transactionsUpdate a transaction

Update a transaction

Edits a transaction. Requires the transactions:write scope, writes_enabled, an Idempotency-Key, and expected_version in the body.

Bank-synced rows are fully editable here: the bank-recorded value of each field is captured at the FIRST user edit, so nothing is destroyed, and revert_to_provider puts it back and hands ownership to the provider again.

409 covers three cases with the same status: expected_version did not match (re-read and retry), the row is a SPLIT parent and the requested category change would have replaced its slices, and revert_to_provider named a field with no captured bank value. A write touching a field this connection's privacy settings hide is 403; changing the currency is 422 field-immutable.

curl -X PATCH "https://api.403fin.io/v1/transactions/123e4567-e89b-12d3-a456-426614174000" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: example_string" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -H "X-API-Key: YOUR_API_KEY" \
  -d '{
  "expected_version": 42,
  "merchant": "example_string",
  "description": "example_string",
  "date": "2024-12-25",
  "amount": "example_string",
  "category_id": "123e4567-e89b-12d3-a456-426614174000",
  "tags": [
    "example_string"
  ],
  "memo": "example_string",
  "location": {
    "street": "example_string",
    "city": "New York",
    "state": "example_string",
    "postal_code": "example_string",
    "country": "USA"
  },
  "clear_location": true,
  "revert_to_provider": [
    "amount"
  ]
}'
{
  "data": {
    "id": "123e4567-e89b-12d3-a456-426614174000",
    "account_id": "123e4567-e89b-12d3-a456-426614174000",
    "category_id": "123e4567-e89b-12d3-a456-426614174000",
    "amount": {
      "amount": "example_string",
      "currency": "example_string"
    },
    "merchant": "example_string",
    "display_name": "John Doe",
    "description": "example_string",
    "date": "2024-12-25",
    "posted_at": "2024-12-25T10:00:00Z",
    "is_pending": true,
    "source": "example_string",
    "payment_channel": "example_string",
    "transfer_pair_id": "123e4567-e89b-12d3-a456-426614174000",
    "recurring_rule_id": "123e4567-e89b-12d3-a456-426614174000",
    "external_ref": "example_string",
    "tags": [
      "example_string"
    ],
    "check_number": "example_string",
    "memo": "example_string",
    "location": {
      "street": "example_string",
      "city": "New York",
      "state": "example_string",
      "postal_code": "example_string",
      "country": "USA"
    },
    "provider_amount": {
      "amount": "example_string",
      "currency": "example_string"
    },
    "provider_merchant_name": "John Doe",
    "provider_transaction_date": "2024-12-25",
    "provider_description": "example_string",
    "provider_memo": "example_string",
    "version": 42,
    "created_at": "2024-12-25T10:00:00Z",
    "updated_at": "2024-12-25T10:00:00Z"
  },
  "pagination": {
    "next_cursor": "example_string",
    "has_more": true
  },
  "redacted_fields": [
    "example_string"
  ],
  "filtered": true
}
PATCH
/v1/transactions/{id}
PATCH
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

An opaque ff_ credential (ff_ak_ / ff_at_) presented as a Bearer token.

An opaque ff_ credential (ff_ak_ / ff_at_) presented as a Bearer token.
API Key (header: X-API-Key)
X-API-Keystring
Required

An opaque ff_ credential presented in the X-API-Key header.

An opaque ff_ credential presented in the X-API-Key header.
path
idstring
Required

The resource UUID.

Format: uuid
Content-Typestring
Required

The media type of the request body

Options: application/json
header
Idempotency-Keystring
Required

A caller-chosen unique key (1-128 chars) that makes the write idempotent. A retry with the SAME key against the SAME operation, resource, and body replays the original response (Idempotency-Replayed: true). The same key with anything different — a changed body, a different endpoint, or a different {id} — is a 409 conflict; a still-in-flight duplicate is 409 with Retry-After. Required on every write. Stored for 24 hours. The key is bound to the target, not only to the payload, so reusing one key across two deletes (which carry no body at all) conflicts rather than replaying the first delete's response.

Min length: 1 • Max length: 128
datestring
Format: date
amountstring

A decimal amount string. The row keeps the currency it settled in.

category_idstring
Format: uuid
tagsarray

Replaces every tag. An empty array clears them all.

memostring

An empty string clears the memo.

locationobject

A purchase location. Redacted as a single unit (transaction.location) — a city plus a postal code answers "where were you" as surely as a street line does, so the components are never hidden separately. On a write it is GROUP-REPLACE: the components sent become the whole stored location and omitted ones are cleared. Use clear_location to remove it entirely.

clear_locationboolean

Removes the whole stored location.

revert_to_providerarray

Restore these fields from what the bank recorded before the row's first user edit, handing ownership back to the provider so later syncs update them again. 409 when there is no captured value to revert to (an unedited row, or a manual one that never had a bank value).

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. An opaque ff_ credential (ff_ak_ / ff_at_) presented as a Bearer token.

header
X-API-Keystring
Required

API Key for authentication. An opaque ff_ credential presented in the X-API-Key header.

Path Parameters

idstring
Required

The resource UUID.

Headers

Idempotency-Keystring
Required

A caller-chosen unique key (1-128 chars) that makes the write idempotent. A retry with the SAME key against the SAME operation, resource, and body replays the original response (Idempotency-Replayed: true). The same key with anything different — a changed body, a different endpoint, or a different {id} — is a 409 conflict; a still-in-flight duplicate is 409 with Retry-After. Required on every write. Stored for 24 hours.

The key is bound to the target, not only to the payload, so reusing one key across two deletes (which carry no body at all) conflicts rather than replaying the first delete's response.

Body

application/json
amountstring

A decimal amount string. The row keeps the currency it settled in.

tagsarray

Replaces every tag. An empty array clears them all.

memostring

An empty string clears the memo.

locationobject

A purchase location. Redacted as a single unit (transaction.location) — a city plus a postal code answers "where were you" as surely as a street line does, so the components are never hidden separately. On a write it is GROUP-REPLACE: the components sent become the whole stored location and omitted ones are cleared. Use clear_location to remove it entirely.

clear_locationboolean

Removes the whole stored location.

revert_to_providerarray

Restore these fields from what the bank recorded before the row's first user edit, handing ownership back to the provider so later syncs update them again. 409 when there is no captured value to revert to (an unedited row, or a manual one that never had a bank value).

Responses

dataobject
Required
paginationstring

Cursor pagination state, present on list endpoints.

redacted_fieldsstring[]

Field ids stripped from the payload by connection scope.

filteredboolean

True when row or aggregate filtering is in effect for this response.