Skip to main content
Cresora Commerce
Core Concepts

API Keys

How Cresora API keys are structured, which environment they belong to, and how to rotate them safely.

Every API request to Cresora must be authenticated with a Bearer token. Your API key is that token.

Key format

Cresora keys have the shape csk_{prefix}_{secret}, three segments:

  • csk: fixed namespace.
  • {prefix}: 8 URL-safe characters, shown in the Partner Portal and logs so a key can be identified without exposing it (for example csk_ab12cd34…).
  • {secret}: the secret component, shown in full only once, at creation.

The prefix is a random identifier. It does not encode the environment, so you cannot tell a sandbox key from a live key by looking at the string. Track where each key was created. See Environment Model for how sandbox and production are separated.

🔁Mode

There is no test/live marker inside a key. Sandbox and production are reached at different hosts, each with its own credentials, and there is no test_mode field on responses.

Where to find your keys

Partner Portal → Developers → API keys

Keys are displayed in full once, at creation. If you lose one, rotate it; you cannot retrieve the original.

Key rotation

Rotate a key in the Partner Portal at any time. Rotation is not instant: for a grace period after you rotate, both the old and new keys are valid, and the old key is invalidated only when that grace period expires. That window lets you roll over with zero downtime:

  1. Rotate the key in the Partner Portal (the new key is issued; the old key keeps working during the grace period)
  2. Deploy the new key to your secrets manager
  3. Verify requests are flowing on the new key
  4. Revoke the old key, or let the grace period expire

To cut a key off immediately (for example, on suspected compromise), use Revoke instead. It takes effect at once, with no grace period.

Scoping

Keys are scoped to your Partner account. A sandbox key can only access merchants under your partner account in the sandbox environment. A live key can only access your production merchants.

🔒Security

Store API keys in a secrets manager (AWS Secrets Manager, HashiCorp Vault, Vercel Environment Variables, and similar). Never commit keys to source control or log them. Treat sandbox keys with the same care as production keys; they can create merchants and submit transactions in your sandbox.

Capabilities

Some features are enabled per partner account — not per key: ach_payments, recurring_payments, hpp_flow, three_ds2, tap_to_pay. Check what your account can use:

GET https://api.sandbox.cresoracommerce.ai/api/v1/capabilities
Authorization: Bearer csk_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxx

The response's enabled_features lists the features enabled for your partner account; every key of the account sees the same set. Calling a feature-gated endpoint without the feature returns 403 feature_not_enabled. Feature flags do not unlock unreleased endpoints — a planned operation (see API versioning) is not served for anyone, flag or no flag.