Skip to content

Core concepts

CreditCore sits between your checkout page and the payment gateway. It holds your products, routes each card to the right merchant account, stores customers securely and bills subscriptions automatically.

┌──────────────────────┐ encrypted card ┌────────────────┐ ┌──────────────────────┐
│ Your page │ ─────────────────▶ │ CreditCore API │ ─────▶ │ Merchant accounts / │
│ + Payment SDK │ │ │ │ payment gateway │
└──────────────────────┘ └───────┬────────┘ └──────────────────────┘
webhooks │ ▲ sessions, refunds, queries
▼ │
┌────────┴───────┐
│ Your server │
└────────────────┘

Account

Your company in CreditCore. Every API call is authenticated with the account’s API token, and all data you can read (customers, transactions) is scoped to that account.

Product

What you sell: a one-time purchase or a subscription with a price, renewal frequency and optional trial/delayed charge. Products are configured by CreditCore and referenced by productId.

Session

A short-lived token (5 minutes) that authorizes one checkout on one domain. Created by your server, passed to the SDK.

Customer

A buyer’s subscription to a product: email, name, card fingerprint, status, next renewal date and billing attempts. Identified by customerId.

Transaction

Every money movement: sales, recurring payments, pre-authorizations, captures, voids and refunds. Each has an internal id and the gateway’s transactionId.

Merchant account (MID)

The acquiring accounts your payments go through. CreditCore selects the MID automatically based on the product, card type and previous attempts.

Identifier Where it comes from Used in
API token Provided by CreditCore Authorization: Bearer … on server-to-server calls
productId CreditCore product catalog Session checkout, SDK config, webhooks
sessionId POST /api/session SDK config
customerId Checkout response and webhooks Customers API, unsubscribe
Transaction id Webhooks and transactions API Refunds, lookups
Gateway transactionId Payment gateway Reconciliation with the processor
  • Card data is encrypted in the browser by the SDK and only decrypted inside a PCI-compliant relay on its way to the gateway. Neither your servers nor your page ever see the card number.
  • Customers and transactions are stored by CreditCore and exposed through the API and webhooks.