Aller au contenu

Create a sales return

Creates a sales return for a sales order.

Set finalize_immediately with location_id to receive all returned quantities immediately — the location must be covered by the team’s plan or the request fails with 402. return_number may only contain letters, numbers, hyphens, underscores, and whitespace; auto-generated when omitted.

POSThttps://rest.boxhero-app.com/v1/returns
Authorizationstringobligatoire

En-tête d’authentification Bearer au format Bearer <token>, où <token> est votre jeton d’API.

return_numberstring

Return number. Whitespace is ignored and letters are uppercased. Use only letters, numbers, hyphens, and underscores. Auto-generated when omitted on create.

return_timestring | number | string

ISO 8601 timestamp or millisecond epoch.

memostringmax length 2000
order_idintegerminimum 0, maximum 2147483647

Source sales order id. Mutually exclusive with order_number.

order_numberstring

Source sales order number. Mutually exclusive with order_id.

order_revisionintegerminimum 0, maximum 9007199254740991

Latest observed source order revision.

itemsarray of objectobligatoire
Afficher les propriétés
order_item_idintegerminimum 0, maximum 2147483647obligatoire

Source sales order line id. Identifies the line being returned — return lines are matched to source lines by this id (there is no separate return line id to send).

quantitynumberobligatoire

Quantity. May include up to four decimal places in core data.

finalize_immediatelyboolean

Receive all returned quantities immediately and mark the return done.

location_idintegerminimum 0, maximum 2147483647

Required when finalize_immediately is true.

201The created return’s id.
idintegerminimum 0, maximum 2147483647obligatoire

Created return id.

400Request validation failed or core rejected the return.
idstringobligatoire

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringobligatoire

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Valeurs possibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringobligatoire

Human-readable summary of the error, in English.

correlationIDstringobligatoire

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringobligatoire

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Afficher les propriétés
patharray of string | numberobligatoire
messagestringobligatoire
401Missing or invalid API token.
idstringobligatoire

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringobligatoire

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Valeurs possibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringobligatoire

Human-readable summary of the error, in English.

correlationIDstringobligatoire

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringobligatoire

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Afficher les propriétés
patharray of string | numberobligatoire
messagestringobligatoire
402The team is over its location plan limit — it has more locations than the current plan covers (for example, extra locations kept after a downgrade), so the finalize_immediately stock write is blocked. The limit is team-wide, so targeting a different location does not help; upgrade the plan or remove excess locations to continue.
idstringobligatoire

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringobligatoire

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Valeurs possibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringobligatoire

Human-readable summary of the error, in English.

correlationIDstringobligatoire

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringobligatoire

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Afficher les propriétés
patharray of string | numberobligatoire
messagestringobligatoire
404No source order with the given id was found in this team.
idstringobligatoire

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringobligatoire

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Valeurs possibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringobligatoire

Human-readable summary of the error, in English.

correlationIDstringobligatoire

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringobligatoire

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Afficher les propriétés
patharray of string | numberobligatoire
messagestringobligatoire
422Returns are only supported for sales orders.
idstringobligatoire

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringobligatoire

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Valeurs possibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringobligatoire

Human-readable summary of the error, in English.

correlationIDstringobligatoire

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringobligatoire

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Afficher les propriétés
patharray of string | numberobligatoire
messagestringobligatoire
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
idstringobligatoire

Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.

typestringobligatoire

Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.

Valeurs possibles/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled

titlestringobligatoire

Human-readable summary of the error, in English.

correlationIDstringobligatoire

Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.

instancestringobligatoire

Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.

codestring

Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.

errorsarray of object

Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.

Afficher les propriétés
patharray of string | numberobligatoire
messagestringobligatoire

Requête

Terminal window
curl --request POST \
--url 'https://rest.boxhero-app.com/v1/returns' \
--header "Authorization: Bearer $BOXHERO_API_TOKEN" \
--header 'Content-Type: application/json' \
--data '{
"return_number": "R-1001",
"order_number": "SO-2001",
"return_time": "2026-01-15T09:30:00.000Z",
"memo": "Damaged on arrival",
"items": [
{
"order_item_id": 700201,
"quantity": 5
}
]
}'

Réponse

{
"id": 90301
}