> For the complete documentation index, see [llms.txt](https://www.boxhero.io/docs/llms.txt). Every page is available as Markdown by appending `.md` to its URL; this page is [Markdown](https://www.boxhero.io/docs/th/developers/api/reference/transactions/update-transaction.md).

# Update a transaction

> Partially updates an existing transaction.

Only the fields you include are changed; pass `items` to replace the entire line-item list, or `tx_time` to change the transaction's effective time (e.g. correct a shipment date). Provide `revision` to enforce optimistic concurrency. Type-specific rules from create still apply (`tx_time` is rejected on Adjust Stock). When `to_location_id` is omitted, the existing transaction's `to_location` is preserved (memo-only / partial updates are supported).

`PUT https://rest.boxhero-app.com/v1/transactions/{tx_id}`

## การยืนยันสิทธิ์

- `Authorization` (string, จำเป็น): เฮดเดอร์การยืนยันตัวตนแบบ Bearer ในรูปแบบ `Bearer <token>` โดย `<token>` คือ [โทเค็น API](https://www.boxhero.io/docs/th/developers/api/authentication.md) ของคุณ

## พารามิเตอร์ของพาธ

- `tx_id` (integer, minimum 0, maximum 2147483647, จำเป็น)

## เนื้อหาคำขอ

- `tx_time` (string, date-time): New effective time of the transaction (ISO 8601 datetime string). Cannot be in the future. Not allowed on Adjust Stock. Omit to keep the existing transaction time. Moving the time into the past is rejected with `tx-modify-too-old-tx-id` when more than 5,000 of the team's transactions would need recalculation.
- `from_location_id` (integer, minimum 0, maximum 2147483647): New source location. Only allowed on Move Stock transactions; rejected with `400` on other types.
- `to_location_id` (integer, minimum 0, maximum 2147483647): New destination location.
- `partner_id` (integer, minimum 0, maximum 2147483647, nullable): New counterparty. Pass `null` to clear an existing partner. Not allowed on Move Stock or Adjust Stock.
- `memo` (string, max length 2000): New memo. Pass an empty string to clear.
- `items` (array of object): Replacement line items. When provided, the entire item list is replaced; must contain at least one entry.

  - `item_id` (integer, minimum 0, maximum 2147483647): Item id. Mutually exclusive with item_sku.
  - `item_sku` (string, min length 1, max length 255): Item SKU (case-insensitive). Mutually exclusive with item_id.
  - `quantity` (number, จำเป็น): Signed line quantity. Positive for Stock In and Move Stock; negative for Stock Out; signed for Adjust Stock.
- `revision` (integer, minimum 0, maximum 9007199254740991): Latest `revision` you have observed. Omit to skip the concurrency check; pass the current value to refuse the update if another writer beat you to it.

## การตอบกลับ

**200** The updated transaction's id.

- `id` (integer, minimum 0, maximum 2147483647, จำเป็น): Id of the updated transaction.

**400** Request validation failed, the type-specific rules were violated, or the team is not in LOCATION mode.

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

**401** Missing, invalid, or revoked API token. `/errors/tokens/required` when no Bearer token is sent; `/errors/tokens/invalid` when the token is unknown or revoked (a revoked token may keep working for up to 60 seconds because validation results are cached).

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

**402** The team is over one of its plan limits (items, locations, or members). Upgrade the plan or reduce usage to continue.

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

**403** `/errors/invalid-request` (HTTP 403) from core, distinguished by `code`: `invalid-quantity-tx-type-in`/`invalid-quantity-tx-type-out` when a line `quantity` has the wrong sign (positive for Stock In and Move Stock, negative for Stock Out), `tx-modify-revision-mismatch` when the supplied `revision` is stale (refetch the latest transaction and retry), `tx-invalid-param-tx-time-is-future` when `tx_time` is in the future, `tx-modify-too-old-tx-id` when the edit would require recalculating more than the team's 5,000 most recent transactions (editing very old transactions — including moving `tx_time` far into the past — is rejected for performance), `txs-barcode-id-unique-error` when the same item appears on more than one line, or `cannot-edit-inventory-count-generated-tx` when the transaction was generated by an inventory count (those cannot be edited).

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

**404** No transaction with the given id was found in this team, or it was already deleted.

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

**413** Request body exceeds the size limit (1 MiB). Returned with type `/errors/invalid-request`.

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

**429** Rate limit exceeded. Limits are per team and shared by all of the team's API tokens: 5 requests per second and 300 requests per minute. The `RateLimit` and `X-RateLimit-*` headers reflect the per-minute window; check them and `Retry-After` before retrying. This status is also returned when the client IP exceeds 30 failed authentication attempts within 60 seconds, even if the token is valid.

- `id` (string, จำเป็น): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, จำเป็น): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  ค่าที่เป็นไปได้: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, จำเป็น): Human-readable summary of the error, in English.
- `correlationID` (string, จำเป็น): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. A client-supplied `X-Correlation-Id` request header (at most 128 chars of `A-Z a-z 0-9 . _ : / = -`) is echoed back here and in the response header; a missing or invalid value is silently replaced with a generated `rq_…` id.
- `instance` (string): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix. Absent on unknown-path `404` and unexpected `500` responses.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on request-validation `/errors/invalid-request` (400) responses. Absent on malformed-JSON `400`, `413` body-too-large, and most errors mapped from BoxHero core (which include it only when core supplies an array; this can include `403`). Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, จำเป็น)
  - `message` (string, จำเป็น)

คำขอ

**cURL**

```bash
curl --request PUT \
  --url 'https://rest.boxhero-app.com/v1/transactions/{tx_id}' \
  --header "Authorization: Bearer $BOXHERO_API_TOKEN" \
  --header 'Content-Type: application/json' \
  --data '{
    "tx_time": "2026-01-16T11:00:00.000Z",
    "to_location_id": 47043,
    "partner_id": 431485,
    "items": [
      {
        "item_id": 14290445,
        "quantity": 2
      }
    ],
    "memo": "Updated memo.",
    "revision": 1
  }'
```

**JavaScript**

```javascript
const response = await fetch("https://rest.boxhero-app.com/v1/transactions/{tx_id}", {
  method: "PUT",
  headers: {
    Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "tx_time": "2026-01-16T11:00:00.000Z",
    "to_location_id": 47043,
    "partner_id": 431485,
    "items": [
      {
        "item_id": 14290445,
        "quantity": 2
      }
    ],
    "memo": "Updated memo.",
    "revision": 1
  }),
});
const data = await response.json();
```

**Python**

```python
import os
import requests

response = requests.put(
    "https://rest.boxhero-app.com/v1/transactions/{tx_id}",
    headers={
        "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"],
    },
    json={
        "tx_time": "2026-01-16T11:00:00.000Z",
        "to_location_id": 47043,
        "partner_id": 431485,
        "items": [
            {
                "item_id": 14290445,
                "quantity": 2,
            },
        ],
        "memo": "Updated memo.",
        "revision": 1,
    },
)
data = response.json()
```

**HTTP**

```http
PUT /v1/transactions/{tx_id} HTTP/1.1
Host: rest.boxhero-app.com
Authorization: Bearer <token>
Content-Type: application/json

{
  "tx_time": "2026-01-16T11:00:00.000Z",
  "to_location_id": 47043,
  "partner_id": 431485,
  "items": [
    {
      "item_id": 14290445,
      "quantity": 2
    }
  ],
  "memo": "Updated memo.",
  "revision": 1
}
```

การตอบกลับ

**200**

```json
{
  "id": 14012345
}
```

**400**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/invalid-request",
  "title": "Request validation failed, the type-specific rules were violated, or the team is not in LOCATION mode.",
  "instance": "/transactions/12345"
}
```

**401**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/tokens/required",
  "title": "Missing API token. Provide a Bearer token in the Authorization header.",
  "instance": "/transactions/12345",
  "example": "Bearer wqnot0dlysdg5vymubzi4kiv"
}
```

**402**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/core/usage-limit-exceeded",
  "title": "The team is over one of its plan limits (items, locations, or members). Upgrade the plan or reduce usage to continue.",
  "instance": "/transactions/12345"
}
```

**403**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/core/forbidden",
  "title": "/errors/invalid-request (HTTP 403) from core, distinguished by code: invalid-quantity-tx-type-in/invalid-quantity-tx-type-out when a line quantity has the wrong sign (positive for Stock In and Move Stock, negative for Stock Out), tx-modify-revision-mismatch when the supplied revision is stale (refetch the latest transaction and retry), tx-invalid-param-tx-time-is-future when tx_time is in the future, tx-modify-too-old-tx-id when the edit would require recalculating more than the team's 5,000 most recent transactions (editing very old transactions — including moving tx_time far into the past — is rejected for performance), txs-barcode-id-unique-error when the same item appears on more than one line, or cannot-edit-inventory-count-generated-tx when the transaction was generated by an inventory count (those cannot be edited).",
  "instance": "/transactions/12345",
  "code": "feature-auth-error-example"
}
```

**404**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/not-found",
  "title": "No transaction with the given id was found in this team, or it was already deleted.",
  "instance": "/transactions/12345"
}
```

**413**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/invalid-request",
  "title": "Request body is too large.",
  "instance": "/transactions/12345"
}
```

**429**

```json
{
  "id": "ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a",
  "correlationID": "rq_01abf3c2b8e44a59be2a9c0f1e7d6a40",
  "type": "/errors/too-many-requests",
  "title": "Too many requests.",
  "instance": "/transactions/12345",
  "retryAfter": 60
}
```
