BoxHero
BUSINESS · COMMERCE & FINANCE
Inventory items, their attributes, partners, and team members in the account they connected.
Acts as the person, not as itself
Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.
Credentials never touch the agent
Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.
Every call on the record
Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
box_hero_delete_v1_bundles_by_bundle_idWRITEDelete bundle via DELETE /v1/bundles/{bundle_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_bundles_by_sku_by_skuWRITEDelete bundle by SKU via DELETE /v1/bundles/by-sku/{sku}. SKU-addressed twin of the id-addressed delete. A SKU containing a slash cannot be passed through this tool. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_item_attrs_by_attr_idWRITEDelete item attr via DELETE /v1/item-attrs/{attr_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_delete_v1_items_by_item_idWRITEDelete item via DELETE /v1/items/{item_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_items_by_sku_by_skuWRITEDelete item by SKU via DELETE /v1/items/by-sku/{sku}. SKU-addressed twin of the id-addressed delete. A SKU containing a slash cannot be passed through this tool (see the read). DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_locations_by_location_idWRITEDelete location via DELETE /v1/locations/{location_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_partners_by_partner_idWRITEDelete partner via DELETE /v1/partners/{partner_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_price_lists_by_price_list_idWRITEDelete price list via DELETE /v1/price-lists/{price_list_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.
box_hero_delete_v1_purchase_orders_by_number_by_order_numberWRITEDelete purchase order by number via DELETE /v1/purchase-orders/by-number/{order_number}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.
box_hero_delete_v1_purchase_orders_by_order_idWRITEDelete purchase order via DELETE /v1/purchase-orders/{order_id}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.
box_hero_delete_v1_returns_by_number_by_return_numberWRITEDelete return by number via DELETE /v1/returns/by-number/{return_number}. Delete a return. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.
box_hero_delete_v1_returns_by_return_idWRITEDelete return via DELETE /v1/returns/{return_id}. Delete a return. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.
box_hero_delete_v1_sales_orders_by_number_by_order_numberWRITEDelete sales order by number via DELETE /v1/sales-orders/by-number/{order_number}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.
box_hero_delete_v1_sales_orders_by_order_idWRITEDelete sales order via DELETE /v1/sales-orders/{order_id}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.
box_hero_delete_v1_transactions_by_tx_idWRITEDelete transaction via DELETE /v1/transactions/{tx_id}. Soft-delete an existing transaction. Subsequent reads return `404`; subsequent updates/deletes return `400`. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_get_v1_bundlesREADList bundles via GET /v1/bundles. Cursor-paginated list of bundles.
box_hero_get_v1_bundles_by_bundle_idREADGet bundle via GET /v1/bundles/{bundle_id}. A single bundle with its component items.
box_hero_get_v1_bundles_by_sku_by_skuREADGet bundle by SKU via GET /v1/bundles/by-sku/{sku}. A single bundle with its component items. Addresses the bundle by its SKU instead of its id. A SKU containing a slash cannot be passed through this tool (see the item read).
box_hero_get_v1_item_attrsREADList item attrs via GET /v1/item-attrs. All custom attribute specs defined for the team, sorted by `rank` ascending. File-type attributes are excluded.
box_hero_get_v1_item_attrs_by_attr_idREADGet item attr via GET /v1/item-attrs/{attr_id}. A single attribute spec.
box_hero_get_v1_itemsREADList items via GET /v1/items. Cursor-paginated list of items.
box_hero_get_v1_items_by_item_idREADGet item via GET /v1/items/{item_id}. A single item.
box_hero_get_v1_items_by_sku_by_skuREADGet item by SKU via GET /v1/items/by-sku/{sku}. A single item. Addresses the item by its SKU instead of its id. A SKU containing a slash cannot be passed through this tool: the connector refuses a path argument that could re-address the request, and no BoxHero credential exists to verify how BoxHero decodes an escaped segment. Use the id-addressed twin for those.
box_hero_get_v1_locationsREADList locations via GET /v1/locations. All active locations in the team.
box_hero_get_v1_locations_by_location_idREADGet location via GET /v1/locations/{location_id}. A single location.
box_hero_get_v1_membersREADList members via GET /v1/members. Active members of the team linked to the current API token.
box_hero_get_v1_members_by_member_idREADGet member via GET /v1/members/{member_id}. A single team member.
box_hero_get_v1_partnersREADList partners via GET /v1/partners. Cursor-paginated list of partners.
box_hero_get_v1_partners_by_partner_idREADGet partner via GET /v1/partners/{partner_id}. A single partner.
box_hero_get_v1_price_listsREADList price lists via GET /v1/price-lists. Cursor-paginated list of price lists (id ascending).
box_hero_get_v1_price_lists_by_price_list_idREADGet price list via GET /v1/price-lists/{price_list_id}. A single price list with its line items.
box_hero_get_v1_purchase_ordersREADList purchase orders via GET /v1/purchase-orders. Cursor-paginated list of orders.
box_hero_get_v1_purchase_orders_by_number_by_order_numberREADGet purchase order by number via GET /v1/purchase-orders/by-number/{order_number}. A single purchase order with lines and fulfillment summaries.
box_hero_get_v1_purchase_orders_by_order_idREADGet purchase order via GET /v1/purchase-orders/{order_id}. A single purchase order with lines and fulfillment summaries.
box_hero_get_v1_returnsREADList returns via GET /v1/returns. Cursor-paginated list of returns.
box_hero_get_v1_returns_by_number_by_return_numberREADGet return by number via GET /v1/returns/by-number/{return_number}. A single return with lines and fulfillment summaries.
box_hero_get_v1_returns_by_return_idREADGet return via GET /v1/returns/{return_id}. A single return with lines and fulfillment summaries.
box_hero_get_v1_sales_ordersREADList sales orders via GET /v1/sales-orders. Cursor-paginated list of orders.
box_hero_get_v1_sales_orders_by_number_by_order_numberREADGet sales order by number via GET /v1/sales-orders/by-number/{order_number}. A single sales order with lines, sales-return totals, and fulfillment summaries.
box_hero_get_v1_sales_orders_by_order_idREADGet sales order via GET /v1/sales-orders/{order_id}. A single sales order with lines, sales-return totals, and fulfillment summaries.
box_hero_get_v1_teams_linkedREADGet linked team via GET /v1/teams/linked. The team that owns the current API token. Reports the ONE team this connection's API token is bound to (id, name, currency, mode). A BoxHero token cannot reach any other team, so this is also the answer to "which account is this connection?", and it is what Agentic Fabriq calls to check a pasted token on the hosted connect page. It takes no arguments.
box_hero_get_v1_transactionsREADList transactions via GET /v1/transactions. Cursor-paginated list of transactions without per-item detail. Fetch `GET /transactions/{tx_id}` for the line items.
box_hero_get_v1_transactions_by_tx_idREADGet transaction via GET /v1/transactions/{tx_id}. A single transaction with its line items.
box_hero_post_v1_bundlesWRITECreate bundle via POST /v1/bundles. Create a new bundle. A bundle is a fixed group of existing component items and does not carry its own stock quantity. BoxHero answers 201 Created with the new record, id and all.
box_hero_post_v1_item_attrsWRITECreate item attr via POST /v1/item-attrs. Create a new custom attribute spec. The `type` cannot be changed once items have values for this attribute. BoxHero answers 201 Created with the new record, id and all.
box_hero_post_v1_itemsWRITECreate item via POST /v1/items. Create a new item. Pass `location_id` (query) together with `quantity` (body) to seed initial stock at that location; otherwise the item starts with zero stock everywhere. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_locationsWRITECreate location via POST /v1/locations. Create a new location. `name` must be unique within the team. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_partnersWRITECreate partner via POST /v1/partners. Create a new partner. Set `type` to `0` for a supplier or `1` for a customer. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_price_listsWRITECreate price list via POST /v1/price-lists. Create a price list. BoxHero answers 201 Created with the new record, id and all.
box_hero_post_v1_purchase_ordersWRITECreate purchase order via POST /v1/purchase-orders. Create a purchase or sales order. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_purchase_orders_by_number_by_order_number_transactionsWRITECreate purchase order transaction by number via POST /v1/purchase-orders/by-number/{order_number}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_purchase_orders_by_number_by_order_number_transactions_completeWRITEComplete purchase order transactions by number via POST /v1/purchase-orders/by-number/{order_number}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_purchase_orders_by_order_id_transactionsWRITECreate purchase order transaction via POST /v1/purchase-orders/{order_id}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_purchase_orders_by_order_id_transactions_completeWRITEComplete purchase order transactions via POST /v1/purchase-orders/{order_id}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_returnsWRITECreate return via POST /v1/returns. Create a sales return. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_returns_by_number_by_return_number_transactionsWRITECreate return transaction by number via POST /v1/returns/by-number/{return_number}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_returns_by_number_by_return_number_transactions_completeWRITEComplete return transactions by number via POST /v1/returns/by-number/{return_number}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_returns_by_return_id_transactionsWRITECreate return transaction via POST /v1/returns/{return_id}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_returns_by_return_id_transactions_completeWRITEComplete return transactions via POST /v1/returns/{return_id}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_sales_ordersWRITECreate sales order via POST /v1/sales-orders. Create a purchase or sales order. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_sales_orders_by_number_by_order_number_transactionsWRITECreate sales order transaction by number via POST /v1/sales-orders/by-number/{order_number}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_sales_orders_by_number_by_order_number_transactions_completeWRITEComplete sales order transactions by number via POST /v1/sales-orders/by-number/{order_number}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_sales_orders_by_order_id_transactionsWRITECreate sales order transaction via POST /v1/sales-orders/{order_id}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_sales_orders_by_order_id_transactions_completeWRITEComplete sales order transactions via POST /v1/sales-orders/{order_id}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_post_v1_transactionsWRITECreate transaction via POST /v1/transactions. Create a new inventory transaction. Type-specific rules: Stock In/Out require `to_location_id` and may carry `partner_id`/`tx_time`; Move Stock requires both `from_location_id` and `to_location_id`, rejects `partner_id`, and may carry `tx_time`; Adjust Stock requires `to_location_id` and rejects `partner_id`/`tx_time`. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_put_v1_bundles_by_bundle_idWRITEUpdate bundle via PUT /v1/bundles/{bundle_id}. Partially update a bundle. Omitted scalar fields are preserved. When `components` is provided, it replaces the full component list.
box_hero_put_v1_bundles_by_sku_by_skuWRITEUpdate bundle by SKU via PUT /v1/bundles/by-sku/{sku}. Partially update a bundle. Omitted scalar fields are preserved. When `components` is provided, it replaces the full component list. SKU-addressed twin of the id-addressed update. A SKU containing a slash cannot be passed through this tool.
box_hero_put_v1_item_attrs_by_attr_idWRITERename item attr via PUT /v1/item-attrs/{attr_id}. Rename a custom attribute spec. Only `name` is editable; create a new attribute if you need a different `type`. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_put_v1_item_attrs_ranksWRITEReorder item attrs via PUT /v1/item-attrs/ranks. Reorder custom attribute specs. Pass a list of `(id, rank)` pairs; ranks need not be contiguous and only the specs you include are updated. The request body is a JSON ARRAY of `(id, rank)` pairs, not an object. Whether a spec OMITTED from the array keeps its rank or is reordered implicitly is not stated by BoxHero's contract and was not measurable for this build (no BoxHero token exists), so send the full intended order and read the specs back. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_put_v1_items_by_item_idWRITEUpdate item via PUT /v1/items/{item_id}. Update an existing item. Only the fields you include are changed; pass `attrs[k] = null` to remove a single attribute value.
box_hero_put_v1_items_by_sku_by_skuWRITEUpdate item by SKU via PUT /v1/items/by-sku/{sku}. Update an existing item. Only the fields you include are changed; pass `attrs[k] = null` to remove a single attribute value. SKU-addressed twin of the id-addressed update. A SKU containing a slash cannot be passed through this tool (see the read).
box_hero_put_v1_locations_by_location_idWRITEUpdate location via PUT /v1/locations/{location_id}. Update a location's name and/or memo. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
box_hero_put_v1_partners_by_partner_idWRITEUpdate partner via PUT /v1/partners/{partner_id}. Update an existing partner. `type` cannot be changed once set; create a new partner if you need to switch supplier ↔ customer.
box_hero_put_v1_price_lists_by_price_list_idWRITEUpdate price list via PUT /v1/price-lists/{price_list_id}. Update a price list. Only included fields change. `items`, when provided, replaces the entire line set.
box_hero_put_v1_purchase_orders_by_number_by_order_numberWRITEUpdate purchase order by number via PUT /v1/purchase-orders/by-number/{order_number}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.
box_hero_put_v1_purchase_orders_by_number_by_order_number_statusWRITEUpdate purchase order status by number via PUT /v1/purchase-orders/by-number/{order_number}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.
box_hero_put_v1_purchase_orders_by_order_idWRITEUpdate purchase order via PUT /v1/purchase-orders/{order_id}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.
box_hero_put_v1_purchase_orders_by_order_id_statusWRITEUpdate purchase order status via PUT /v1/purchase-orders/{order_id}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.
box_hero_put_v1_returns_by_number_by_return_numberWRITEUpdate return by number via PUT /v1/returns/by-number/{return_number}. Partially update a sales return. Omitted scalar fields and omitted items are preserved.
box_hero_put_v1_returns_by_return_idWRITEUpdate return via PUT /v1/returns/{return_id}. Partially update a sales return. Omitted scalar fields and omitted items are preserved.
box_hero_put_v1_sales_orders_by_number_by_order_numberWRITEUpdate sales order by number via PUT /v1/sales-orders/by-number/{order_number}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.
box_hero_put_v1_sales_orders_by_number_by_order_number_statusWRITEUpdate sales order status by number via PUT /v1/sales-orders/by-number/{order_number}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.
box_hero_put_v1_sales_orders_by_order_idWRITEUpdate sales order via PUT /v1/sales-orders/{order_id}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.
box_hero_put_v1_sales_orders_by_order_id_statusWRITEUpdate sales order status via PUT /v1/sales-orders/{order_id}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.
box_hero_put_v1_transactions_by_tx_idWRITEUpdate transaction via PUT /v1/transactions/{tx_id}. Partially update an existing transaction. Type-specific rules from create still apply (e.g. Move Stock cannot gain a partner; Adjust Stock cannot carry `tx_time`). Pass `revision` to enforce optimistic concurrency. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.
Often connected alongside
Put BoxHero behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.