> ## Documentation Index
> Fetch the complete documentation index at: https://docs.waffo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cancel One-Time Order

> Cancel a pending one-time order before payment is completed

Cancel a pending one-time order. Only orders in `pending` status can be canceled.

```
POST /v1/actions/onetime-order/cancel-order
```

**Authentication:** Session Token — see [Customer Endpoints](/api-reference/endpoints/auth/customer-endpoints) (customer or customer role)

## Cancellation Behavior

| Current Status | Action           | Result Status        |
| -------------- | ---------------- | -------------------- |
| `pending`      | Immediate cancel | `canceled`           |
| `completed`    | Rejected         | unchanged (terminal) |
| `canceled`     | Rejected         | unchanged (terminal) |

<Note>
  * **pending**: The order is canceled immediately and its status becomes `canceled`
  * The underlying PSP checkout session expires automatically — there is no separate PSP cancel call to make
  * `completed` and `canceled` are terminal states and cannot be canceled again
</Note>

## Request Body

| Field     | Type   | Required | Description                                   |
| --------- | ------ | -------- | --------------------------------------------- |
| `orderId` | string | Yes      | One-time order ID (Short ID format `ORD_xxx`) |

## Example Request

<CodeGroup>
  ```typescript TypeScript (SDK) theme={"system"}
  import { WaffoPancake } from "@waffo/pancake-ts";

  const client = new WaffoPancake({
    sessionToken: window.WAFFO_SESSION_TOKEN, // injected by the merchant's portal
    environment: "prod",
  });

  const result = await client.orders.cancelOnetime({
    orderId: "ORD_2aUyqjCzEIiEcYMKj7TZtw",
  });

  console.log(result.orderId); // "ORD_2aUyqjCzEIiEcYMKj7TZtw"
  console.log(result.status);  // "canceled"
  ```

  ```typescript TypeScript (Manual) theme={"system"}
  const result = await fetch("https://api.waffo.ai/v1/actions/onetime-order/cancel-order", {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${SESSION_TOKEN}`,
      "Content-Type": "application/json",
      "X-Environment": "prod",
    },
    body: JSON.stringify({
      orderId: "ORD_2aUyqjCzEIiEcYMKj7TZtw",
    }),
  }).then(r => r.json());
  ```

  ```bash cURL theme={"system"}
  curl -X POST "https://api.waffo.ai/v1/actions/onetime-order/cancel-order" \
    -H "Authorization: Bearer $SESSION_TOKEN" \
    -H "Content-Type: application/json" \
    -H "X-Environment: prod" \
    -d '{"orderId":"ORD_2aUyqjCzEIiEcYMKj7TZtw"}'
  ```

  ```bash wget theme={"system"}
  wget -qO- \
    --header="Authorization: Bearer $SESSION_TOKEN" \
    --header="Content-Type: application/json" \
    --header="X-Environment: prod" \
    --post-data='{"orderId":"ORD_2aUyqjCzEIiEcYMKj7TZtw"}' \
    "https://api.waffo.ai/v1/actions/onetime-order/cancel-order"
  ```
</CodeGroup>

## Success Response (200)

```json theme={"system"}
{
  "data": {
    "orderId": "ORD_2aUyqjCzEIiEcYMKj7TZtw",
    "status": "canceled"
  }
}
```

### Response Fields

| Field     | Type   | Description                                     |
| --------- | ------ | ----------------------------------------------- |
| `orderId` | string | Order ID (Short ID)                             |
| `status`  | string | New order status (always `canceled` on success) |

## Errors

> **Retry policy:** Never retry 4xx — fix the request and resubmit. Retry 5xx with exponential backoff (start 5s, max 3 attempts).

| Status | `errors[0].message`                           | What it means                                                          | Recommended handling                                      |
| ------ | --------------------------------------------- | ---------------------------------------------------------------------- | --------------------------------------------------------- |
| 400    | `Missing required field: orderId`             | `orderId` was not provided in the body                                 | Fix the request body, then resubmit                       |
| 400    | `Expected format: ORD_xxx, got "..."`         | `orderId` Short ID could not be decoded                                | Fix the `orderId` format, then resubmit                   |
| 400    | `Order cannot be canceled, current status: X` | Order status is not `pending` (e.g. already `completed` or `canceled`) | The order is no longer cancellable                        |
| 401    | `Authentication failed`                       | Session token invalid, expired, or malformed                           | Re-mint the session token via Issue Session Token         |
| 403    | `Order does not belong to user`               | Ownership check failed                                                 | Verify the caller owns the order                          |
| 404    | `Order not found`                             | Order does not exist                                                   | Verify the order ID                                       |
| 500    | `Internal server error`                       | Unexpected server-side failure                                         | Retry with exponential backoff (start 5s, max 3 attempts) |
