> ## Documentation Index
> Fetch the complete documentation index at: https://docs.therius.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Reverse a Payment

> Automatically cancels if the payment is authorized, or refunds if already captured. No need to track payment state.

If you don't want to track whether a payment is in the `authorized` or `captured` state in your own system, `POST /payment/{id}/cancel_or_refund` handles it for you. Therius checks the current payment state and automatically cancels the authorization (if uncaptured) or issues a full refund (if already captured). This is especially useful in order reversal workflows where the payment state may vary depending on timing — for example, a customer cancelling an order while fulfillment is in progress.

## Identifying the payment

`{id}` is the Therius payment `id` returned by `POST /payment/authorization` and `POST /payment/purchase`. `orderCode` and `paymentCode` are your own reference fields and are **not** accepted here. An unknown or non-owned `id` returns `404`.

<Note>
  This endpoint always reverses the **full** payment — it voids the entire authorization hold, or refunds the entire captured amount. To issue a *partial* refund on a captured payment, call [Refund](/api-reference/refund) with an `amount` instead.
</Note>

## Example

### Reverse a payment without knowing its state

<RequestExample>
  ```bash cURL theme={"dark"}
  curl -X POST https://api.therius.io/v1/payment/9f8b2c1e-4d5a-6b7c-8d9e-0f1a2b3c4d5e/cancel_or_refund \
    -H "Authorization: Bearer prv_production_your_key_here" \
    -H "Idempotency-Key: $(uuidgen)" \
    -H "Content-Type: application/json" \
    -d '{
      "merchantCode": "MERCHANT_001"
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 OK theme={"dark"}
  {
    "id": "9f8b2c1e-4d5a-6b7c-8d9e-0f1a2b3c4d5e",
    "status": "cancelled",
    "paymentCode": "PC-1234567890",
    "orderCode": "ORDER-20240101-002",
    "merchantCode": "MERCHANT_001",
    "amount": { "currency": "USD", "value": 9900, "exponent": 2 }
  }
  ```
</ResponseExample>

**Response when payment was captured (refund path) — `200 OK`**

```json theme={"dark"}
{
  "id": "9f8b2c1e-4d5a-6b7c-8d9e-0f1a2b3c4d5e",
  "status": "refunded",
  "paymentCode": "PC-1234567890",
  "orderCode": "ORDER-20240101-001",
  "merchantCode": "MERCHANT_001",
  "amount": { "currency": "USD", "value": 4999, "exponent": 2 }
}
```

<Tip>
  This endpoint is ideal for order reversal flows triggered by your customer-facing cancellation UI, where the same code path handles both pre-capture and post-capture states. Use the `status` in the response to determine which action was taken and update your internal records accordingly.
</Tip>


## OpenAPI

````yaml POST /payment/{id}/cancel_or_refund
openapi: 3.1.0
info:
  title: Therius API
  description: REST API for payments, subscriptions, and billing plans.
  version: 1.0.0
servers:
  - url: https://api.therius.io/v1
    description: Production
  - url: https://api-sandbox.therius.io/v1
    description: Sandbox
security:
  - bearerAuth: []
paths:
  /payment/{id}/cancel_or_refund:
    post:
      tags:
        - Payments
      summary: Reverse a payment
      operationId: cancelOrRefundPayment
      parameters:
        - $ref: '#/components/parameters/PaymentId'
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - merchantCode
              properties:
                merchantCode:
                  type: string
                  description: >-
                    Your merchant account identifier. Validated against the
                    Bearer key's merchant; required if the key maps to more than
                    one merchant account.
                reference:
                  type: string
                  description: Optional internal reference for this operation.
      responses:
        '200':
          description: Reverse result
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ModificationResponse'
components:
  parameters:
    PaymentId:
      name: id
      in: path
      required: true
      description: >-
        The Therius payment `id` returned by `POST /payment/authorization` or
        `POST /payment/purchase`.
      schema:
        type: string
        format: uuid
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      description: >-
        A UUID you generate per operation. Required in production. Retrying with
        the same key returns the original response.
      schema:
        type: string
        format: uuid
  schemas:
    ModificationResponse:
      type: object
      description: Result of a capture, refund, cancel or cancel_or_refund.
      properties:
        id:
          type: string
          description: The Therius payment `id`.
        merchantCode:
          type: string
        orderCode:
          type: string
        paymentCode:
          type: string
          description: Therius receipt ID.
        amount:
          $ref: '#/components/schemas/Amount'
        status:
          type: string
          enum:
            - captured
            - refunded
            - cancelled
            - failed
          description: Outcome of the operation.
    Amount:
      type: object
      required:
        - currency
        - value
        - exponent
      properties:
        currency:
          type: string
          description: >-
            ISO 4217 currency code. On capture, refund and cancel it must match
            the currency of the original payment.
          example: USD
        value:
          type: integer
          description: >-
            Amount in minor units (cents, pence, etc.). `4999` = $49.99 for USD
            (exponent 2); `5000` = ¥5000 for JPY (exponent 0). On capture it
            must not exceed the authorized value; on refund the cumulative total
            across refunds must not exceed the captured amount.
          example: 4999
        exponent:
          type: integer
          description: >-
            Number of decimal places for the currency — `2` for USD/EUR, `0` for
            JPY. Determines where the decimal point sits in `value`.
          example: 2
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Your secret API key: `Bearer prv_production_xxx` (production) or `Bearer
        prv_sandbox_xxx` (sandbox).

````