# Undo an approved payment-method correction

Source: https://docs.fiest.io/api/reference/undo-payment-correction
Canonical sandbox contract: https://docs.fiest.io/openapi.yaml

## POST /v1/restaurants/{restaurantId}/payment-corrections/undo

Applies an unchanged, explicitly approved undo preview for one exact payment source. Use the same apply contract with action=undo, confirmed=true, the unchanged preview fingerprint, expected revision, expiry, reason, and a UUID idempotency key. Undo writes a reversal in the immutable correction ledger and rechecks the resulting report; it preserves unrelated corrections for the same day. Organization-boundary tokens also require fiest.organization.read; when a token covers several organizations, organization_id must identify an exact organization returned by listOrganizations.

## Authentication

Send an OAuth access token in the `Authorization` header as
`Bearer $FIEST_ACCESS_TOKEN`.

Required scopes: `fiest.restaurant.read`, `fiest.accounting.read`, `fiest.analytics.read`, `fiest.accounting.corrections.write`

## Quick request

```bash
curl --request POST \
  --url 'https://api-sandbox.fiest.io/v1/restaurants/11111111-1111-4111-8111-111111111111/payment-corrections/undo' \
  --header 'Authorization: Bearer $FIEST_ACCESS_TOKEN'
```

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| `restaurantId` | path | Yes | string (uuid) | A restaurant identifier returned by the authorized restaurant list. |
| `organization_id` | query | No | string (uuid) | An organizationId returned by GET /v1/organizations. Required for restaurant-scoped calls when a Management portfolio authorization covers more than one organization; omitted for a single-restaurant authorization and optional for a one-organization grant. |

## Success response

### 200 — The immutable reversal batch and revision result with a rechecked payment report.

```json
{
  "data": {
    "restaurantId": "11111111-1111-4111-8111-111111111111",
    "batchId": "22222222-2222-4222-8222-222222222222",
    "revisionId": "33333333-3333-4333-8333-333333333333",
    "replayed": false,
    "report": {
      "refundReporting": {
        "policy": "refund-event-date/v1",
        "legacyTiming": false,
        "incompleteEvidence": false
      },
      "restaurantId": "11111111-1111-4111-8111-111111111111",
      "scope": "day",
      "period": {
        "startDate": "2026-07-15",
        "endDate": "2026-07-15",
        "timeZone": "Europe/Helsinki",
        "dayStartHour": 4
      },
      "currency": "EUR",
      "rawRows": [
        {
          "key": "card",
          "label": "Card",
          "transactionCount": 459,
          "grossMinor": 2795000,
          "netMinor": 2390000,
          "vatMinor": 405000,
          "grossByRateMinor": null,
          "vatByRateMinor": null
        }
      ],
      "adjustedRows": null,
      "rawTotalMinor": 2795000,
      "adjustedTotalMinor": null,
      "status": "review_required",
      "warnings": [
        {
          "code": "correction_ledger_unavailable",
          "message": "Raw values are available; adjusted values need review.",
          "businessDate": null,
          "correctionId": null
        }
      ],
      "days": [],
      "corrections": [],
      "sources": [],
      "appliedCorrectionIds": [],
      "rawSourceBasis": "services_accounting",
      "calculationVersion": "services-accounting/payment-report/1",
      "schemaVersion": null,
      "currentSourceFingerprint": null,
      "readOnly": true
    }
  }
}
```

## Error responses

### 400 — The request parameters are invalid.

```json
{
  "error": "invalid_request",
  "message": "The requested date range is invalid.",
  "request_id": "req_sandbox_invalid_request"
}
```

### 401 — The access token is missing, invalid, or expired.

```json
{
  "error": "invalid_token",
  "error_description": "The access token is invalid.",
  "request_id": "req_sandbox_invalid_token"
}
```

### 403 — The authorization has expired or does not include the required scope.

```json
{
  "error": "insufficient_scope",
  "error_description": "The operation requires an OAuth scope that is not granted.",
  "request_id": "req_sandbox_insufficient_scope"
}
```

### 404 — The restaurant or requested resource does not exist or is outside the authorization.

```json
{
  "error": "not_found",
  "request_id": "req_sandbox_not_found"
}
```

### 409 — The write conflicts with current state, its idempotency key, or an active external integration.

```json
{
  "error": "conflict",
  "request_id": "req_sandbox_conflict"
}
```

### 413 — The JSON request body exceeds one megabyte.

```json
{
  "error": "payload_too_large",
  "request_id": "req_sandbox_payload_too_large"
}
```

### 429 — The partner request limit has been exceeded.

```json
{
  "error": "rate_limited",
  "request_id": "req_sandbox_rate_limited"
}
```

### 503 — The capability is disabled in this environment or a required service is unavailable.

```json
{
  "error": "capability_disabled",
  "request_id": "req_sandbox_capability_disabled"
}
```

## Related

- [Quick start](https://docs.fiest.io/api/quickstart)
- [Stable API errors](https://docs.fiest.io/api/reference/errors)
- [OpenAPI 3.1 contract, YAML](https://docs.fiest.io/openapi.yaml)
- [OpenAPI 3.1 contract, JSON](https://docs.fiest.io/openapi.json)
- [Authorize and call the Fiest Partner API](https://docs.fiest.io/api/quickstart)