Environment Model
Cresora runs separate sandbox and production hosts. The host you call selects the environment; whether a merchant moves real money is a gateway-side flag Cresora controls.
Cresora runs two separate environments, each on its own API host. You select the environment by calling the matching host with the credentials issued for it. Nothing in the API key encodes test vs. live.
Hosts
| Environment | Base URL | Settlement |
|---|---|---|
| Sandbox | https://api.sandbox.cresoracommerce.ai/api/v1 | Certification and testing. No real money moves. |
| Production | https://api.cresoracommerce.ai/api/v1 | Live traffic. Real settlement. |
There is no test/live marker inside the API key. You reach the sandbox or production environment by calling its host with the credentials that were issued for that environment.
API keys
Keys have the format csk_{prefix}_{secret}, three segments:
csk: fixed namespace.{prefix}: 8 URL-safe characters, shown in the Partner Portal and logs so you can identify a key without revealing it (e.g.csk_Ab3kX9mQ_β¦).{secret}: the secret component, shown in full only once at creation.
The prefix is a random identifier. It does not encode the environment. A key is issued for one environment (a live key is distinct from a sandbox key), but you cannot tell which from the string alone, so track where you created each key.
What "test vs. live" means
Whether a given merchant transacts with real funds is governed by a gateway-side test flag on the merchant's reseller/merchant registration. Cresora administrators switch that flag from test to live once the merchant is ready. The platform itself carries no per-merchant environment field, and there is no test_mode field on API responses.
Onboarding a merchant for real processing requires your partner certification status to be CERTIFIED (see GET /capabilities, field certification_status).
Implications
- Switching environments means changing the host and using that environment's credentials, not swapping a key prefix. Your request-building code is otherwise identical.
- Merchant IDs are environment-specific. A merchant id (UUID) created in sandbox does not exist in production.
- Register webhooks per environment. Configure your sandbox and production webhook endpoints separately in the Partner Portal.
Capabilities endpoint
Some features are behind feature flags. Use the capabilities endpoint to discover what your credentials can access:
GET https://api.sandbox.cresoracommerce.ai/api/v1/capabilities
Authorization: Bearer csk_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxSee Capabilities β for the response shape.