/v1/config/hpp-page — Create or replace the partner-level HPP template
  • Config — Added GET /api/v1/config/hpp-page/configs — List the partner's HPP configs
  • Config — Added DELETE /api/v1/config/hpp-page/merchants/{merchantId} — Delete a per-merchant HPP override
  • Config — Added PUT /api/v1/config/hpp-page/merchants/{merchantId} — Create or replace a per-merchant HPP override
  • Merchants — Added GET /api/v1/merchants/{merchantId}/bank-verification — Get the settlement bank-account verification status
  • Merchants — Added POST /api/v1/merchants/{merchantId}/bank-verification/check — Poll the provider and refresh the bank-verification status

2026-06-15

  • Merchants — Added GET /api/v1/merchants/{merchantId}/application — Get a merchant's application sections 2–5 (PII masked)
  • Merchants — Added GET /api/v1/merchants/{merchantId}/compliance-documents — List own merchant's compliance documents (metadata only)
  • Merchants — Added POST /api/v1/merchants/{merchantId}/compliance-documents — Upload a compliance document (encrypted at rest)
  • Merchants — Added GET /api/v1/merchants/{merchantId}/compliance/baa-template — Download the HIPAA BAA template to sign
  • Merchants — Added POST /api/v1/merchants/{merchantId}/compliance/saq-type — Record the SAQ type determined by the SAQ wizard
  • Merchants — Added GET /api/v1/merchants/{merchantId}/go-live-gate — Get a merchant's go-live gate status
  • Merchants — Added POST /api/v1/merchants/{merchantId}/respond-clarification — Respond to a clarification request
  • Merchants — Added POST /api/v1/merchants/{merchantId}/resubmit — Resubmit a rejected merchant for review

2026-06-13

  • Transactions — Added GET /api/v1/transactions/export — Export transactions as CSV
  • Transactions — Added GET /api/v1/transactions/summary — Transaction KPI summary
  • 2 × response property type changed Breaking Change
  • 1 × response required property removed Breaking Change

2026-06-12

  • 3 × response property became nullable Breaking Change

2026-06-11

  • ApiKeys — Moved GET /api/v1/api-keys → GET /api/v1/iam/api-keys — List API keys Breaking Change
  • ApiKeys — Moved POST /api/v1/api-keys → POST /api/v1/iam/api-keys — Create API key Breaking Change
  • ApiKeys — Added GET /api/v1/iam/api-keys/{keyId} — Get API key
  • ApiKeys — Moved DELETE /api/v1/api-keys/{keyId} → DELETE /api/v1/iam/api-keys/{keyId} — Revoke API key Breaking Change
  • ApiKeys — Added POST /api/v1/iam/api-keys/{keyId}/rotate — Rotate API key
  • Certification — Removed GET /api/v1/certification/checks — List certification checks Breaking Change
  • Certification — Removed POST /api/v1/certification/checks — Request certification check Breaking Change
  • Certification — Removed GET /api/v1/certification/checks/{checkId} — Get certification check Breaking Change
  • Certification — Added POST /api/v1/certification/checks/{checkId}/fail — Mark certification check failed
  • Certification — Added POST /api/v1/certification/checks/{checkId}/pass — Mark certification check passed
  • Certification — Added POST /api/v1/certification/checks/{checkId}/waive — Waive certification check
  • Certification — Added POST /api/v1/certification/flows — Begin certification flow
  • Certification — Added GET /api/v1/certification/flows/{flowId} — Get certification flow
  • Certification — Added GET /api/v1/certification/flows/active — Get the active certification flow
  • Merchants — Added PATCH /api/v1/merchants/{merchantId} — Update merchant (DRAFT only)
  • Merchants — Removed PUT /api/v1/merchants/{merchantId} — Update merchant (DRAFT only) Breaking Change
  • Merchants — Removed POST /api/v1/merchants/{merchantId}/close — Close merchant Breaking Change
  • Merchants — Added GET /api/v1/merchants/{merchantId}/locations — List merchant locations
  • Merchants — Added POST /api/v1/merchants/{merchantId}/locations — Create merchant location
  • Merchants — Added DELETE /api/v1/merchants/{merchantId}/locations/{locationId} — Delete merchant location
  • Merchants — Added GET /api/v1/merchants/{merchantId}/locations/{locationId} — Get merchant location
  • Merchants — Added PATCH /api/v1/merchants/{merchantId}/locations/{locationId} — Update merchant location
  • Merchants — Added GET /api/v1/merchants/{merchantId}/transitions — Get merchant state-transition history
  • Notifications — Added GET /api/v1/notifications — List the calling user's notification feed
  • Notifications — Added POST /api/v1/notifications/{notificationId}/read — Mark one notification as read
  • Notifications — Added POST /api/v1/notifications/read-all — Mark every notification in the calling user's feed as read
  • Partners — Added PATCH /api/v1/partner/me/feature-selection (removed 2026-07-04) — Save the authenticated partner's feature selection
  • Recurring — Added GET /api/v1/contracts — List recurring contracts
  • Recurring — Added POST /api/v1/contracts — Create recurring contract
  • Recurring — Added GET /api/v1/contracts/{contractId} — Get recurring contract
  • Recurring — Added PATCH /api/v1/contracts/{contractId} — Update recurring contract (limited fields)
  • Recurring — Added POST /api/v1/contracts/{contractId}/cancel — Cancel recurring contract
  • Recurring — Added POST /api/v1/contracts/{contractId}/retry — Retry failed recurring charge
  • Recurring — Removed GET /api/v1/recurring/plans — List recurring plans Breaking Change
  • Recurring — Removed POST /api/v1/recurring/plans — Enroll recurring plan Breaking Change
  • Recurring — Removed DELETE /api/v1/recurring/plans/{planId} — Cancel recurring plan Breaking Change
  • Recurring — Removed GET /api/v1/recurring/plans/{planId} — Get recurring plan Breaking Change
  • Recurring — Removed PATCH /api/v1/recurring/plans/{planId} — Update recurring plan Breaking Change
  • Recurring — Removed POST /api/v1/recurring/plans/{planId}/retry — Retry failed recurring charge manually Breaking Change
  • Terminals — Removed GET /api/v1/terminals — List terminals Breaking Change
  • Terminals — Removed POST /api/v1/terminals — Register terminal Breaking Change
  • Terminals — Removed GET /api/v1/terminals/{terminalId} — Get terminal Breaking Change
  • Terminals — Removed POST /api/v1/terminals/{terminalId}/provision — Provision terminal Breaking Change
  • Terminals — Removed POST /api/v1/terminals/{terminalId}/reactivate — Reactivate suspended terminal Breaking Change
  • Terminals — Removed POST /api/v1/terminals/{terminalId}/rotate-api-key — Rotate terminal API key Breaking Change
  • Terminals — Removed POST /api/v1/terminals/{terminalId}/suspend — Suspend terminal Breaking Change
  • Transactions — Added POST /api/v1/transactions — Create transaction (polymorphic — all card + ACH operations)
  • Transactions — Removed POST /api/v1/transactions/{transactionId}/ach-reverse — Reverse ACH transaction (NACHA 5-day window) Breaking Change
  • Transactions — Removed POST /api/v1/transactions/{transactionId}/capture — Capture authorized transaction Breaking Change
  • Transactions — Removed POST /api/v1/transactions/{transactionId}/refund — Refund transaction (full or partial) Breaking Change
  • Transactions — Removed POST /api/v1/transactions/{transactionId}/reverse — Reverse authorization Breaking Change
  • Transactions — Removed POST /api/v1/transactions/{transactionId}/void — Void transaction Breaking Change
  • Transactions — Removed POST /api/v1/transactions/batch-close — Close current settlement batch Breaking Change
  • Transactions — Removed POST /api/v1/transactions/sale — Process sale Breaking Change
  • Transactions — Removed POST /api/v1/transactions/verify — Verify card ($0 auth) Breaking Change
  • 1 × response property became nullable Breaking Change
  • 1 × response property type changed Breaking Change
  • 6 × response required property removed Breaking Change
  • 1 × response success status removed Breaking Change

2026-06-08

  • HPP — Added PUT /api/v1/hpp/embedding-domains (removed 2026-06-26) — Register HPP embedding domains

2026-06-07

  • 1 × new required request property Breaking Change
  • 1 × request property max length decreased Breaking Change

May 2026

2026-05-27

  • 6 × response property max length increased Breaking Change

2026-05-26

  • Partners — Added GET /api/v1/partner/dashboard/summary — Get the authenticated partner's dashboard summary
  • Partners — Added GET /api/v1/partner/me — Get the authenticated caller's partner
  • Partners — Added GET /api/v1/partner/onboarding-state — Get the authenticated partner's onboarding-checklist state
  • Partners — Added GET /api/v1/partner/status — Get the authenticated partner's status badge inputs
  • Webhooks — Added POST /api/v1/webhook-subscriptions/{subscriptionId}/test-delivery — Send a synchronous test event to the subscription URL

2026-05-25

  • Config — Added DELETE /api/v1/config/feature-flags/{flagName}/partners/{partnerId} (removed 2026-07-04) — Remove a partner-level feature flag override
  • Config — Added PUT /api/v1/config/feature-flags/{flagName}/partners/{partnerId} (removed 2026-07-04) — Set a partner-level feature flag override
  • Config — Added GET /api/v1/config/partners/{partnerId} — Get partner configuration
  • Config — Added PUT /api/v1/config/partners/{partnerId} — Create or replace partner configuration
  • 3 × new required request default parameter to existing path Breaking Change
  • 4 × new required request parameter Breaking Change
  • 269 × response property became optional Breaking Change
  • 538 × response required property removed Breaking Change
  • 1 × webhook removed Breaking Change

2026-05-24

  • Webhooks — Moved GET /api/v1/webhooks/subscriptions → GET /api/v1/webhook-subscriptions — List webhook subscriptions Breaking Change
  • Webhooks — Moved POST /api/v1/webhooks/subscriptions → POST /api/v1/webhook-subscriptions — Create webhook subscription Breaking Change
  • Webhooks — Moved DELETE /api/v1/webhooks/subscriptions/{subscriptionId} → DELETE /api/v1/webhook-subscriptions/{subscriptionId} — Delete webhook subscription Breaking Change
  • Webhooks — Moved GET /api/v1/webhooks/subscriptions/{subscriptionId} → GET /api/v1/webhook-subscriptions/{subscriptionId} — Get webhook subscription Breaking Change
  • Webhooks — Moved PATCH /api/v1/webhooks/subscriptions/{subscriptionId} → PATCH /api/v1/webhook-subscriptions/{subscriptionId} — Update webhook subscription Breaking Change
  • Webhooks — Added GET /api/v1/webhook-subscriptions/{subscriptionId}/deliveries — List webhook delivery history
  • Webhooks — Added POST /api/v1/webhook-subscriptions/{subscriptionId}/deliveries/{eventId}/redeliver — Redeliver a historical webhook event
  • Webhooks — Moved POST /api/v1/webhooks/subscriptions/{subscriptionId}/rotate-secret → POST /api/v1/webhook-subscriptions/{subscriptionId}/rotate-secret — Rotate HMAC secret Breaking Change

2026-05-21

  • Transactions — Added POST /api/v1/transactions/verify (removed 2026-06-11) — Verify card ($0 auth)
  • 1 × new required request property Breaking Change
  • 9 × response property one of added Breaking Change

2026-05-20

  • 1 × request parameter enum value removed Breaking Change
  • 6 × request property enum value removed Breaking Change

2026-05-15 — v1.2.0: ACH recurring billing — Reg E re-notification support (never shipped)

ACH recurring billing — Reg E re-notification support Planned

  • This entry announced a capability that never shipped. No re-notification webhook exists and none is sent. Sending the Reg E re-notification is the integrator's responsibility. See NACHA compliance and Recurring billing.
  • Added NACHA Regulation E re-notification support for recurring ACH plans. Cresora now sends re-notification webhooks at the required intervals before charging a recurring ACH plan where the original authorization was not date-specific. (No such support was ever added and no re-notification is sent — corrected 2026-09-07.)
  • New webhook event: ach.renotification_required — fires when Cresora determines that re-notification is required before the next recurring charge. (No such event exists and nothing emits it — corrected 2026-09-07.)
  • No breaking changes. Existing recurring ACH integrations will begin receiving the new event automatically. (No event is delivered — corrected 2026-09-07.)

2026-05-04

  • Compliance — Removed GET /api/v1/compliance/documents — List compliance documents Breaking Change
  • Compliance — Removed POST /api/v1/compliance/documents — Upload compliance document Breaking Change
  • Migration — Removed GET /api/v1/migration/jobs — List migration jobs Breaking Change
  • Migration — Removed POST /api/v1/migration/jobs — Start migration job Breaking Change
  • Migration — Removed GET /api/v1/migration/jobs/{jobId} — Get migration job status Breaking Change
  • Migration — Removed POST /api/v1/migration/jobs/{jobId}/pause — Pause migration job Breaking Change
  • Migration — Removed POST /api/v1/migration/jobs/{jobId}/resume — Resume migration job Breaking Change
  • Settlement — Removed GET /api/v1/settlement/batches — List settlement batches Breaking Change
  • Settlement — Removed GET /api/v1/settlement/batches/{batchId} — Get batch details Breaking Change
  • Settlement — Removed GET /api/v1/settlement/exceptions — List reconciliation exceptions Breaking Change
  • 1 × request parameter enum value removed Breaking Change

April 2026

2026-04-24

  • ApiKeys — Added GET /api/v1/api-keys (removed 2026-06-11) — List API keys
  • ApiKeys — Added POST /api/v1/api-keys (removed 2026-06-11) — Create API key
  • ApiKeys — Added DELETE /api/v1/api-keys/{keyId} (removed 2026-06-11) — Revoke API key
  • Capabilities — Added GET /api/v1/capabilities — Get partner capabilities
  • Certification — Added GET /api/v1/certification/checks (removed 2026-06-11) — List certification checks
  • Certification — Added POST /api/v1/certification/checks (removed 2026-06-11) — Request certification check
  • Certification — Added GET /api/v1/certification/checks/{checkId} (removed 2026-06-11) — Get certification check
  • Compliance — Added GET /api/v1/compliance/documents (removed 2026-05-04) — List compliance documents
  • Compliance — Added POST /api/v1/compliance/documents (removed 2026-05-04) — Upload compliance document
  • Health — Added GET /api/v1/health — Health probe
  • HPP — Added POST /api/v1/hpp/sessions — Create HPP session
  • HPP — Added GET /api/v1/hpp/sessions/{sessionId} — Get HPP session status
  • Merchants — Added GET /api/v1/merchants — List merchants
  • Merchants — Added POST /api/v1/merchants — Create merchant (DRAFT)
  • Merchants — Added GET /api/v1/merchants/{merchantId} — Get merchant
  • Merchants — Added PUT /api/v1/merchants/{merchantId} (removed 2026-06-11) — Update merchant (DRAFT only)
  • Merchants — Added POST /api/v1/merchants/{merchantId}/close (removed 2026-06-11) — Close merchant
  • Merchants — Added POST /api/v1/merchants/{merchantId}/submit — Submit merchant for review
  • Migration — Added GET /api/v1/migration/jobs (removed 2026-05-04) — List migration jobs
  • Migration — Added POST /api/v1/migration/jobs (removed 2026-05-04) — Start migration job
  • Migration — Added GET /api/v1/migration/jobs/{jobId} (removed 2026-05-04) — Get migration job status
  • Migration — Added POST /api/v1/migration/jobs/{jobId}/pause (removed 2026-05-04) — Pause migration job
  • Migration — Added POST /api/v1/migration/jobs/{jobId}/resume (removed 2026-05-04) — Resume migration job
  • Recurring — Added GET /api/v1/recurring/plans (removed 2026-06-11) — List recurring plans
  • Recurring — Added POST /api/v1/recurring/plans (removed 2026-06-11) — Enroll recurring plan
  • Recurring — Added DELETE /api/v1/recurring/plans/{planId} (removed 2026-06-11) — Cancel recurring plan
  • Recurring — Added GET /api/v1/recurring/plans/{planId} (removed 2026-06-11) — Get recurring plan
  • Recurring — Added PATCH /api/v1/recurring/plans/{planId} (removed 2026-06-11) — Update recurring plan
  • Recurring — Added POST /api/v1/recurring/plans/{planId}/retry (removed 2026-06-11) — Retry failed recurring charge manually
  • Settlement — Added GET /api/v1/settlement/batches (removed 2026-05-04) — List settlement batches
  • Settlement — Added GET /api/v1/settlement/batches/{batchId} (removed 2026-05-04) — Get batch details
  • Settlement — Added GET /api/v1/settlement/exceptions (removed 2026-05-04) — List reconciliation exceptions
  • Terminals — Added GET /api/v1/terminals (removed 2026-06-11) — List terminals
  • Terminals — Added POST /api/v1/terminals (removed 2026-06-11) — Register terminal
  • Terminals — Added GET /api/v1/terminals/{terminalId} (removed 2026-06-11) — Get terminal
  • Terminals — Added POST /api/v1/terminals/{terminalId}/provision (removed 2026-06-11) — Provision terminal
  • Terminals — Added POST /api/v1/terminals/{terminalId}/reactivate (removed 2026-06-11) — Reactivate suspended terminal
  • Terminals — Added POST /api/v1/terminals/{terminalId}/rotate-api-key (removed 2026-06-11) — Rotate terminal API key
  • Terminals — Added POST /api/v1/terminals/{terminalId}/suspend (removed 2026-06-11) — Suspend terminal
  • Transactions — Added GET /api/v1/surcharge/rules (removed 2026-09-28) — Preview surcharge rules
  • Transactions — Added GET /api/v1/transactions — List transactions
  • Transactions — Added GET /api/v1/transactions/{transactionId} — Get transaction
  • Transactions — Added POST /api/v1/transactions/{transactionId}/ach-reverse (removed 2026-06-11) — Reverse ACH transaction (NACHA 5-day window)
  • Transactions — Added POST /api/v1/transactions/{transactionId}/capture (removed 2026-06-11) — Capture authorized transaction
  • Transactions — Added POST /api/v1/transactions/{transactionId}/refund (removed 2026-06-11) — Refund transaction (full or partial)
  • Transactions — Added POST /api/v1/transactions/{transactionId}/reverse (removed 2026-06-11) — Reverse authorization
  • Transactions — Added POST /api/v1/transactions/{transactionId}/three-ds/complete — Complete 3DS2 challenge
  • Transactions — Added POST /api/v1/transactions/{transactionId}/void (removed 2026-06-11) — Void transaction
  • Transactions — Added POST /api/v1/transactions/batch-close (removed 2026-06-11) — Close current settlement batch
  • Transactions — Added POST /api/v1/transactions/sale (removed 2026-06-11) — Process sale
  • Webhooks — Added GET /api/v1/webhooks/subscriptions (removed 2026-05-24) — List webhook subscriptions
  • Webhooks — Added POST /api/v1/webhooks/subscriptions (removed 2026-05-24) — Create webhook subscription
  • Webhooks — Added DELETE /api/v1/webhooks/subscriptions/{subscriptionId} (removed 2026-05-24) — Delete webhook subscription
  • Webhooks — Added GET /api/v1/webhooks/subscriptions/{subscriptionId} (removed 2026-05-24) — Get webhook subscription
  • Webhooks — Added PATCH /api/v1/webhooks/subscriptions/{subscriptionId} (removed 2026-05-24) — Update webhook subscription
  • Webhooks — Added POST /api/v1/webhooks/subscriptions/{subscriptionId}/rotate-secret (removed 2026-05-24) — Rotate HMAC secret

2026-04-10 — v1.1.0: HPP white-label branding (Preview)

HPP white-label branding (Preview) Preview

  • Hosted Payment Page branding — logo, custom CSS and button text — is configured per hosted page in the Partner Portal. (This entry originally described the capability as gated by an hpp_whitelabel feature flag; no such flag exists — corrected 2026-08-31.)
  • New endpoint: POST /api/v1/hpp/sessions — see API Reference. (This entry originally announced a /v1/payments/… path that never existed — corrected 2026-08-12.)

March 2026

2026-03-01 — v1.0.0: Platform launch

Platform launch Stable

Initial release of the Cresora Commerce platform:

  • Card payments (authorization, capture, void, refund)
  • ACH debit payments and returns
  • Hosted Payment Page (HPP) integration
  • Recurring billing plans
  • Webhooks with HMAC-SHA256 verification
  • 3DS2 support
  • Partner Portal (merchant management, payments operations, reporting)