Testing
Sandbox testing on Cresora — hosted-page card entry and amount-cents triggers.
Everything in this section follows from two rules. Learn them once and the individual pages become lookup tables.
Rule 1 — card data is entered on the hosted page
Cards never travel to the Cresora API. There is no card object on any
request body, and a raw PAN sent to the API is rejected with 400. A
sandbox card test always has three steps: create a Hosted Payment Page
session, open the hpp_url it returns, then type the test values into
that page.
curl -X POST https://api.sandbox.cresoracommerce.ai/api/v1/hpp/sessions \
-H "Authorization: Bearer $CRESORA_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"merchant_id": "<uuid>", "amount": "10.00", "currency": "USD"}'Idempotency-Key is required on session creation. Reusing a key
replays the first response instead of creating a second session.
Rule 2 — the cents portion of the amount selects the outcome
The PAN selects the network. The amount selects the outcome.
An amount ending in .00 — for example 10.00 — approves; other cents
values map to specific failures.
Card and ACH use different cents maps. .01 is "refer to issuer"
on the card rail and R01 Insufficient Funds on the ACH rail. Never
carry a row from one rail over to the other.
Card rail — selected triggers
| Amount | Vendor scenario | Kind |
|---|---|---|
$10.00 | approved | — |
$0.01 | refer to issuer | CALL |
$0.05 | pick up card | hard |
$0.07 | lost card | fraud, hard |
$0.20 | do not honor | decline |
These are the canonical certification rows. The full amount-to-outcome sheet is vendor-owned and larger than this table.
ACH rail — cents select the NACHA R-code
.01 → R01, .02 → R02, .03 → R03, and so on; .00 settles
normally. Full table: ACH returns.
Canonical test cards
One card per network. All expire 12/28. Pair each PAN with the CVV on
its own row — see AVS and CVV for why.
| Network | PAN | CVV |
|---|---|---|
| Visa | 4012000098765439 | 999 |
| MasterCard | 5146315000000055 | 998 |
| Discover | 6011000993026909 | 996 |
| Amex | 371449635392376 | 9997 |
Test PANs from other providers do not work here. 4242… is a Stripe
value and this sandbox does not recognise it.
How outcomes surface
A decline is a business outcome, not a transport error. You get HTTP
200 with a state of CAPTURED (approved) or FAILED (declined),
plus a decline_code when it failed. Discriminate on those two fields
— never on the HTTP status.
Pages in this section
- Test cards — the four PANs, end to end.
- ACH returns — cents to R-code, asynchronous.
- AVS and CVV — address and security-code results.
- Certification scenarios — required.
- 3DS simulation — current status.