curl --request PATCH \
--url https://api.arcuserp.com/v1/purchase-orders/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expected_date": "2023-12-25",
"notes": "<string>",
"payment_term_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"location_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"vendor_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "<string>"
}
'import requests
url = "https://api.arcuserp.com/v1/purchase-orders/{id}"
payload = {
"expected_date": "2023-12-25",
"notes": "<string>",
"payment_term_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"location_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"vendor_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
expected_date: '2023-12-25',
notes: '<string>',
payment_term_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
location_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
vendor_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
status: '<string>'
})
};
fetch('https://api.arcuserp.com/v1/purchase-orders/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.arcuserp.com/v1/purchase-orders/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'expected_date' => '2023-12-25',
'notes' => '<string>',
'payment_term_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'location_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'vendor_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'status' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.arcuserp.com/v1/purchase-orders/{id}"
payload := strings.NewReader("{\n \"expected_date\": \"2023-12-25\",\n \"notes\": \"<string>\",\n \"payment_term_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"location_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"vendor_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"status\": \"<string>\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.arcuserp.com/v1/purchase-orders/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expected_date\": \"2023-12-25\",\n \"notes\": \"<string>\",\n \"payment_term_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"location_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"vendor_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"status\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.arcuserp.com/v1/purchase-orders/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expected_date\": \"2023-12-25\",\n \"notes\": \"<string>\",\n \"payment_term_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"location_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"vendor_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"status\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"object": "purchase_order",
"entity_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"po_number": "<string>",
"vendor_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"location_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "draft",
"po_date": "2023-11-07T05:31:56Z",
"expected_date": "2023-11-07T05:31:56Z",
"subtotal": 123,
"tax_total": 123,
"shipping_total": 123,
"po_total": 123,
"currency": "USD",
"notes": "<string>",
"internal_notes": "<string>",
"metadata": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"approved_total": 123,
"approval_stale": true,
"header_editability": {},
"billed_total": 123,
"unbilled_balance": 123
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}Update a purchase order
Updates header-level fields on a purchase order (delivery date, payment due date, receiving location, tracking reference, notes, internal notes). Line items are updated via the items sub-resource.
Editability by stage (2026-08-17). The four OPERATIONAL fields
(expected_date, due_date, location_id, po_tracking_reference) are editable
while the purchase order is draft, open or processing. On fulfilled and
cancelled only notes and internal_notes remain writable, as an annotation. On
archived and expired nothing is writable. While approval_status is pending
only internal_notes is writable. Any other status is treated as locked
(fail-closed). A request that touches a blocked field is refused WHOLE with 422 and
the response names the offending fields in blocked_fields; nothing is partially
applied. Reason codes: po_status_locked, po_status_unknown_locked,
notes_only_on_terminal, po_pending_approval_edit_locked,
po_pending_approval_and_terminal.
NOTE: the previous version of this description claimed header edits were limited to
status: draft and that “orders in approved or later status require a change-order
flow”. Neither was true — this handler had no status gate at all, and approved /
sent are not members of the real order_status vocabulary
(draft / open / processing / fulfilled / cancelled / archived / expired).
Requires purchasing:write scope.
Drop-ship destination (2026-07-10). shipping_address_id is writable ONLY on a
drop-ship-linked PO (a sales-order line sources from it) that is unsent and
unreceived; otherwise 422 po_shipto_not_editable, 409
dropship_po_sent_blocks_shipto_change (change it on the parent sales order with
propagate_to_sent_pos: true instead), or 409
dropship_po_received_blocks_shipto_change. The address must belong to the entity.
curl --request PATCH \
--url https://api.arcuserp.com/v1/purchase-orders/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expected_date": "2023-12-25",
"notes": "<string>",
"payment_term_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"location_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"vendor_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "<string>"
}
'import requests
url = "https://api.arcuserp.com/v1/purchase-orders/{id}"
payload = {
"expected_date": "2023-12-25",
"notes": "<string>",
"payment_term_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"location_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"vendor_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
expected_date: '2023-12-25',
notes: '<string>',
payment_term_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
location_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
vendor_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
status: '<string>'
})
};
fetch('https://api.arcuserp.com/v1/purchase-orders/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.arcuserp.com/v1/purchase-orders/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'expected_date' => '2023-12-25',
'notes' => '<string>',
'payment_term_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'location_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'vendor_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'status' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.arcuserp.com/v1/purchase-orders/{id}"
payload := strings.NewReader("{\n \"expected_date\": \"2023-12-25\",\n \"notes\": \"<string>\",\n \"payment_term_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"location_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"vendor_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"status\": \"<string>\"\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.arcuserp.com/v1/purchase-orders/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expected_date\": \"2023-12-25\",\n \"notes\": \"<string>\",\n \"payment_term_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"location_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"vendor_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"status\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.arcuserp.com/v1/purchase-orders/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expected_date\": \"2023-12-25\",\n \"notes\": \"<string>\",\n \"payment_term_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"location_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"vendor_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"status\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"object": "purchase_order",
"entity_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"po_number": "<string>",
"vendor_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"location_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "draft",
"po_date": "2023-11-07T05:31:56Z",
"expected_date": "2023-11-07T05:31:56Z",
"subtotal": 123,
"tax_total": 123,
"shipping_total": 123,
"po_total": 123,
"currency": "USD",
"notes": "<string>",
"internal_notes": "<string>",
"metadata": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"approved_total": 123,
"approval_stale": true,
"header_editability": {},
"billed_total": 123,
"unbilled_balance": 123
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}{
"error": "not_found",
"code": "not_found",
"type": "not_found",
"hint": "The requested order does not exist or does not belong to this entity.",
"param": "expand[0]",
"required": "accounts:read",
"request_id": "req_abc123"
}Authorizations
API key issued per entity via Settings > Developers > API Keys.
Each key carries scopes (e.g. orders:read, products:write).
Bearer token format: Authorization: Bearer ark_live_ent_Test keys use ark_test_ent_. Both are issued per entity
via Settings > Developers > API Keys.
Path Parameters
Purchase order UUID or PO number (e.g. PO-001234). Polymorphic lookup: if the value is not a UUID it is resolved to a UUID via orders.order_number where document_type=purchase_order within the entity scope. (NEW-GAP-API-V1-POLYMORPHIC-LOOKUP-CROSS-RESOURCE 2026-05-20)
Body
Response
Updated purchase order
A purchase order issued to a vendor.
purchase_order draft, approved, sent, partially_received, received, closed, cancelled The order total as it stood when an approver approved this purchase order -- the basis they actually saw. NULL on every approval predating 2026-08-17 (no backfill) and NULL means "basis unknown", which is treated as fail-safe.
DERIVED, not stored. True when the order is approved AND its total has since risen above approved_total. The purchase order still receives normally; this is a non-blocking prompt to re-approve.
Per-field verdicts for the header fields, from the same predicate the write handlers enforce. Keys: notes, internal_notes, due_date, expected_date, location_id, po_tracking_reference. Each is { allowed: boolean, reason: string|null } where reason is a token from the PoLineEditReason vocabulary.
Show child attributes
Show child attributes
How much of this purchase order's commitment a vendor bill has already taken over: the sum of total over every linked bill in open, partial, paid or written_off. 0 when no bill has been raised, never null.
What the purchase order STILL commits the buyer to: max(order_total - billed_total, 0), cents-quantized. Read this rather than balance_due, which on a purchase order is the ORIGINAL COMMITMENT the header was raised for and is never decremented when a bill is raised (the payable is the bill). Clamped at zero because a vendor may add freight on the bill and over-bill the order.
Was this page helpful?

