Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

The control surface credential. Send Authorization: Bearer <token>.

Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.

Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.

Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.

Path Parameters

id
string
required

The order id, as GET /v1/fulfilments reports it.

Response

The device is back and the order is ended.

What ending an order did.

id
string
required

The order this answers about.

state
enum<string>
required

What the order is now. Always cancelled: both of these routes end an order.

Available options:
cancelled
alreadyDone
boolean
required

TRUE when the order had already been ended before this call, so nothing was asked of the payment provider and no second refund was issued. Both cases answer 200. Pressing the button twice is not an error and must not read like one, and this is how a client tells them apart.

deviceId
string | null

The device that went back, on a return. Null on a cancellation, where no device had been provided, and null on a repeated call.

leaseCut
boolean

Whether a session that was live at that moment was ended by this. False for the ordinary return of an idle device, and false on any deployment configured to let sessions expire on their own.