Skip to main content
PATCH
/
v1
/
partner
/
orders
/
{id}
/
status
Transition an order through its state machine
curl --request PATCH \
  --url https://api.dev.shadowchef.co/v1/partner/orders/{id}/status \
  --header 'Authorization: Basic <encoded-value>' \
  --header 'Content-Type: application/json' \
  --header 'Idempotency-Key: <idempotency-key>' \
  --data '
{
  "reason_code": "<string>",
  "occurred_at": "2023-11-07T05:31:56Z"
}
'
{
  "request_id": "req_4d1b7e3f-...",
  "data": {
    "id": "<string>",
    "status": "<string>",
    "updated_at": "2023-11-07T05:31:56Z"
  },
  "error": {
    "code": "auth_invalid_credential",
    "message": "<string>",
    "details": "<unknown>"
  }
}

Authorizations

Authorization
string
header
required

Authorization: Basic base64(partner_key:secret_key).

Credentials are issued by a klikit operator. The plaintext secret_key is shown once at issuance and cannot be retrieved later — store it securely. If lost, ask your operator to rotate the secret to receive a new one. The old secret stops working immediately on rotation; there is no overlap window.

Headers

Idempotency-Key
string
required

Stable client-supplied token. Same key + same body within 24h replays the cached response; same key + different body returns 409 state_idempotency_conflict. Use a UUID per logical write.

Path Parameters

id
string
required

Body

application/json
status
enum<string>
required
Available options:
accepted,
ready,
picked_up,
rejected,
cancelled
reason_code
string

Required for rejected and cancelled transitions.

occurred_at
string<date-time>

Response

Status update accepted

Canonical response wrapper. Every response — success or error — carries the request_id so you can quote one id to klikit support to correlate a request end-to-end.

request_id
string
required
Example:

"req_4d1b7e3f-..."

data
object

Endpoint-specific payload on success.

error
object

Machine-readable error code + human message. The code is stable across releases — switch on code in your client code rather than parsing the message text.

Common codes you will encounter as a partner:

CodeHTTPMeaning
auth_missing401Authorization header absent / malformed
auth_invalid_credential401partner_key or secret_key did not verify
auth_revoked403Credential is revoked
auth_forbidden403Credential not authorized for the requested scope
request_invalid400Body / query parameters failed validation
request_missing_idempotency_key400Write endpoint called without Idempotency-Key
request_invalid_range400Date range > 90 days
resource_not_found404Order / store / mapping does not exist
resource_unmapped404Stock / availability call referenced an unknown SKU
state_invalid_transition409Order PATCH not allowed by current state
state_idempotency_conflict409Same Idempotency-Key reused with a different body
rate_limit_exceeded429Per-credential rate cap hit
downstream_unavailable502An internal klikit dependency is unreachable