Skip to main content
Cresora Commerce
Testing & Sandbox

Certification Scenarios

Required test scenarios you must complete before Cresora issues live API keys.

Complete all required scenarios in the sandbox before submitting for certification. Each scenario tests a critical part of your integration.

πŸ”’Required

All scenarios marked Required must be completed and evidenced before Cresora issues production keys.

Card payment scenarios

Card capture happens through a hosted-page session (cards are never POSTed to the API β€” see HPP guide); follow-up operations are type values on POST /api/v1/transactions.

#ScenarioRequiredTest with
C-01Successful card payment (sale)βœ…HPP session with capture_mode: sale (default), completed on the hosted page
C-02Auth-only paymentβœ…HPP session with capture_mode: authorize β€” completion materialises an AUTHORIZED transaction
C-03Explicit capture of C-02βœ…POST /api/v1/transactions with type: CAPTURE + parent_transaction_id
C-04Cancel an authorizationβœ…type: AUTH_REVERSAL (or VOID) + parent_transaction_id
C-05Soft decline handlingβœ…Decline scenario driven by the amount's cents portion β€” see Testing
C-06Hard decline handlingβœ…Decline scenario driven by the amount's cents portion β€” see Testing
C-07Full refundβœ…type: REFUND (no amount) against a SETTLED parent
C-08Partial refundβœ…type: PARTIAL_REFUND with amount < original, against a SETTLED parent

Idempotency scenarios

#ScenarioRequired
I-01Idempotent retry β€” same result on replayβœ…
I-02Idempotency conflict β€” different params, same keyβœ…

Webhook scenarios

#ScenarioRequired
W-01Receive and verify transaction.captured signatureβœ…
W-02Handle retry β€” return 200 on duplicate deliveryβœ…
W-03Reject stale delivery (timestamp > 5 min)βœ…

ACH scenarios (if using ACH)

#ScenarioRequired
A-01Successful ACH debitβœ…
A-02R01 return handlingβœ…
A-03R10 return handling β€” stop retryingβœ…

Error handling scenarios

#ScenarioRequired
E-01401 unauthorized β€” invalid keyβœ…
E-02400 validation_error β€” malformed requestβœ…
E-03200 with state: FAILED and a decline_code β€” gateway declineβœ…
β„ΉNote

E-03 is not an HTTP error. Both approved and declined outcomes return 200 β€” a decline is a normal business outcome, not a transport failure. Discriminate on state and decline_code. Evidence for this scenario should therefore show a 200 response whose state is FAILED.

How completion is verified

Certification is a check run, not an evidence upload: in the Partner Portal under Integration β†’ Certification, start certification and run the checks. Automated checks verify your sandbox activity directly (the scenarios above are what they look for); some checks are self-attestations you confirm in the portal; a few are ruled by Cresora. You can re-run the checks as you fix gaps.

Keep your own record of each scenario (request, response, webhook received) β€” it is what lets you fix a failing check quickly β€” but there is no evidence-file upload.

See Certification overview β†’ for the full process.