Skip to main content
Cresora Commerce
Core Concepts

Audit Logging

What the partner audit trail records, how to read it, and what is retained.

Cresora keeps an audit trail of the actions taken on your partner account — by your portal users, by your API keys, and by Cresora itself — for compliance, debugging, and dispute resolution.

What the trail records

The unit is an action on an entity, not an HTTP request:

RecordedExamples
Payment actionsA transaction created, captured, voided, refunded — with the acting API key or portal user
Merchant lifecycleSubmitted, approved, suspended, gone live
Account actionsPortal logins, key creations and rotations, webhook subscription changes
Cresora actions on your accountA merchant approval, an HPP completion, a retention sweep — the actor is redacted to an opaque cresora principal

Raw HTTP request logs (every call's method, path and status) are internal platform logs — they are not part of the partner-facing trail. To correlate a specific failed request, use its error_id: the trail is filterable by trace_id, and the error_id on an error response is that trace id.

Reading the trail

Partner Portal → Account → Audit Log.

The audit log is a portal surface: it is read with your signed-in portal session, and it is not callable with csk_ API keys — a static integration credential cannot browse the account's audit history. Filters available in the portal, AND-combined:

  • date range — from inclusive, to exclusive (RFC 3339 instants)
  • actor_type — partner_user, api_key, or cresora
  • entity_type (e.g. Merchant, ApiKey) and entity_id
  • trace_id — paste the error_id from a failed API response to see exactly what that request did

Results are cursor-paginated. The trail is scoped to your own partner account server-side — there is no way to read another tenant's.

Entry shape

{
  "id": "0190a1e6-7081-7c9d-8e0f-3a4b5c6d7e8f",
  "occurred_at": "2026-08-12T14:32:09Z",
  "trace_id": "0190a1e6-7081-7c9d-8e0f-3a4b5c6d7e90",
  "actor_type": "api_key",
  "actor_id": "csk_ab12cd34",
  "actor_label": "Production key",
  "action": "transaction_created",
  "entity_type": "Transaction",
  "entity_id": "0190a1d5-6f70-7b8c-9d0e-2f3a4b5c6d7e",
  "old_value": null,
  "new_value": { "state": "CAPTURED" },
  "metadata": {}
}

Retention

The partner audit trail is not pruned — entries stay readable through the portal. No fixed retention horizon is published, and there is no export mechanism today — neither a key-authenticated API nor a portal download; the portal view (with its filters) is the access path. If your compliance program needs a guaranteed archival window or a bulk export, raise it with your Cresora contact so it can be planned rather than assumed.