Security
Transport security, authentication, webhook identity, and rate limiting for Cresora integrations.
This section documents Cresora's security architecture and your obligations as an integrating partner.
Transport security
All Cresora API traffic is TLS 1.2+ only. TLS 1.0 and 1.1 are not supported. Certificate pinning is not required but is supported.
Authentication
All API requests require a Bearer token (a csk_{prefix}_{secret} key) in the Authorization header. Keys are scoped to your Partner account.
See API Keys for rotation and scoping details.
Webhook identity
Verify the X-Cresora-Signature HMAC-SHA256 header on every webhook delivery before trusting the payload. See Signature verification →.
Rate limiting
API requests are rate-limited per Partner key over a 60-second sliding window, at a budget set by your partner account's tier — 600 requests per minute on the default STANDARD tier, 6,000 on PREMIUM, negotiated on ENTERPRISE. On limit breach, Cresora returns 429 Too Many Requests with a Retry-After header. See Rate Limiting →.
Vulnerability disclosure
Report security issues to: security@cresoracommerce.com
See Vulnerability disclosure → for the full responsible disclosure policy.