Rate Limiting & Abuse Protection
The real protection layers in front of the API, and what to do about suspicious activity.
Two enforcement layers sit in front of the API, protecting platform stability for every partner.
Per-partner rate limits
Authenticated traffic is budgeted per partner account over a 60-second sliding
window, by tier (STANDARD 600/min by default). Exceeding it returns 429 rate_limit_exceeded with Retry-After. See Rate Limiting →
for the tiers, headers and backoff guidance.
Perimeter protection (WAF)
Ahead of the application, a web application firewall rate-limits unauthenticated traffic per source IP and blocks known-malicious patterns. Authenticated partner traffic is deliberately excluded from the per-IP cap, so partners behind a shared egress IP are budgeted by their own tier, not by their neighbors.
Transport and identity
- TLS-only (see Transport security →)
- Webhook deliveries signed with HMAC-SHA256 (see Webhook identity →)
IP allowlisting
Your partner account can carry an IP allowlist: when set, API calls from other
addresses are rejected (403 ip_not_allowed). It is account configuration — ask your
Cresora account manager to set or change it. Defense-in-depth only: it never replaces key
hygiene.
What the platform does not do today
There is no behavioral fraud scoring on the partner API — no device fingerprinting, geolocation matching or velocity-based review holds, and no in-portal security-alerts feed. Declines come from the card networks, issuers and processors. Build your own velocity controls where your business needs them.
Reporting suspicious activity
If you observe unauthorized transactions or unexpected API calls on your account: rotate/revoke the affected keys immediately (Developers → API keys), then contact security@cresoracommerce.com and your account manager. See Key management → for the compromise checklist.