Refund Transaction
POST/api/pos/transactions/:posTransaction/refund
Refund a completed POS sale in full — credit and restock the items, then either refund the original tenders (card via processor, cash at the drawer) or top up the customer's store-credit wallet.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token.
Permission: pos.refund.
Request body fields:
refund_to(enum, nullable) —original(default; back to the original tenders) orstore_credit(top up the attached customer's wallet). Store credit requires a customer on the sale (enforced server-side). Omitting the field defaults tooriginal.
Refunds are serialized under a row lock so a duplicate refund aborts. Returns 200 with the updated transaction (is_refunded true) and a message.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Validation failed — the body is a field → messages map (Laravel shape) or the platform envelope with a stable machine-readable code. Fix the payload and resubmit.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.