Skip to main content
Cresora Commerce
Testing & Sandbox

Testing

Sandbox testing on Cresora — hosted-page card entry and amount-cents triggers.

Everything in this section follows from two rules. Learn them once and the individual pages become lookup tables.

Rule 1 — card data is entered on the hosted page

Cards never travel to the Cresora API. There is no card object on any request body, and a raw PAN sent to the API is rejected with 400. A sandbox card test always has three steps: create a Hosted Payment Page session, open the hpp_url it returns, then type the test values into that page.

curl
curl -X POST https://api.sandbox.cresoracommerce.ai/api/v1/hpp/sessions \
  -H "Authorization: Bearer $CRESORA_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{"merchant_id": "<uuid>", "amount": "10.00", "currency": "USD"}'
ℹNote

Idempotency-Key is required on session creation. Reusing a key replays the first response instead of creating a second session.

Rule 2 — the cents portion of the amount selects the outcome

The PAN selects the network. The amount selects the outcome. An amount ending in .00 — for example 10.00 — approves; other cents values map to specific failures.

ℹNote

Card and ACH use different cents maps. .01 is "refer to issuer" on the card rail and R01 Insufficient Funds on the ACH rail. Never carry a row from one rail over to the other.

Card rail — selected triggers

AmountVendor scenarioKind
$10.00approved—
$0.01refer to issuerCALL
$0.05pick up cardhard
$0.07lost cardfraud, hard
$0.20do not honordecline

These are the canonical certification rows. The full amount-to-outcome sheet is vendor-owned and larger than this table.

ACH rail — cents select the NACHA R-code

.01 → R01, .02 → R02, .03 → R03, and so on; .00 settles normally. Full table: ACH returns.

Canonical test cards

One card per network. All expire 12/28. Pair each PAN with the CVV on its own row — see AVS and CVV for why.

NetworkPANCVV
Visa4012000098765439999
MasterCard5146315000000055998
Discover6011000993026909996
Amex3714496353923769997
ℹNote

Test PANs from other providers do not work here. 4242… is a Stripe value and this sandbox does not recognise it.

How outcomes surface

A decline is a business outcome, not a transport error. You get HTTP 200 with a state of CAPTURED (approved) or FAILED (declined), plus a decline_code when it failed. Discriminate on those two fields — never on the HTTP status.

Pages in this section