Create purchase order fulfillment transaction by order number
Looks up a purchase order by order number and creates a partial fulfillment transaction.
The target location_id must be covered by the team’s plan. Whitespace is ignored and letters are uppercased.
https://rest.boxhero-app.com/v1/purchase-orders/by-number/{order_number}/transactionsAutorización
Sección titulada «Autorización»Encabezado de autenticación Bearer con el formato Bearer <token>, donde <token> es tu token de API.
Parámetros de ruta
Sección titulada «Parámetros de ruta»Order number. Whitespace is ignored and letters are uppercased. Use only letters, numbers, hyphens, and underscores.
Cuerpo de la solicitud
Sección titulada «Cuerpo de la solicitud»Mostrar propiedades
Item id to fulfill. Mutually exclusive with item_sku. Bundles cannot be fulfilled.
Item SKU to fulfill (case-insensitive). Mutually exclusive with item_id.
Positive quantity; direction is derived by resource.
Respuestas
Sección titulada «Respuestas»201The created transaction’s id.
Created location transaction id.
401Missing or invalid API token.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores posibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propiedades
402The team is over its location plan limit — it has more locations than the current plan covers (for example, extra locations kept after a downgrade), so this stock write is blocked. The limit is team-wide, so targeting a different location does not help; upgrade the plan or remove excess locations to continue.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores posibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propiedades
404No purchase order with the given order number was found in this team.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores posibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propiedades
409The supplied revision is stale.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores posibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propiedades
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores posibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propiedades
Solicitud
curl --request POST \ --url 'https://rest.boxhero-app.com/v1/purchase-orders/by-number/{order_number}/transactions' \ --header "Authorization: Bearer $BOXHERO_API_TOKEN" \ --header 'Content-Type: application/json' \ --data '{ "location_id": 47041, "transaction_time": "2026-01-16T11:00:00.000Z", "memo": "Partial receipt", "items": [ { "item_sku": "SKU-12345678", "quantity": 60 } ], "revision": 3 }'const response = await fetch("https://rest.boxhero-app.com/v1/purchase-orders/by-number/{order_number}/transactions", { method: "POST", headers: { Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`, "Content-Type": "application/json", }, body: JSON.stringify({ "location_id": 47041, "transaction_time": "2026-01-16T11:00:00.000Z", "memo": "Partial receipt", "items": [ { "item_sku": "SKU-12345678", "quantity": 60 } ], "revision": 3 }),});const data = await response.json();import osimport requests
response = requests.post( "https://rest.boxhero-app.com/v1/purchase-orders/by-number/{order_number}/transactions", headers={ "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"], }, json={ "location_id": 47041, "transaction_time": "2026-01-16T11:00:00.000Z", "memo": "Partial receipt", "items": [ { "item_sku": "SKU-12345678", "quantity": 60, }, ], "revision": 3, },)data = response.json()POST /v1/purchase-orders/by-number/{order_number}/transactions HTTP/1.1Host: rest.boxhero-app.comAuthorization: Bearer <token>Content-Type: application/json
{ "location_id": 47041, "transaction_time": "2026-01-16T11:00:00.000Z", "memo": "Partial receipt", "items": [ { "item_sku": "SKU-12345678", "quantity": 60 } ], "revision": 3}Respuesta
{ "id": 14012345}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/tokens/required", "title": "Missing API token. Provide a Bearer token in the Authorization header.", "example": "Bearer wqnot0dlysdg5vymubzi4kiv"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/core/usage-limit-exceeded", "title": "The team is over its location plan limit — it has more locations than the current plan covers (for example, extra locations kept after a downgrade), so this stock write is blocked. The limit is team-wide, so targeting a different location does not help; upgrade the plan or remove excess locations to continue.", "instance": "/purchase-orders/by-number/PO-1001/transactions"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/not-found", "title": "No purchase order with the given order number was found in this team.", "instance": "/purchase-orders/by-number/PO-1001/transactions"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/invalid-request", "title": "The supplied revision is stale.", "instance": "/purchase-orders/by-number/PO-1001/transactions"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/too-many-requests", "title": "Too many requests.", "instance": "/purchase-orders/by-number/PO-1001/transactions", "retryAfter": 60}