Create RMA
POST/api/rmas
Create a new RMA for a fulfilled sales order.
returns:writeGrant this scope to your token under Settings → Developer → Personal Access Tokens.
Authentication: Requires Bearer token.
Validation rules:
- sales_order_id: required, must be an order that has been fulfilled (unless sales_credit_id is provided)
- warehouse_id: required
- status: optional, allowed values: draft, approved
- notes: optional, max 1000 chars
- sales_credit_id: optional, if provided skips fulfillment and quantity validation
- rma_lines: required array with at least 1 line
- product_id: required
- expected_quantity: required, min 1, cannot exceed fulfilled minus already RMA'd quantity
- sales_order_line_id: optional, must belong to the specified sales order and match the product
- return_reason_id: optional
- notes: optional, max 500 chars
Requires permission: returns.create
Request
Responses
- 201
- 401
- 403
- 422
- 429
Created
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.