> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arcuserp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Purchase a package shipping label

> Purchases a carrier shipping label for a package using a previously fetched rate, saving the label URL and tracking number to the package. Returns 409 with code `order_not_spendable` if the package's order is cancelled, archived, or expired, evaluated immediately before the carrier is called; idempotent via the `Idempotency-Key` header.



## OpenAPI

````yaml /openapi.yaml post /packages/{id}/buy-label
openapi: 3.1.0
info:
  title: Arcus ERP Public API
  version: 1.0.0
  description: >
    Arcus ERP public REST API. Designed for external integrations and data
    migration.


    **Authentication.** Bearer token (API key) via the `Authorization` header.

    Format: `Authorization: Bearer ark_live_ent_<code>_<random>` (or
    `ark_test_*` for sandbox).

    API keys are issued per-entity in **Settings > Developers > API Keys**.


    **Entity scoping.** The entity is encoded in the API key prefix; routes are
    flat

    (e.g. `/v1/accounts`, `/v1/orders`, `/v1/products`). A small set of platform
    endpoints

    (migration, reconciliation, events, webhook endpoints, API keys) use the

    `/v1/entities/{entity_id}/...` form -- those are noted in their tags.


    **Key capabilities.**
      - Related-resource hydration via `?expand[]=` (see `x-arcus-expand` on each resource).
      - Cursor-based pagination (`starting_after` / `ending_before` / `limit`).
      - Idempotency via the `Idempotency-Key` header.
      - Webhook events for asynchronous notification.
      - Conditional requests / ETag for cache validation.

    **Changelog.** Entries are dated and name every published contract whose
    MEANING moved, not

    only the ones whose field names changed. The narrative version of the same
    entries, written

    for integrators, is published at https://arcuserp.mintlify.app/changelog.


    **2026-09-22 (planned 2026-09-21), REORDER-BUYER-TRUTH: demand changed what
    it MEANS on three

    published contracts, with no field renamed.** An integrator that pins field
    names sees no

    breakage and different numbers, which is why this entry exists.

      - **Demand now counts build consumption.** `demand_avg_per_day` on the public product, kit
        and inventory-balance objects, and `daily_demand` / `demand_basis` / `net_suggested_qty`
        on `GET /v1/purchasing/reorder-report`, are composed from fulfilled sales lines PLUS
        posted `build_consume` inventory draws: each physical decrement of a product counts
        exactly once. The previous rule adopted an internal-consumption basis only when the sales
        blend was exactly zero, so a product both sold AND consumed into work orders planned as
        if the build draws did not exist. Products drawn into work orders move; on one
        production-shaped dataset five did, the largest from 0.05/day to 14.95/day.
      - **`demand_basis` now carries four values, not two:** `sales`, `sales_and_builds`,
        `builds` and `consumption`. A consumer with a two-branch reader (anything that is not
        `consumption` is `sales`) silently hides the two new ones.
      - **`current_demand_units` on `GET /v1/inventory/balances/:id` moved, by a second rule.**
        It counts committed-but-unshipped CUSTOMER demand, and it now counts a kit component's
        own line rather than its parent kit line, and excludes non-sales documents. On one
        production dataset 269 of 1,043 balance rows changed, 227 of them downward; the largest
        single move was 1,941 to 25, on a product whose open PURCHASE order line had been
        reported as customer demand. Re-baseline anything that alerts or reorders off this field.
      - `run_rate_30/90/180/365` and `blended_daily` on the same balance object move for the
        first reason above.
      - **Added, not changed:** `GET /v1/purchasing/reorder-report` accepts `demand_window` and
        returns the unit, cover-through and reorder-point-provenance fields documented on that
        operation; `order_multiple` is accepted and returned on the product-vendor doors.
      - **Volume note.** The `inventory.low_stock`, `inventory.out_of_stock` and
        `inventory.back_in_stock` webhook events are population-gated on
        `on_hand <= reorder_point`, and reorder points move with the demand above, so
        subscribers should expect a one-time step change in event volume around the release.
servers:
  - url: https://api.arcuserp.com/v1
    description: Arcus ERP API (accepts both live `ark_live_*` and test `ark_test_*` keys)
  - url: https://dev-api.arcuserp.com/v1
    description: >-
      Dev sandbox API (test-only data, accepts `ark_test_*` keys against dev
      RDS)
security: []
paths:
  /packages/{id}/buy-label:
    parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
          format: uuid
    post:
      tags:
        - Fulfillment
      summary: Purchase a package shipping label
      description: >-
        Purchases a carrier shipping label for a package using a previously
        fetched rate, saving the label URL and tracking number to the package.
        Returns 409 with code `order_not_spendable` if the package's order is
        cancelled, archived, or expired, evaluated immediately before the
        carrier is called; idempotent via the `Idempotency-Key` header.
      operationId: buyPackageLabel
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                rate_object_id:
                  type: string
                carrier:
                  type: string
                service_token:
                  type: string
                service_name:
                  type: string
                shipment_object_id:
                  type: string
                parcel_object_id:
                  type: string
                estimated_amount:
                  type: number
                label_file_type:
                  type: string
                  enum:
                    - PDF
                    - ZPLII
                    - PNG
                  default: PDF
      responses:
        '200':
          description: >
            Purchased label record.
            NEW-GAP-RERATE-SHIPPING-CHARGE-DELTA-WORKFLOW

            (2026-05-16): the response now includes a `shipping_cost_analysis`

            block when the carrier cost diverges from what the customer was

            charged for shipping. When `suggest_action !== 'absorb'`, the

            operator (or a downstream automation) should call

            `POST /packages/{id}/recharge-label` to settle the delta.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/PackageLabel'
                  - type: object
                    properties:
                      shipping_cost_analysis:
                        nullable: true
                        type: object
                        description: |
                          Carrier-cost-vs-customer-charged delta. Null when
                          the analysis could not be computed (logged
                          server-side as a non-blocking warning).
                        properties:
                          customer_charged:
                            type: number
                            description: orders.shipping_total at time of label purchase
                          carrier_cost:
                            type: number
                            description: just-purchased label actual_amount
                          delta:
                            type: number
                            description: |
                              carrier_cost - customer_charged. Positive means
                              Arcus is absorbing cost (upgrade case); negative
                              means customer overpaid.
                          suggest_action:
                            type: string
                            enum:
                              - recharge
                              - refund_overpay
                              - absorb
                            description: |
                              recharge -- delta > threshold; bill the customer
                              refund_overpay -- delta < -threshold; refund
                              absorb -- |delta| <= threshold; no operator action
                          threshold:
                            type: number
                            description: per-entity setting, default $2
                          label_id:
                            type: string
                            format: uuid
                            nullable: true
                          package_id:
                            type: string
                            format: uuid
                            nullable: true
                          order_id:
                            type: string
                            format: uuid
                            nullable: true
        '400':
          $ref: '#/components/responses/Error'
        '401':
          $ref: '#/components/responses/Error'
        '403':
          $ref: '#/components/responses/Error'
        '404':
          $ref: '#/components/responses/Error'
        '409':
          description: |
            `order_not_spendable` -- the package's order is terminal (cancelled,
            archived, or expired) and cannot buy carrier labels. Body carries
            `order_status` and `order_number` alongside the standard error
            envelope. CANCEL-PACKAGE-LIFECYCLE WS-A, 2026-07-27.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
                  - type: object
                    properties:
                      order_status:
                        type: string
                        enum:
                          - cancelled
                          - archived
                          - expired
                      order_number:
                        type: string
                        nullable: true
        '422':
          $ref: '#/components/responses/Error'
      security:
        - ApiKeyAuth: []
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: false
      description: |
        Client-generated unique key for idempotent POST/PATCH/DELETE operations.
        Alias for the Idempotency parameter. Max 255 chars. On retry with the
        same key, the original response is returned without re-executing the
        operation. Keys expire after 24 hours.
      schema:
        type: string
        maxLength: 255
  schemas:
    PackageLabel:
      type: object
      description: >
        A shipping label purchased from a carrier (typically Shippo). One label
        per package.

        URLs expire 30 days after purchase; persist the PDF locally for
        long-term retention.
      properties:
        id:
          type: string
          format: uuid
        package_id:
          type: string
          format: uuid
        carrier:
          type: string
        service_level:
          type: string
        tracking_number:
          type: string
        label_url:
          type: string
          description: Carrier-hosted PDF URL (time-limited).
        label_pdf_url:
          type: string
          nullable: true
          description: Arcus-archived PDF URL (permanent).
        purchased_cost:
          type: number
          description: Amount Arcus paid the carrier.
        billed_cost:
          type: number
          nullable: true
          description: Amount billed to the customer.
        purchased_at:
          type: string
          format: date-time
          readOnly: true
        voided_at:
          type: string
          format: date-time
          nullable: true
          readOnly: true
    Error:
      description: |
        Alias for ErrorEnvelope. Canonical error response shape used by all
        API endpoints. Refer to ErrorEnvelope for the full field definition.
      allOf:
        - $ref: '#/components/schemas/ErrorEnvelope'
    ErrorEnvelope:
      type: object
      description: |
        Canonical error response envelope. All API errors use this shape.
      required:
        - error
        - code
      properties:
        error:
          type: string
          description: Machine-readable error key
          example: not_found
        code:
          type: string
          description: Machine-readable error code (often same as error)
          example: not_found
        type:
          type: string
          enum:
            - validation_error
            - permission_error
            - not_found
            - conflict
            - rate_limit
            - internal
            - expand_error
            - not_implemented
          example: not_found
        hint:
          type: string
          description: Human-readable one-sentence explanation (English)
          example: >-
            The requested order does not exist or does not belong to this
            entity.
        param:
          type: string
          description: The parameter that caused the error, if applicable
          example: expand[0]
        required:
          type: string
          description: The scope required (only on insufficient_scope errors)
          example: accounts:read
        request_id:
          type: string
          description: >-
            Unique request ID for support tracing (maps to CloudWatch log
            stream)
          example: req_abc123
  responses:
    Error:
      description: Error response (400/401/403/404/409/422/429/500)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      description: |
        API key issued per entity via Settings > Developers > API Keys.
        Each key carries scopes (e.g. orders:read, products:write).
        Bearer token format: Authorization: Bearer ark_live_ent_<code>_<random>
        Test keys use ark_test_ent_<code>_<random>. Both are issued per entity
        via Settings > Developers > API Keys.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.