Skip to content

API reference

The CreditCore API is a REST API over HTTPS. Requests and responses use JSON unless stated otherwise.

https://api.creditcore.io

The same host serves sandbox and production accounts. Your account’s configuration decides which environment processes the payments.

Topic Convention
Authentication Authorization: Bearer <API token> on server-to-server endpoints. See Authentication.
Content type application/json for request bodies.
Versioning Optional X-API-Version: 1.0 header. 1.0 is the current and default version.
Dates ISO 8601 local date-time without a time zone, e.g. 2026-09-29T14:03:12.123 (CET). Query parameters use YYYY-MM-DD.
Amounts Decimal numbers in the product currency, e.g. 9.99. Refunds are negative.
IDs Numeric IDs for customers and transactions; UUID strings for sessions.
CORS Enabled for all origins on GET, POST, DELETE and PATCH.
Method Path Auth Description
POST /api/session Token Create a checkout session
GET /api/session Token Check a session
GET /api/customer/{id} Token Get a customer
POST /api/unsubscribe/{customerId} Token Cancel a subscription
GET /api/transaction/{id} Token Get a transaction
GET /api/refund/{id} Token Refund a transaction

GET /actuator/health returns the service status and can be used for uptime monitoring.