Skip to main content
Cresora Commerce
Security

Rate Limiting & Abuse Protection

The real protection layers in front of the API, and what to do about suspicious activity.

Two enforcement layers sit in front of the API, protecting platform stability for every partner.

Per-partner rate limits

Authenticated traffic is budgeted per partner account over a 60-second sliding window, by tier (STANDARD 600/min by default). Exceeding it returns 429 rate_limit_exceeded with Retry-After. See Rate Limiting → for the tiers, headers and backoff guidance.

Perimeter protection (WAF)

Ahead of the application, a web application firewall rate-limits unauthenticated traffic per source IP and blocks known-malicious patterns. Authenticated partner traffic is deliberately excluded from the per-IP cap, so partners behind a shared egress IP are budgeted by their own tier, not by their neighbors.

Transport and identity

IP allowlisting

Your partner account can carry an IP allowlist: when set, API calls from other addresses are rejected (403 ip_not_allowed). It is account configuration — ask your Cresora account manager to set or change it. Defense-in-depth only: it never replaces key hygiene.

What the platform does not do today

There is no behavioral fraud scoring on the partner API — no device fingerprinting, geolocation matching or velocity-based review holds, and no in-portal security-alerts feed. Declines come from the card networks, issuers and processors. Build your own velocity controls where your business needs them.

Reporting suspicious activity

If you observe unauthorized transactions or unexpected API calls on your account: rotate/revoke the affected keys immediately (Developers → API keys), then contact security@cresoracommerce.com and your account manager. See Key management → for the compromise checklist.