Skip to main content
Cresora Commerce
Security

Security

Transport security, authentication, webhook identity, and rate limiting for Cresora integrations.

This section documents Cresora's security architecture and your obligations as an integrating partner.

Transport security

All Cresora API traffic is TLS 1.2+ only. TLS 1.0 and 1.1 are not supported. Certificate pinning is not required but is supported.

Authentication

All API requests require a Bearer token (a csk_{prefix}_{secret} key) in the Authorization header. Keys are scoped to your Partner account.

See API Keys for rotation and scoping details.

Webhook identity

Verify the X-Cresora-Signature HMAC-SHA256 header on every webhook delivery before trusting the payload. See Signature verification →.

Rate limiting

API requests are rate-limited per Partner key over a 60-second sliding window, at a budget set by your partner account's tier — 600 requests per minute on the default STANDARD tier, 6,000 on PREMIUM, negotiated on ENTERPRISE. On limit breach, Cresora returns 429 Too Many Requests with a Retry-After header. See Rate Limiting →.

Vulnerability disclosure

Report security issues to: security@cresoracommerce.com

See Vulnerability disclosure → for the full responsible disclosure policy.

Topics in this section