Skip to main content
Cresora Commerce
Compliance

ACH Authorization Language

The Cresora-registered NACHA authorization text your integration must display, and the catalog of registered versions.

For API-submitted (direct) ACH debits, the authorization language is not a template you adapt — it is a registered text. The consent_text_version field on ACH_DEBIT attests which registered text your payer saw, and Cresora pins that exact language as the NACHA WEB authorization evidence for the 2-year retention window. An unknown version id is rejected with 400 ach_consent_version_unknown.

🔒Display the registered text verbatim

Show the registered text word-for-word before collecting bank account details. Custom or edited wording cannot be attested: referencing a version id while displaying different language mislabels your NACHA evidence. If you need different language, request a new registered version (below) — never modify an existing one.

Registered version catalog

VersionStatusIntroduced
v1.0active2026-05-22

The text below is byte-identical to what the platform records as your NACHA evidence — this page is the authoritative source. Cresora also mirrors the catalog machine-readably in the OpenAPI specification, as the root extension x-cresora-consent-versions; use it once the specification you pull carries it.

v1.0 — one-time WEB debit authorization

By clicking "I Authorize" you authorize the merchant to initiate a one-time electronic debit from the bank account you provided in the amount displayed at checkout. You certify that the bank account is your own (or that you are an authorized signer), and that funds are available to cover the debit. This authorization applies only to the transaction you are completing now; the merchant will not initiate any further debits without separate authorization. You may revoke this authorization by contacting the merchant before the debit is processed; once the debit has been transmitted to your bank, revocation must be requested through your bank under the NACHA Operating Rules. A non-sufficient-funds (NSF) return may result in additional fees per the merchant's terms.

Usage rules:

  • Display this text verbatim (copy it — do not retype) immediately before collecting bank account details.
  • Capture the payer's IP address and the UTC instant of acceptance — they go on the debit as consent_ip and consent_at.
  • For a payer-initiated debit (use_type: ONE_TIME_FUTURE), submit it within 7 days of consent_at; older consent is rejected with consent_at exceeds 7-day recency window. The 7 days is Cresora policy quantifying NACHA's "reasonably recent" — NACHA sets the retention obligation, not the number. Merchant-initiated debits stand on the authorization already held and are not subject to the window — see the ACH guide.
  • Send consent_text_version: "v1.0" on the ACH_DEBIT — including debits of a saved bank account (vault_token); every entry carries its own authorization record.

Requesting different language

The catalog is additive: registered versions are never edited (existing evidence pins them) and old versions remain valid for the retention window. If your checkout needs different wording, raise it with Cresora before going live: different wording is registered as a NEW version id, which you then display and attest. Never adapt the text yourself while continuing to attest an existing id — that mislabels your evidence.

Hosted-page and recurring flows

When the payer enters bank details on the Cresora-hosted payment page (one-time payments, saving a bank account, or recurring enrollment), the authorization language is displayed and recorded by the hosted page — you do not display the text or submit consent_* fields for those flows.

The templates below are general NACHA guidance for authorization surfaces outside the API attestation path (for example, written or phone authorizations under other SEC codes). They are not attestable via consent_text_version.

Recurring ACH debit (fixed amount)

By providing your bank account information and clicking "Authorize Payment," you authorize [Your Company Name] to initiate recurring electronic debits from your bank account ending in [last 4 digits] for $[amount] on [schedule, e.g., "the 15th of each month"]. This authorization will remain in effect until you cancel by contacting us at [contact information] with at least 3 business days' notice before the next scheduled debit.

Recurring ACH debit (variable amount)

By providing your bank account information and clicking "Authorize Payment," you authorize [Your Company Name] to initiate recurring electronic debits from your bank account ending in [last 4 digits] for amounts that may vary based on your usage, on [schedule]. You will receive advance notice of the debit amount at least 10 days before each charge. This authorization remains in effect until cancelled.

Retaining authorization records

NACHA requires you to retain authorization records for 2 years after the last ACH entry. Store:

  • The full authorization text displayed to the customer
  • Timestamp of customer acceptance
  • IP address and user agent (for digital authorizations)
  • Account number (masked) and routing number

Re-notification language

Cresora does not detect when re-notification is due and sends no notice of its own, so track it yourself against the authorization timestamp you supplied at enrollment and the contract's frequency and next_charge_date. When it applies, send the customer:

This is a notice that we will be debiting your bank account ending in [last 4] for $[new amount] on [new date]. If you wish to revoke this authorization, contact us at [contact info] at least 3 business days before the debit date.