All integrations

BoxHero

BUSINESS · COMMERCE & FINANCE

Inventory items, their attributes, partners, and team members in the account they connected.

Acts as the person, not as itself

Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.

Credentials never touch the agent

Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.

Every call on the record

Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.

What an agent can do

Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.

box_hero_delete_v1_bundles_by_bundle_idWRITE

Delete bundle via DELETE /v1/bundles/{bundle_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_bundles_by_sku_by_skuWRITE

Delete bundle by SKU via DELETE /v1/bundles/by-sku/{sku}. SKU-addressed twin of the id-addressed delete. A SKU containing a slash cannot be passed through this tool. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_item_attrs_by_attr_idWRITE

Delete item attr via DELETE /v1/item-attrs/{attr_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_delete_v1_items_by_item_idWRITE

Delete item via DELETE /v1/items/{item_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_items_by_sku_by_skuWRITE

Delete item by SKU via DELETE /v1/items/by-sku/{sku}. SKU-addressed twin of the id-addressed delete. A SKU containing a slash cannot be passed through this tool (see the read). DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_locations_by_location_idWRITE

Delete location via DELETE /v1/locations/{location_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_partners_by_partner_idWRITE

Delete partner via DELETE /v1/partners/{partner_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_price_lists_by_price_list_idWRITE

Delete price list via DELETE /v1/price-lists/{price_list_id}. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource.

api
box_hero_delete_v1_purchase_orders_by_number_by_order_numberWRITE

Delete purchase order by number via DELETE /v1/purchase-orders/by-number/{order_number}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.

api
box_hero_delete_v1_purchase_orders_by_order_idWRITE

Delete purchase order via DELETE /v1/purchase-orders/{order_id}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.

api
box_hero_delete_v1_returns_by_number_by_return_numberWRITE

Delete return by number via DELETE /v1/returns/by-number/{return_number}. Delete a return. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.

api
box_hero_delete_v1_returns_by_return_idWRITE

Delete return via DELETE /v1/returns/{return_id}. Delete a return. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.

api
box_hero_delete_v1_sales_orders_by_number_by_order_numberWRITE

Delete sales order by number via DELETE /v1/sales-orders/by-number/{order_number}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.

api
box_hero_delete_v1_sales_orders_by_order_idWRITE

Delete sales order via DELETE /v1/sales-orders/{order_id}. Delete an order. The body is optional. Linked stock transactions are NOT auto-reversed — delete them separately via `/v1/transactions/{tx_id}` if you need to restore inventory. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. Deleting an order or a return does NOT reverse the stock transactions it was fulfilled with: inventory stays as those transactions left it until they are deleted separately via /v1/transactions/{tx_id}.

api
box_hero_delete_v1_transactions_by_tx_idWRITE

Delete transaction via DELETE /v1/transactions/{tx_id}. Soft-delete an existing transaction. Subsequent reads return `404`; subsequent updates/deletes return `400`. DESTRUCTIVE. BoxHero's contract publishes no undelete for this resource. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_get_v1_bundlesREAD

List bundles via GET /v1/bundles. Cursor-paginated list of bundles.

api
box_hero_get_v1_bundles_by_bundle_idREAD

Get bundle via GET /v1/bundles/{bundle_id}. A single bundle with its component items.

api
box_hero_get_v1_bundles_by_sku_by_skuREAD

Get bundle by SKU via GET /v1/bundles/by-sku/{sku}. A single bundle with its component items. Addresses the bundle by its SKU instead of its id. A SKU containing a slash cannot be passed through this tool (see the item read).

api
box_hero_get_v1_item_attrsREAD

List item attrs via GET /v1/item-attrs. All custom attribute specs defined for the team, sorted by `rank` ascending. File-type attributes are excluded.

api
box_hero_get_v1_item_attrs_by_attr_idREAD

Get item attr via GET /v1/item-attrs/{attr_id}. A single attribute spec.

api
box_hero_get_v1_itemsREAD

List items via GET /v1/items. Cursor-paginated list of items.

api
box_hero_get_v1_items_by_item_idREAD

Get item via GET /v1/items/{item_id}. A single item.

api
box_hero_get_v1_items_by_sku_by_skuREAD

Get item by SKU via GET /v1/items/by-sku/{sku}. A single item. Addresses the item by its SKU instead of its id. A SKU containing a slash cannot be passed through this tool: the connector refuses a path argument that could re-address the request, and no BoxHero credential exists to verify how BoxHero decodes an escaped segment. Use the id-addressed twin for those.

api
box_hero_get_v1_locationsREAD

List locations via GET /v1/locations. All active locations in the team.

api
box_hero_get_v1_locations_by_location_idREAD

Get location via GET /v1/locations/{location_id}. A single location.

api
box_hero_get_v1_membersREAD

List members via GET /v1/members. Active members of the team linked to the current API token.

api
box_hero_get_v1_members_by_member_idREAD

Get member via GET /v1/members/{member_id}. A single team member.

api
box_hero_get_v1_partnersREAD

List partners via GET /v1/partners. Cursor-paginated list of partners.

api
box_hero_get_v1_partners_by_partner_idREAD

Get partner via GET /v1/partners/{partner_id}. A single partner.

api
box_hero_get_v1_price_listsREAD

List price lists via GET /v1/price-lists. Cursor-paginated list of price lists (id ascending).

api
box_hero_get_v1_price_lists_by_price_list_idREAD

Get price list via GET /v1/price-lists/{price_list_id}. A single price list with its line items.

api
box_hero_get_v1_purchase_ordersREAD

List purchase orders via GET /v1/purchase-orders. Cursor-paginated list of orders.

api
box_hero_get_v1_purchase_orders_by_number_by_order_numberREAD

Get purchase order by number via GET /v1/purchase-orders/by-number/{order_number}. A single purchase order with lines and fulfillment summaries.

api
box_hero_get_v1_purchase_orders_by_order_idREAD

Get purchase order via GET /v1/purchase-orders/{order_id}. A single purchase order with lines and fulfillment summaries.

api
box_hero_get_v1_returnsREAD

List returns via GET /v1/returns. Cursor-paginated list of returns.

api
box_hero_get_v1_returns_by_number_by_return_numberREAD

Get return by number via GET /v1/returns/by-number/{return_number}. A single return with lines and fulfillment summaries.

api
box_hero_get_v1_returns_by_return_idREAD

Get return via GET /v1/returns/{return_id}. A single return with lines and fulfillment summaries.

api
box_hero_get_v1_sales_ordersREAD

List sales orders via GET /v1/sales-orders. Cursor-paginated list of orders.

api
box_hero_get_v1_sales_orders_by_number_by_order_numberREAD

Get sales order by number via GET /v1/sales-orders/by-number/{order_number}. A single sales order with lines, sales-return totals, and fulfillment summaries.

api
box_hero_get_v1_sales_orders_by_order_idREAD

Get sales order via GET /v1/sales-orders/{order_id}. A single sales order with lines, sales-return totals, and fulfillment summaries.

api
box_hero_get_v1_teams_linkedREAD

Get linked team via GET /v1/teams/linked. The team that owns the current API token. Reports the ONE team this connection's API token is bound to (id, name, currency, mode). A BoxHero token cannot reach any other team, so this is also the answer to "which account is this connection?", and it is what Agentic Fabriq calls to check a pasted token on the hosted connect page. It takes no arguments.

api
box_hero_get_v1_transactionsREAD

List transactions via GET /v1/transactions. Cursor-paginated list of transactions without per-item detail. Fetch `GET /transactions/{tx_id}` for the line items.

api
box_hero_get_v1_transactions_by_tx_idREAD

Get transaction via GET /v1/transactions/{tx_id}. A single transaction with its line items.

api
box_hero_post_v1_bundlesWRITE

Create bundle via POST /v1/bundles. Create a new bundle. A bundle is a fixed group of existing component items and does not carry its own stock quantity. BoxHero answers 201 Created with the new record, id and all.

api
box_hero_post_v1_item_attrsWRITE

Create item attr via POST /v1/item-attrs. Create a new custom attribute spec. The `type` cannot be changed once items have values for this attribute. BoxHero answers 201 Created with the new record, id and all.

api
box_hero_post_v1_itemsWRITE

Create item via POST /v1/items. Create a new item. Pass `location_id` (query) together with `quantity` (body) to seed initial stock at that location; otherwise the item starts with zero stock everywhere. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_locationsWRITE

Create location via POST /v1/locations. Create a new location. `name` must be unique within the team. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_partnersWRITE

Create partner via POST /v1/partners. Create a new partner. Set `type` to `0` for a supplier or `1` for a customer. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_price_listsWRITE

Create price list via POST /v1/price-lists. Create a price list. BoxHero answers 201 Created with the new record, id and all.

api
box_hero_post_v1_purchase_ordersWRITE

Create purchase order via POST /v1/purchase-orders. Create a purchase or sales order. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_purchase_orders_by_number_by_order_number_transactionsWRITE

Create purchase order transaction by number via POST /v1/purchase-orders/by-number/{order_number}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_purchase_orders_by_number_by_order_number_transactions_completeWRITE

Complete purchase order transactions by number via POST /v1/purchase-orders/by-number/{order_number}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_purchase_orders_by_order_id_transactionsWRITE

Create purchase order transaction via POST /v1/purchase-orders/{order_id}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_purchase_orders_by_order_id_transactions_completeWRITE

Complete purchase order transactions via POST /v1/purchase-orders/{order_id}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_returnsWRITE

Create return via POST /v1/returns. Create a sales return. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_returns_by_number_by_return_number_transactionsWRITE

Create return transaction by number via POST /v1/returns/by-number/{return_number}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_returns_by_number_by_return_number_transactions_completeWRITE

Complete return transactions by number via POST /v1/returns/by-number/{return_number}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_returns_by_return_id_transactionsWRITE

Create return transaction via POST /v1/returns/{return_id}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_returns_by_return_id_transactions_completeWRITE

Complete return transactions via POST /v1/returns/{return_id}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_sales_ordersWRITE

Create sales order via POST /v1/sales-orders. Create a purchase or sales order. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_sales_orders_by_number_by_order_number_transactionsWRITE

Create sales order transaction by number via POST /v1/sales-orders/by-number/{order_number}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_sales_orders_by_number_by_order_number_transactions_completeWRITE

Complete sales order transactions by number via POST /v1/sales-orders/by-number/{order_number}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_sales_orders_by_order_id_transactionsWRITE

Create sales order transaction via POST /v1/sales-orders/{order_id}/transactions. Create a partial fulfillment stock transaction. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_sales_orders_by_order_id_transactions_completeWRITE

Complete sales order transactions via POST /v1/sales-orders/{order_id}/transactions/complete. Fulfill all remaining per-item quantities and mark the order or return done. Pending quantities are clamped to zero after over-fulfillment. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_post_v1_transactionsWRITE

Create transaction via POST /v1/transactions. Create a new inventory transaction. Type-specific rules: Stock In/Out require `to_location_id` and may carry `partner_id`/`tx_time`; Move Stock requires both `from_location_id` and `to_location_id`, rejects `partner_id`, and may carry `tx_time`; Adjust Stock requires `to_location_id` and rejects `partner_id`/`tx_time`. BoxHero answers 201 Created with the new record, id and all. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_put_v1_bundles_by_bundle_idWRITE

Update bundle via PUT /v1/bundles/{bundle_id}. Partially update a bundle. Omitted scalar fields are preserved. When `components` is provided, it replaces the full component list.

api
box_hero_put_v1_bundles_by_sku_by_skuWRITE

Update bundle by SKU via PUT /v1/bundles/by-sku/{sku}. Partially update a bundle. Omitted scalar fields are preserved. When `components` is provided, it replaces the full component list. SKU-addressed twin of the id-addressed update. A SKU containing a slash cannot be passed through this tool.

api
box_hero_put_v1_item_attrs_by_attr_idWRITE

Rename item attr via PUT /v1/item-attrs/{attr_id}. Rename a custom attribute spec. Only `name` is editable; create a new attribute if you need a different `type`. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_put_v1_item_attrs_ranksWRITE

Reorder item attrs via PUT /v1/item-attrs/ranks. Reorder custom attribute specs. Pass a list of `(id, rank)` pairs; ranks need not be contiguous and only the specs you include are updated. The request body is a JSON ARRAY of `(id, rank)` pairs, not an object. Whether a spec OMITTED from the array keeps its rank or is reordered implicitly is not stated by BoxHero's contract and was not measurable for this build (no BoxHero token exists), so send the full intended order and read the specs back. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_put_v1_items_by_item_idWRITE

Update item via PUT /v1/items/{item_id}. Update an existing item. Only the fields you include are changed; pass `attrs[k] = null` to remove a single attribute value.

api
box_hero_put_v1_items_by_sku_by_skuWRITE

Update item by SKU via PUT /v1/items/by-sku/{sku}. Update an existing item. Only the fields you include are changed; pass `attrs[k] = null` to remove a single attribute value. SKU-addressed twin of the id-addressed update. A SKU containing a slash cannot be passed through this tool (see the read).

api
box_hero_put_v1_locations_by_location_idWRITE

Update location via PUT /v1/locations/{location_id}. Update a location's name and/or memo. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api
box_hero_put_v1_partners_by_partner_idWRITE

Update partner via PUT /v1/partners/{partner_id}. Update an existing partner. `type` cannot be changed once set; create a new partner if you need to switch supplier ↔ customer.

api
box_hero_put_v1_price_lists_by_price_list_idWRITE

Update price list via PUT /v1/price-lists/{price_list_id}. Update a price list. Only included fields change. `items`, when provided, replaces the entire line set.

api
box_hero_put_v1_purchase_orders_by_number_by_order_numberWRITE

Update purchase order by number via PUT /v1/purchase-orders/by-number/{order_number}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.

api
box_hero_put_v1_purchase_orders_by_number_by_order_number_statusWRITE

Update purchase order status by number via PUT /v1/purchase-orders/by-number/{order_number}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.

api
box_hero_put_v1_purchase_orders_by_order_idWRITE

Update purchase order via PUT /v1/purchase-orders/{order_id}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.

api
box_hero_put_v1_purchase_orders_by_order_id_statusWRITE

Update purchase order status via PUT /v1/purchase-orders/{order_id}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.

api
box_hero_put_v1_returns_by_number_by_return_numberWRITE

Update return by number via PUT /v1/returns/by-number/{return_number}. Partially update a sales return. Omitted scalar fields and omitted items are preserved.

api
box_hero_put_v1_returns_by_return_idWRITE

Update return via PUT /v1/returns/{return_id}. Partially update a sales return. Omitted scalar fields and omitted items are preserved.

api
box_hero_put_v1_sales_orders_by_number_by_order_numberWRITE

Update sales order by number via PUT /v1/sales-orders/by-number/{order_number}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.

api
box_hero_put_v1_sales_orders_by_number_by_order_number_statusWRITE

Update sales order status by number via PUT /v1/sales-orders/by-number/{order_number}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.

api
box_hero_put_v1_sales_orders_by_order_idWRITE

Update sales order via PUT /v1/sales-orders/{order_id}. Partially update a purchase or sales order. Omitted scalar fields and omitted items are preserved.

api
box_hero_put_v1_sales_orders_by_order_id_statusWRITE

Update sales order status via PUT /v1/sales-orders/{order_id}/status. Set order status directly. No transition guard is applied: any status may transition to any other status, including backward (e.g. `done` → `draft`). This mirrors BoxHero core behavior.

api
box_hero_put_v1_transactions_by_tx_idWRITE

Update transaction via PUT /v1/transactions/{tx_id}. Partially update an existing transaction. Type-specific rules from create still apply (e.g. Move Stock cannot gain a partner; Adjust Stock cannot carry `tx_time`). Pass `revision` to enforce optimistic concurrency. A 402 `/errors/core/usage-limit-exceeded` here is the TEAM's plan limit rather than a credential problem, and a 403 `/errors/core/forbidden` with `code: not-available-for-api-token` is an operation the API token may not perform at all.

api

Put BoxHero behind one governed endpoint.

Same permissions, same audit trail, whatever else you connect next.