---
title: Flag Order as Fraud
slug: api-documentation/flag-order-as-fraud
docTags: 
createdAt: 2026-08-27T16:57:40.129Z
---

{
  "id": "iNIhZ4AlrFv1US9XTXtTD",
  "type": "api-oas-v2",
  "data": {
    "method": "POST",
    "url": "https://api.upstartcommerce.com/v1/order/{orderId}/fraud",
    "servers": [
      {
        "url": "https://api.upstartcommerce.com/v1/order/{orderId}/fraud"
      }
    ],
    "name": "Flag Order as Fraud",
    "description": "<p>This endpoint allows administrators to flag an order as fraudulent.</p>\n<p>Authorized permissions:</p>\n<ul>\n<li><code>order.update</code></li>\n</ul>",
    "contentType": "application/json",
    "request": {
      "pathParameters": [
        {
          "kind": "required",
          "name": "orderId",
          "type": "string<uuid>",
          "description": "The parameterized order id in the URI.",
          "format": "uuid"
        }
      ],
      "headerParameters": [
        {
          "kind": "required",
          "name": "x-upstart-tenant",
          "type": "string",
          "description": "Tenant identifier associated with the site this call is for."
        }
      ],
      "queryParameters": [],
      "bodyDataParameters": [],
      "formDataParameters": [],
      "oAuthParameters": [
        {
          "id": "NoChannelPortalAccess",
          "name": "NoChannelPortalAccess",
          "kind": "optional",
          "type": "http",
          "description": "<p>This authentication is required for clients to interact with any of the management APIs. Similar to 'LoggedIn', it indicates that the user has actually logged into the system, but in this case with a management role.</p>",
          "scheme": "bearer"
        },
        {
          "id": "ApiKeyAccess",
          "name": "X-Upstart-Api-Key",
          "kind": "optional",
          "type": "apiKey",
          "description": "Api key based authorization.",
          "in": "header"
        },
        {
          "id": "SessionIdAccess",
          "name": "X-Upstart-Session-Id",
          "kind": "optional",
          "type": "apiKey",
          "description": "<p>Session based authorization. This authentication is required for clients to interact with any of the management APIs. Similar to 'LoggedIn', it indicates that the user has actually logged into the system, but in this case with a management role.</p>",
          "in": "header"
        }
      ],
      "cookieParameters": []
    },
    "responses": [
      {
        "statusCode": "200",
        "description": "<p>Success-order flagged as fraud.</p>",
        "jsonExample": "",
        "isExpanded": true
      },
      {
        "statusCode": "401",
        "description": "The provided credentials were not valid for this endpoint. It may be that they are expired or that the user's roles are insufficient.",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "description": "",
            "customType": "ErrorResponse",
            "schema": [
              {
                "name": "name",
                "kind": "required",
                "type": "string",
                "description": ""
              },
              {
                "name": "code",
                "kind": "required",
                "type": "string",
                "description": ""
              },
              {
                "name": "detail",
                "kind": "required",
                "type": "string",
                "description": ""
              },
              {
                "name": "reason",
                "kind": "optional",
                "type": "string",
                "description": ""
              }
            ],
            "modelRef": "#/components/schemas/ErrorResponse",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "404",
        "description": "The requested resource was not found in the NoChannel system.",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "description": "",
            "customType": "ErrorResponse",
            "schema": [
              {
                "name": "name",
                "kind": "required",
                "type": "string",
                "description": ""
              },
              {
                "name": "code",
                "kind": "required",
                "type": "string",
                "description": ""
              },
              {
                "name": "detail",
                "kind": "required",
                "type": "string",
                "description": ""
              },
              {
                "name": "reason",
                "kind": "optional",
                "type": "string",
                "description": ""
              }
            ],
            "modelRef": "#/components/schemas/ErrorResponse",
            "isExpanded": true
          }
        ]
      }
    ],
    "hasXCodeSamples": false,
    "examples": {
      "languages": [
        {
          "id": "WnAXThuTik1UeJYpnZe01",
          "language": "curl",
          "label": "cURL",
          "code": "curl --request POST \\\n     --url https://api.upstartcommerce.com/v1/order/{orderId}/fraud \\\n     --header 'accept: application/json' \\\n     --header 'x-upstart-tenant: string'"
        },
        {
          "id": "QGTGOkfAfExiVevWTXMqx",
          "language": "javascript",
          "label": "javascript",
          "code": "var myHeaders = new Headers();\nmyHeaders.append(\"accept\", \"application/json\");\nmyHeaders.append(\"content-type\", \"application/json\");\nmyHeaders.append(\"x-upstart-tenant\", \"string\");\n\nvar requestOptions = {\n   method: 'POST',\n   headers: myHeaders,\n   redirect: 'follow'\n};\n\nfetch(\"https://api.upstartcommerce.com/v1/order/{orderId}/fraud\", requestOptions)\n   .then(response => response.text())\n   .then(result => console.log(result))\n   .catch(error => console.log('error', error));"
        },
        {
          "id": "pOOBvI_WnMXk7sowG6chb",
          "language": "ruby",
          "label": "Ruby",
          "code": "require \"uri\"\nrequire \"json\"\nrequire \"net/http\"\n\nurl = URI(\"https://api.upstartcommerce.com/v1/order/{orderId}/fraud\")\n\nhttps = Net::HTTP.new(url.host, url.port)\nhttps.use_ssl = true\n\nrequest = Net::HTTP::Post.new(url)\nrequest[\"accept\"] = \"application/json\"\nrequest[\"content-type\"] = \"application/json\"\nrequest[\"x-upstart-tenant\"] = \"string\"\n\nresponse = https.request(request)\nputs response.read_body\n"
        },
        {
          "id": "I9EUo7zLRj6l3nNaOou2s",
          "language": "python",
          "label": "Python",
          "code": "import requests\nimport json\n\nurl = \"https://api.upstartcommerce.com/v1/order/{orderId}/fraud\"\n\npayload = {}\nheaders = {\n   'accept': 'application/json',\n   'content-type': 'application/json',\n   'x-upstart-tenant': 'string'\n}\n\nresponse = requests.request(\"POST\", url, headers=headers, data=payload)\n\nprint(response.text)\n"
        }
      ],
      "selectedLanguageId": "WnAXThuTik1UeJYpnZe01"
    },
    "results": {
      "languages": [
        {
          "id": "LaFv1ztLo4j6UiIC2IvEs",
          "language": "200",
          "code": "// Success-order flagged as fraud.\n"
        },
        {
          "id": "uu_3pugWNG6QUXAiBObj5",
          "language": "401",
          "code": "// The provided credentials were not valid for this endpoint. It may be that they are expired or that the user's roles are insufficient.\n{\n  \"name\": \"\",\n  \"code\": \"\",\n  \"detail\": \"\",\n  \"reason\": \"\"\n}"
        },
        {
          "id": "wZOHE2FnI5gLIA6O1L9wx",
          "language": "404",
          "code": "// The requested resource was not found in the NoChannel system.\n{\n  \"name\": \"\",\n  \"code\": \"\",\n  \"detail\": \"\",\n  \"reason\": \"\"\n}"
        }
      ],
      "selectedLanguageId": "LaFv1ztLo4j6UiIC2IvEs"
    }
  },
  "children": [
    {
      "text": ""
    }
  ]
}