> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oncanary.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace usage or transition work-order part status

> Reuse the identical command and idempotency key after an uncertain response. Refetch the section after a version conflict. Issued quantity edits append stock corrections.



## OpenAPI

````yaml /openapi.yaml post /work-orders/{id}/parts
openapi: 3.1.0
info:
  title: Canary API
  version: '1.0'
  description: >
    Build integrations around Canary work orders, requests, equipment,
    inventory, meters,

    custom fields, and scannable identifiers.


    ## Authentication


    All API requests require authentication using an API key. Include your API
    key in the `Authorization` header:


    ```

    Authorization: Bearer sk_live_your_api_key_here

    ```


    ## Rate Limits


    - **Live keys**: 1,000 requests per minute

    - **Test keys**: 100 requests per minute


    Both key prefixes access the same organization data. The prefix selects the
    rate-limit bucket.


    Successful authenticated responses include rate limit headers:

    - `X-RateLimit-Limit`: Maximum requests per window

    - `X-RateLimit-Remaining`: Requests remaining in current window

    - `X-RateLimit-Reset`: Unix timestamp when the window resets


    ## Pagination


    Canary-native list endpoints use ID cursors and the standard `data`/`meta`
    envelope.

    MaintainX-compatible request endpoints use their compatibility response
    wrappers and

    encoded offset cursors. Follow each operation's response schema.


    Native list responses include:

    - `data`: Array of items

    - `meta.pagination.cursor`: Cursor for the next page (if `has_more` is true)

    - `meta.pagination.has_more`: Whether more items exist


    Use the cursor value in your next request: `?cursor=<cursor_value>`
servers:
  - url: https://api.oncanary.com/v1
    description: Production
  - url: http://localhost:3000/api/v1
    description: Local Development
security:
  - bearerAuth: []
tags:
  - name: Meters
    description: Meters track equipment usage and readings
  - name: Meter Readings
    description: Record and retrieve meter readings
  - name: Work Orders
    description: Maintenance work orders
  - name: Work Requests
    description: Requests that can be reviewed and converted into work orders
  - name: Work Request Portals
    description: Public request portal configuration
  - name: Assets
    description: Equipment and machinery
  - name: Locations
    description: Physical places where assets, parts, and meters are assigned
  - name: Parts
    description: Spare parts and inventory records
  - name: Identifiers
    description: Scannable identifiers for assets, locations, and parts
  - name: Custom Fields
    description: Typed custom-field definitions shared by maintenance resources
paths:
  /work-orders/{id}/parts:
    post:
      tags:
        - Work Orders
      summary: Replace usage or transition work-order part status
      description: >-
        Reuse the identical command and idempotency key after an uncertain
        response. Refetch the section after a version conflict. Issued quantity
        edits append stock corrections.
      operationId: commandWorkOrderParts
      parameters:
        - $ref: '#/components/parameters/id'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WorkOrderPartsCommand'
      responses:
        '200':
          description: >-
            Direct mutation result; replayed indicates a previously accepted
            command
          content:
            application/json:
              schema:
                type: object
                required:
                  - workOrderId
                  - partStatus
                  - aggregateVersion
                  - replayed
                  - affectedPartIds
                  - competingWorkOrderIds
                properties:
                  workOrderId:
                    type: string
                  partStatus:
                    $ref: '#/components/schemas/WorkOrderPartStatus'
                  aggregateVersion:
                    type: string
                  replayed:
                    type: boolean
                  affectedPartIds:
                    type: array
                    items:
                      type: string
                  competingWorkOrderIds:
                    type: array
                    items:
                      type: string
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  parameters:
    id:
      name: id
      in: path
      required: true
      description: Resource ID
      schema:
        type: string
  schemas:
    WorkOrderPartsCommand:
      oneOf:
        - type: object
          additionalProperties: false
          required:
            - operation
            - idempotencyKey
            - expectedAggregateVersion
            - targetStatus
          properties:
            operation:
              type: string
              const: transition
            idempotencyKey:
              type: string
              minLength: 1
              maxLength: 512
            expectedAggregateVersion:
              type: string
              pattern: ^[0-9a-f]{64}$
            targetStatus:
              $ref: '#/components/schemas/WorkOrderPartStatus'
            confirmOvercommit:
              type: boolean
              default: false
        - type: object
          additionalProperties: false
          required:
            - operation
            - idempotencyKey
            - expectedAggregateVersion
            - items
          properties:
            operation:
              type: string
              const: replace
            idempotencyKey:
              type: string
              minLength: 1
              maxLength: 512
            expectedAggregateVersion:
              type: string
              pattern: ^[0-9a-f]{64}$
            items:
              type: array
              maxItems: 1000
              items:
                type: object
                additionalProperties: false
                required:
                  - id
                  - partId
                  - locationId
                  - quantity
                properties:
                  id:
                    type: string
                    pattern: ^[A-Za-z0-9][A-Za-z0-9_-]{0,127}$
                  partId:
                    type: string
                    pattern: ^[A-Za-z0-9][A-Za-z0-9_-]{0,127}$
                  locationId:
                    type: string
                    pattern: ^[A-Za-z0-9][A-Za-z0-9_-]{0,127}$
                  quantity:
                    type: integer
                    minimum: 1
                    maximum: 2147483647
                  unitCostMinor:
                    type: integer
                    minimum: 0
                    maximum: 2147483647
    WorkOrderPartStatus:
      type: string
      enum:
        - assigned
        - reserved
        - kitted
        - staged
        - issued
    ProblemDetails:
      type: object
      description: RFC 7807 Problem Details
      required:
        - type
        - title
        - status
        - detail
        - request_id
        - code
      example:
        type: https://api.oncanary.com/errors/validation_error
        title: Validation Error
        status: 400
        detail: Request validation failed
        request_id: req_01JAY8FVDM6CH4R3X9Q2T7K5NP
        code: validation_error
      properties:
        type:
          type: string
          format: uri
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
        request_id:
          type: string
        code:
          type: string
        validation_errors:
          type: array
          items:
            type: object
            required:
              - field
              - message
            properties:
              field:
                type: string
              message:
                type: string
  responses:
    BadRequest:
      description: Bad Request
      headers:
        X-Request-ID:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    Unauthorized:
      description: Unauthorized - Invalid or missing API key
      headers:
        X-Request-ID:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    Forbidden:
      description: >-
        Forbidden - `insufficient_scope` when the API key lacks the scope, or
        `module_disabled` when the organization module is disabled
      headers:
        X-Request-ID:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    NotFound:
      description: Resource not found
      headers:
        X-Request-ID:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    Conflict:
      description: Resource state conflicts with the requested operation
      headers:
        X-Request-ID:
          $ref: '#/components/headers/RequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    RateLimited:
      description: Rate limit exceeded
      headers:
        X-Request-ID:
          $ref: '#/components/headers/RequestId'
        Retry-After:
          description: Seconds until rate limit resets
          schema:
            type: integer
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
  headers:
    RequestId:
      description: Unique request identifier to include with support requests
      schema:
        type: string
        example: req_01JAY8FVDM6CH4R3X9Q2T7K5NP
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Organization API key with an `sk_live_` or `sk_test_` prefix

````