> ## Documentation Index
> Fetch the complete documentation index at: https://docs.therius.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Release an Authorization Hold

> Void a payment that is still in the authorized state. Funds are released immediately. Cannot cancel a captured payment.

`POST /payment/{id}/cancel` voids an authorization before it is captured, releasing the hold on the cardholder's funds immediately. Use this when an order is cancelled or cannot be fulfilled after the authorization was placed. If the payment has already been captured and settled, use [Refund](/api-reference/refund) instead — you cannot cancel a captured payment.

## Identifying the payment

`{id}` is the Therius payment `id` returned by `POST /payment/authorization` and `POST /payment/purchase`. `orderCode` and `paymentCode` are your own reference fields and are **not** accepted here. An unknown or non-owned `id` returns `404`.

## Example

### Cancel an authorization

<RequestExample>
  ```bash cURL theme={"dark"}
  curl -X POST https://api.therius.io/v1/payment/9f8b2c1e-4d5a-6b7c-8d9e-0f1a2b3c4d5e/cancel \
    -H "Authorization: Bearer prv_production_your_key_here" \
    -H "Idempotency-Key: $(uuidgen)" \
    -H "Content-Type: application/json" \
    -d '{
      "merchantCode": "MERCHANT_001"
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 OK theme={"dark"}
  {
    "id": "9f8b2c1e-4d5a-6b7c-8d9e-0f1a2b3c4d5e",
    "status": "cancelled",
    "paymentCode": "PC-1234567890",
    "orderCode": "ORDER-20240101-002",
    "merchantCode": "MERCHANT_001",
    "amount": { "currency": "USD", "value": 9900, "exponent": 2 }
  }
  ```
</ResponseExample>

<Warning>
  This endpoint only works for payments in the `authorized` state. If the payment has already been captured, this call will return an error. Use [Refund](/api-reference/refund) to return funds on a captured payment, or [Cancel or Refund](/api-reference/cancel-or-refund) if you don't know the current state.
</Warning>

<Note>
  When you cancel an authorization, the cardholder's available balance is restored immediately on Therius's side. The reflected timing on the cardholder's bank statement varies by issuer — it's typically instant to a few hours, but can take up to 3–5 business days for some issuers.
</Note>


## OpenAPI

````yaml POST /payment/{id}/cancel
openapi: 3.1.0
info:
  title: Therius API
  description: REST API for payments, subscriptions, and billing plans.
  version: 1.0.0
servers:
  - url: https://api.therius.io/v1
    description: Production
  - url: https://api-sandbox.therius.io/v1
    description: Sandbox
security:
  - bearerAuth: []
paths:
  /payment/{id}/cancel:
    post:
      tags:
        - Payments
      summary: Release an authorization hold
      operationId: cancelPayment
      parameters:
        - $ref: '#/components/parameters/PaymentId'
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - merchantCode
              properties:
                merchantCode:
                  type: string
                  description: >-
                    Your merchant account identifier. Validated against the
                    Bearer key's merchant; required if the key maps to more than
                    one merchant account.
                reference:
                  type: string
                  description: Optional internal reference for this cancellation.
      responses:
        '200':
          description: Cancellation result
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ModificationResponse'
components:
  parameters:
    PaymentId:
      name: id
      in: path
      required: true
      description: >-
        The Therius payment `id` returned by `POST /payment/authorization` or
        `POST /payment/purchase`.
      schema:
        type: string
        format: uuid
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      description: >-
        A UUID you generate per operation. Required in production. Retrying with
        the same key returns the original response.
      schema:
        type: string
        format: uuid
  schemas:
    ModificationResponse:
      type: object
      description: Result of a capture, refund, cancel or cancel_or_refund.
      properties:
        id:
          type: string
          description: The Therius payment `id`.
        merchantCode:
          type: string
        orderCode:
          type: string
        paymentCode:
          type: string
          description: Therius receipt ID.
        amount:
          $ref: '#/components/schemas/Amount'
        status:
          type: string
          enum:
            - captured
            - refunded
            - cancelled
            - failed
          description: Outcome of the operation.
    Amount:
      type: object
      required:
        - currency
        - value
        - exponent
      properties:
        currency:
          type: string
          description: >-
            ISO 4217 currency code. On capture, refund and cancel it must match
            the currency of the original payment.
          example: USD
        value:
          type: integer
          description: >-
            Amount in minor units (cents, pence, etc.). `4999` = $49.99 for USD
            (exponent 2); `5000` = ¥5000 for JPY (exponent 0). On capture it
            must not exceed the authorized value; on refund the cumulative total
            across refunds must not exceed the captured amount.
          example: 4999
        exponent:
          type: integer
          description: >-
            Number of decimal places for the currency — `2` for USD/EUR, `0` for
            JPY. Determines where the decimal point sits in `value`.
          example: 2
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Your secret API key: `Bearer prv_production_xxx` (production) or `Bearer
        prv_sandbox_xxx` (sandbox).

````