Update a purchase order
Partially updates a purchase order.
Omitted scalar fields are preserved; when items is provided it replaces the full line list.
https://rest.boxhero-app.com/v1/purchase-orders/{order_id}Autorização
Seção intitulada “Autorização”Cabeçalho de autenticação Bearer no formato Bearer <token>, em que <token> é o seu token de API.
Parâmetros de caminho
Seção intitulada “Parâmetros de caminho”Corpo da requisição
Seção intitulada “Corpo da requisição”Order number. Whitespace is ignored and letters are uppercased. Use only letters, numbers, hyphens, and underscores. Auto-generated when omitted on create.
Supplier for purchase orders or customer for sales orders. Pass null to clear.
ISO 8601 timestamp or millisecond epoch.
ISO 8601 timestamp or millisecond epoch.
Ordered custom field name-value pairs.
Mostrar propriedades
ISO 4217 currency code.
Replacement order lines. Omit to preserve the current lines. Within a line, include id to update an existing line in place, or omit it to add a new line.
Mostrar propriedades
Existing line id to update in place. Omit to add a new line.
Existing item id. Mutually exclusive with item_sku, bundle_id, bundle_sku.
Item SKU (case-insensitive). Mutually exclusive with item_id, bundle_id, bundle_sku.
Existing bundle id. Mutually exclusive with item_id, item_sku, bundle_sku.
Bundle SKU (case-sensitive). Mutually exclusive with item_id, item_sku, bundle_id.
Quantity. May include up to four decimal places in core data.
Tax configuration for an order or return line.
Mostrar propriedades
Decimal value encoded as a string to avoid floating point drift.
Discount configuration for an order or return line.
Mostrar propriedades
Discount type. "percent" is a 0-100 percentage; "amount" is an absolute amount.
Valores possíveispercentamount
Decimal value encoded as a string to avoid floating point drift.
Replacement additional costs, in display order. Omit to preserve the current costs; pass an empty array to remove all of them.
Mostrar propriedades
Cost name.
Cost amount. Negative for a deduction such as a prepayment. Additional costs carry no tax or discount, so the amount is the final value.
Latest observed revision. Omit to use the current revision.
Respostas
Seção intitulada “Respostas”200The updated purchase order’s id.
Updated order id.
400Request validation failed or core rejected the update.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores possíveis/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propriedades
401Missing or invalid API token.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores possíveis/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propriedades
404No purchase order with the given id was found in this team.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores possíveis/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propriedades
409The supplied revision is stale.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores possíveis/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propriedades
429Rate limit exceeded. Check RateLimit, Retry-After, and X-RateLimit-* response headers before retrying.
Unique exception id (ex_ followed by 32 lowercase hex chars, no dashes — e.g. ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a). Quote this in support tickets so we can find the request in our logs.
Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on title.
Valores possíveis/errors/not-found/errors/invalid-request/errors/invalid-team-mode/errors/tokens/invalid/errors/tokens/required/errors/too-many-requests/errors/core/usage-limit-exceeded/errors/core/forbidden/errors/core/unhandled/errors/unhandled
Human-readable summary of the error, in English.
Request correlation id (rq_ followed by 32 lowercase hex chars, no dashes — e.g. rq_01abf3...). Identical to the X-Correlation-Id response header. Pass an X-Correlation-Id request header to thread your trace through to ours.
Pointer to the specific failing resource (e.g. /items/12345). Path-only, no /v1 version prefix.
Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. not-available-for-api-token on 403). Use this for fine-grained branching after dispatching on type.
Field-level error details. Present on /errors/invalid-request (400) responses. Each entry locates a single failure via JSONPath-like path segments and a human-readable message.
Mostrar propriedades
Requisição
curl --request PUT \ --url 'https://rest.boxhero-app.com/v1/purchase-orders/{order_id}' \ --header "Authorization: Bearer $BOXHERO_API_TOKEN" \ --header 'Content-Type: application/json' \ --data '{ "memo": "Updated restock note", "costs": [ { "name": "Shipping fee", "amount": "45.00" } ], "items": [ { "id": 700101, "item_sku": "SKU-12345678", "quantity": 120, "price": "19.99" } ], "revision": 3 }'const response = await fetch("https://rest.boxhero-app.com/v1/purchase-orders/{order_id}", { method: "PUT", headers: { Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`, "Content-Type": "application/json", }, body: JSON.stringify({ "memo": "Updated restock note", "costs": [ { "name": "Shipping fee", "amount": "45.00" } ], "items": [ { "id": 700101, "item_sku": "SKU-12345678", "quantity": 120, "price": "19.99" } ], "revision": 3 }),});const data = await response.json();import osimport requests
response = requests.put( "https://rest.boxhero-app.com/v1/purchase-orders/{order_id}", headers={ "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"], }, json={ "memo": "Updated restock note", "costs": [ { "name": "Shipping fee", "amount": "45.00", }, ], "items": [ { "id": 700101, "item_sku": "SKU-12345678", "quantity": 120, "price": "19.99", }, ], "revision": 3, },)data = response.json()PUT /v1/purchase-orders/{order_id} HTTP/1.1Host: rest.boxhero-app.comAuthorization: Bearer <token>Content-Type: application/json
{ "memo": "Updated restock note", "costs": [ { "name": "Shipping fee", "amount": "45.00" } ], "items": [ { "id": 700101, "item_sku": "SKU-12345678", "quantity": 120, "price": "19.99" } ], "revision": 3}Resposta
{ "id": 90101}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/invalid-request", "title": "Request validation failed or core rejected the update.", "instance": "/purchase-orders/12345"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/tokens/required", "title": "Missing API token. Provide a Bearer token in the Authorization header.", "example": "Bearer wqnot0dlysdg5vymubzi4kiv"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/not-found", "title": "No purchase order with the given id was found in this team.", "instance": "/purchase-orders/12345"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/invalid-request", "title": "The supplied revision is stale.", "instance": "/purchase-orders/12345"}{ "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a", "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2", "type": "/errors/too-many-requests", "title": "Too many requests.", "instance": "/purchase-orders/12345", "retryAfter": 60}