Cancel RMA
POST/api/rmas/:rma/cancel
Cancel an RMA and keep it on record (the RMA is not deleted). Only RMAs in a cancellable status (draft, approved, in_transit) with zero return receipts can be canceled — can_be_canceled on the resource reflects this.
returns:writeGrant this scope to your token under Settings → Developer → Personal Access Tokens.
Authentication: Requires Bearer token. Requires permission: returns.cancel.
Status transition: draft / approved / in_transit → canceled
Request body (optional):
cancellation_reason(string, nullable, max 500) — audit note recorded alongsidecanceled_atandcanceled_by_user_id.
The response resource exposes the cancellation audit fields (canceled_at, canceled_by_user_id, canceled_by, cancellation_reason) and the capability flags (can_be_canceled, can_be_deleted).
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Unprocessable Content
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.