curl --request POST \
--url https://api.arcuserp.com/v1/orders/{id}/hold \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"hold_reason": "Pending credit review with finance team.",
"user_id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
}
'import requests
url = "https://api.arcuserp.com/v1/orders/{id}/hold"
payload = {
"hold_reason": "Pending credit review with finance team.",
"user_id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
hold_reason: 'Pending credit review with finance team.',
user_id: 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
})
};
fetch('https://api.arcuserp.com/v1/orders/{id}/hold', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.arcuserp.com/v1/orders/{id}/hold",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'hold_reason' => 'Pending credit review with finance team.',
'user_id' => 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.arcuserp.com/v1/orders/{id}/hold"
payload := strings.NewReader("{\n \"hold_reason\": \"Pending credit review with finance team.\",\n \"user_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.arcuserp.com/v1/orders/{id}/hold")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"hold_reason\": \"Pending credit review with finance team.\",\n \"user_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.arcuserp.com/v1/orders/{id}/hold")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"hold_reason\": \"Pending credit review with finance team.\",\n \"user_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"success": true,
"order_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"hold_type": "manual",
"hold_reason": "<string>"
}
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}Place a manual hold on an order
Places a manual hold on an order (is_on_hold: true, hold_type: 'manual').
Stamps held_at, records held_by, logs a hold_placed timeline event, writes a
HOLD_PLACED activity log entry, and fires an order.hold_placed broadcast.
API callers may only place holds with hold_type: 'manual'. The credit_limit
hold type is set automatically by POST /v1/orders/{id}/confirm when the account
exceeds its credit limit and is not settable via this endpoint.
Guards:
- Order must exist and belong to the entity (Layer 1)
- Order must not already be on hold (400
already_on_hold) - Order must not be in a terminal status:
cancelled,archived(422terminal_status) hold_reasonis required
A user_id is required for the audit trail. API key callers may pass user_id in
the body; if omitted, the API key’s owner user is used as the held-by actor.
Idempotent via Idempotency-Key header. Requires orders:write scope.
Industry parallels:
- Shopify Admin GraphQL
orderHoldmutation (manual reason required) - NetSuite “Place on Credit Hold” per-order override
curl --request POST \
--url https://api.arcuserp.com/v1/orders/{id}/hold \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"hold_reason": "Pending credit review with finance team.",
"user_id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
}
'import requests
url = "https://api.arcuserp.com/v1/orders/{id}/hold"
payload = {
"hold_reason": "Pending credit review with finance team.",
"user_id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
hold_reason: 'Pending credit review with finance team.',
user_id: 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
})
};
fetch('https://api.arcuserp.com/v1/orders/{id}/hold', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.arcuserp.com/v1/orders/{id}/hold",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'hold_reason' => 'Pending credit review with finance team.',
'user_id' => 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.arcuserp.com/v1/orders/{id}/hold"
payload := strings.NewReader("{\n \"hold_reason\": \"Pending credit review with finance team.\",\n \"user_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.arcuserp.com/v1/orders/{id}/hold")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"hold_reason\": \"Pending credit review with finance team.\",\n \"user_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.arcuserp.com/v1/orders/{id}/hold")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"hold_reason\": \"Pending credit review with finance team.\",\n \"user_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"success": true,
"order_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"hold_type": "manual",
"hold_reason": "<string>"
}
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}Authorizations
API key issued per entity via Settings > Developers > API Keys.
Each key carries scopes (e.g. orders:read, products:write).
Bearer token format: Authorization: Bearer ark_live_ent_Test keys use ark_test_ent_. Both are issued per entity
via Settings > Developers > API Keys.
Headers
Client-generated unique key for idempotent POST/PATCH/DELETE operations. Alias for the Idempotency parameter. Max 255 chars. On retry with the same key, the original response is returned without re-executing the operation. Keys expire after 24 hours.
255Path Parameters
UUID of the order to place on hold.
Body
Response
Hold placed successfully.
Show child attributes
Show child attributes
Was this page helpful?

