> For the complete documentation index, see [llms.txt](https://www.boxhero.io/docs/llms.txt). Every page is available as Markdown by appending `.md` to its URL; this page is [Markdown](https://www.boxhero.io/docs/ja/developers/api/reference/sales-orders/create-sales-order.md).

# Create a sales order

> Creates a sales order.

Each item in `items[]` requires `price`. Set `finalize_immediately` with `location_id` to ship all ordered quantities immediately — the location must be covered by the team's plan or the request fails with `402`. `order_number` may only contain letters, numbers, hyphens, underscores, and whitespace; auto-generated when omitted.

`POST https://rest.boxhero-app.com/v1/sales-orders`

## 認証

- `Authorization` (string, 必須): `Bearer <token>` 形式の Bearer 認証ヘッダーです。`<token>` には [APIトークン](https://www.boxhero.io/docs/ja/developers/api/authentication) を指定します。

## リクエストボディ

- `order_number` (string): Order number. Whitespace is ignored and letters are uppercased. Use only letters, numbers, hyphens, and underscores. Auto-generated when omitted on create.
- `partner_id` (integer, minimum 0, maximum 2147483647, nullable): Supplier for purchase orders or customer for sales orders. Pass null to clear.
- `order_time` (string | number | string): ISO 8601 timestamp or millisecond epoch.
- `estimated_time` (string | number | string, nullable): ISO 8601 timestamp or millisecond epoch.
- `memo` (string, max length 2000)
- `custom_fields` (array of object): Ordered custom field name-value pairs.

  - `name` (string, 必須)
  - `value` (string, 必須)
- `currency_code` (string, min length 3, max length 3): ISO 4217 currency code.
- `items` (array of object, 必須)

  - `item_id` (integer, minimum 0, maximum 2147483647): Existing item id. Mutually exclusive with item_sku, bundle_id, bundle_sku.
  - `item_sku` (string, min length 1, max length 255): Item SKU (case-insensitive). Mutually exclusive with item_id, bundle_id, bundle_sku.
  - `bundle_id` (integer, minimum 0, maximum 2147483647): Existing bundle id. Mutually exclusive with item_id, item_sku, bundle_sku.
  - `bundle_sku` (string, min length 1, max length 255): Bundle SKU (case-sensitive). Mutually exclusive with item_id, item_sku, bundle_id.
  - `quantity` (number, 必須): Quantity. May include up to four decimal places in core data.
  - `price` (string, 必須)
  - `tax` (LineTaxInput, nullable): Tax configuration for an order or return line.

    - `name` (string, min length 1, max length 255, 必須)
    - `rate` (string, 必須): Decimal value encoded as a string to avoid floating point drift.
    - `inclusive` (boolean, 必須)
  - `discount` (LineDiscountInput, nullable): Discount configuration for an order or return line.

    - `name` (string, min length 1, max length 255, 必須)
    - `type` (string, 必須): Discount type. `"percent"` is a 0-100 percentage; `"amount"` is an absolute amount.

      指定可能な値: `percent`, `amount`
    - `value` (string, 必須): Decimal value encoded as a string to avoid floating point drift.
- `costs` (array of OrderCostInput): Additional costs to attach, in display order. Included in total_price but not in any items\[\] figure.

  - `name` (string, min length 1, max length 255, 必須): Cost name.
  - `amount` (string, 必須): Cost amount. Negative for a deduction such as a prepayment. Additional costs carry no tax or discount, so the amount is the final value.
- `is_draft` (boolean): Create the order in draft status.
- `finalize_immediately` (boolean): Fulfill all lines immediately and mark the order done.
- `location_id` (integer, minimum 0, maximum 2147483647): Required when finalize_immediately is true.

## レスポンス

**201** The created sales order's id.

- `id` (integer, minimum 0, maximum 2147483647, 必須): Created order id.

**400** Request validation failed or core rejected the order.

- `id` (string, 必須): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, 必須): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  指定可能な値: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, 必須): Human-readable summary of the error, in English.
- `correlationID` (string, 必須): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, 必須): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, 必須)
  - `message` (string, 必須)

**401** Missing or invalid API token.

- `id` (string, 必須): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, 必須): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  指定可能な値: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, 必須): Human-readable summary of the error, in English.
- `correlationID` (string, 必須): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, 必須): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, 必須)
  - `message` (string, 必須)

**402** The team is over its location plan limit — it has more locations than the current plan covers (for example, extra locations kept after a downgrade), so the `finalize_immediately` stock write is blocked. The limit is team-wide, so targeting a different location does not help; upgrade the plan or remove excess locations to continue.

- `id` (string, 必須): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, 必須): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  指定可能な値: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, 必須): Human-readable summary of the error, in English.
- `correlationID` (string, 必須): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, 必須): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, 必須)
  - `message` (string, 必須)

**429** Rate limit exceeded. Check `RateLimit`, `Retry-After`, and `X-RateLimit-*` response headers before retrying.

- `id` (string, 必須): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, 必須): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  指定可能な値: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, 必須): Human-readable summary of the error, in English.
- `correlationID` (string, 必須): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, 必須): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, 必須)
  - `message` (string, 必須)

リクエスト

**cURL**

```bash
curl --request POST \
  --url 'https://rest.boxhero-app.com/v1/sales-orders' \
  --header "Authorization: Bearer $BOXHERO_API_TOKEN" \
  --header 'Content-Type: application/json' \
  --data '{
    "order_number": "PO-1001",
    "partner_id": 431485,
    "order_time": "2026-01-15T09:30:00.000Z",
    "estimated_time": "2026-01-20T00:00:00.000Z",
    "memo": "Restock for Q1",
    "currency_code": "USD",
    "items": [
      {
        "item_sku": "SKU-12345678",
        "quantity": 100,
        "price": "19.99"
      }
    ],
    "costs": [
      {
        "name": "Shipping fee",
        "amount": "45.00"
      }
    ]
  }'
```

**JavaScript**

```javascript
const response = await fetch("https://rest.boxhero-app.com/v1/sales-orders", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "order_number": "PO-1001",
    "partner_id": 431485,
    "order_time": "2026-01-15T09:30:00.000Z",
    "estimated_time": "2026-01-20T00:00:00.000Z",
    "memo": "Restock for Q1",
    "currency_code": "USD",
    "items": [
      {
        "item_sku": "SKU-12345678",
        "quantity": 100,
        "price": "19.99"
      }
    ],
    "costs": [
      {
        "name": "Shipping fee",
        "amount": "45.00"
      }
    ]
  }),
});
const data = await response.json();
```

**Python**

```python
import os
import requests

response = requests.post(
    "https://rest.boxhero-app.com/v1/sales-orders",
    headers={
        "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"],
    },
    json={
        "order_number": "PO-1001",
        "partner_id": 431485,
        "order_time": "2026-01-15T09:30:00.000Z",
        "estimated_time": "2026-01-20T00:00:00.000Z",
        "memo": "Restock for Q1",
        "currency_code": "USD",
        "items": [
            {
                "item_sku": "SKU-12345678",
                "quantity": 100,
                "price": "19.99",
            },
        ],
        "costs": [
            {
                "name": "Shipping fee",
                "amount": "45.00",
            },
        ],
    },
)
data = response.json()
```

**HTTP**

```http
POST /v1/sales-orders HTTP/1.1
Host: rest.boxhero-app.com
Authorization: Bearer <token>
Content-Type: application/json

{
  "order_number": "PO-1001",
  "partner_id": 431485,
  "order_time": "2026-01-15T09:30:00.000Z",
  "estimated_time": "2026-01-20T00:00:00.000Z",
  "memo": "Restock for Q1",
  "currency_code": "USD",
  "items": [
    {
      "item_sku": "SKU-12345678",
      "quantity": 100,
      "price": "19.99"
    }
  ],
  "costs": [
    {
      "name": "Shipping fee",
      "amount": "45.00"
    }
  ]
}
```

レスポンス

**201**

```json
{
  "id": 90101
}
```

**400**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/invalid-request",
  "title": "Request validation failed or core rejected the order.",
  "instance": "/sales-orders"
}
```

**401**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/tokens/required",
  "title": "Missing API token. Provide a Bearer token in the Authorization header.",
  "example": "Bearer wqnot0dlysdg5vymubzi4kiv"
}
```

**402**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/core/usage-limit-exceeded",
  "title": "The team is over its location plan limit — it has more locations than the current plan covers (for example, extra locations kept after a downgrade), so the finalize_immediately stock write is blocked. The limit is team-wide, so targeting a different location does not help; upgrade the plan or remove excess locations to continue.",
  "instance": "/sales-orders"
}
```

**429**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/too-many-requests",
  "title": "Too many requests.",
  "instance": "/sales-orders",
  "retryAfter": 60
}
```
