Audit Logging
What the partner audit trail records, how to read it, and what is retained.
Cresora keeps an audit trail of the actions taken on your partner account — by your portal users, by your API keys, and by Cresora itself — for compliance, debugging, and dispute resolution.
What the trail records
The unit is an action on an entity, not an HTTP request:
| Recorded | Examples |
|---|---|
| Payment actions | A transaction created, captured, voided, refunded — with the acting API key or portal user |
| Merchant lifecycle | Submitted, approved, suspended, gone live |
| Account actions | Portal logins, key creations and rotations, webhook subscription changes |
| Cresora actions on your account | A merchant approval, an HPP completion, a retention sweep — the actor is redacted to an opaque cresora principal |
Raw HTTP request logs (every call's method, path and status) are internal platform logs —
they are not part of the partner-facing trail. To correlate a specific failed request,
use its error_id: the trail is filterable by trace_id, and the error_id on an error
response is that trace id.
Reading the trail
Partner Portal → Account → Audit Log.
The audit log is a portal surface: it is read with your signed-in portal session, and it
is not callable with csk_ API keys — a static integration credential cannot browse
the account's audit history. Filters available in the portal, AND-combined:
- date range —
frominclusive,toexclusive (RFC 3339 instants) actor_type—partner_user,api_key, orcresoraentity_type(e.g.Merchant,ApiKey) andentity_idtrace_id— paste theerror_idfrom a failed API response to see exactly what that request did
Results are cursor-paginated. The trail is scoped to your own partner account server-side — there is no way to read another tenant's.
Entry shape
{
"id": "0190a1e6-7081-7c9d-8e0f-3a4b5c6d7e8f",
"occurred_at": "2026-08-12T14:32:09Z",
"trace_id": "0190a1e6-7081-7c9d-8e0f-3a4b5c6d7e90",
"actor_type": "api_key",
"actor_id": "csk_ab12cd34",
"actor_label": "Production key",
"action": "transaction_created",
"entity_type": "Transaction",
"entity_id": "0190a1d5-6f70-7b8c-9d0e-2f3a4b5c6d7e",
"old_value": null,
"new_value": { "state": "CAPTURED" },
"metadata": {}
}Retention
The partner audit trail is not pruned — entries stay readable through the portal. No fixed retention horizon is published, and there is no export mechanism today — neither a key-authenticated API nor a portal download; the portal view (with its filters) is the access path. If your compliance program needs a guaranteed archival window or a bulk export, raise it with your Cresora contact so it can be planned rather than assumed.