> This page is for Afterpay Online Developer, version v1.
> For other versions, use one of these documentation indexes:
> - Main (default): https://developers.afterpay.com/afterpay-online-developer/main/llms.txt
> - v1: https://developers.afterpay.com/afterpay-online-developer/v-1/llms.txt
> - Chinese: https://developers.afterpay.com/afterpay-online-developer/chinese/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.afterpay.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.afterpay.com/_mcp/server.

# Update Payment

PUT https://global-api-sandbox.afterpay.com/v1/payments/{orderID}/environment:{environment}
Content-Type: application/json

This end point is for merchants that creates merchant side's order id after AfterPay order id creation. Merchants should call immediately after the AfterPay order is created in order to properly update with their order id that can be tracked.

Reference: https://developers.afterpay.com/afterpay-online-developer/api-reference/reference/payments/update-payment-by-order-id

## Authentication

- `Authorization` header (basic auth, required) — Basic authentication of the form `Basic <base64(username:password)>`.

## Request

### Path parameters

- `environment` (string, required) — Use `api-sandbox` for AU/NZ, or `api.us-sandbox` for US.
- `orderID` (string, required) — The Order ID to update

### Headers

- `Accept` (string, optional, default: application/json)

### Body (application/json)

This endpoint expects an object.

- `merchantReference` (string, required, default: new_merchan_order_id_1234) — The merchant’s new order id to replace with

## Response

### 200

Returns object containing the following attributes: | Attribute | Type | Description | | --------- | ---- | ----------- | | id | string | The unique Afterpay (merchant payment) payment Id | | token | string | Checkout token to be used to complete consumer checkout and payment. | | status | string | `APPROVED` (update is only valid for successful orders) | | created | string (ISO-8601) | The payment creation time (ISO 8601 UTC/Zulu time). | | originalAmount | Money object | Total amount for the order. | | openToCaptureAmount | Money object | Total amount that can be captured for order. | | paymentState | string | Available states: `AUTH_APPROVED`, `CAPTURED`, `VOIDED`, `EXPIRED`, `AUTH_DECLINED`, `PARTIALLY_CAPTURED`, CAPTURE_DECLINED` | | merchantReference | string | The merchant’s order id/reference that this payment corresponds to. | | refunds | Refund object | The refund details for merchant's order | | orderDetails | Order Details object | The order bound to the payment. | | events | Events object | Event list for for merchant's order. |

## Errors

### 404 Not Found Error

The Afterpay payment Id to update was not found.

- `any`

## Examples

**Request**

```json
{
  "merchantReference": "new_merchan_order_id_1234"
}
```

**Response**

```json
{}
```

**SDK Code**

```python
import requests

url = "https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment"

payload = { "merchantReference": "new_merchan_order_id_1234" }
headers = {
    "User-Agent": "User-Agent"
    "Content-Type": "application/json"
}

response = requests.put(url, json=payload, headers=headers, auth=("<username>", "<password>"))

print(response.json())
```

```javascript
const url = 'https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment';
const credentials = btoa("<username>:<password>");

const options = {
  method: 'PUT',
  headers: {
    'User-Agent': 'User-Agent',
    Authorization: `Basic ${credentials}`,
    'Content-Type': 'application/json'
  },
  body: '{"merchantReference":"new_merchan_order_id_1234"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment"

	payload := strings.NewReader("{\n  \"merchantReference\": \"new_merchan_order_id_1234\"\n}")

	req, _ := http.NewRequest("PUT", url, payload)

	req.Header.Add("User-Agent", "User-Agent")
	req.SetBasicAuth("<username>", "<password>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Put.new(url)
request["User-Agent"] = 'User-Agent'
request.basic_auth("<username>", "<password>")
request["Content-Type"] = 'application/json'
request.body = "{\n  \"merchantReference\": \"new_merchan_order_id_1234\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.put("https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment")
  .header("User-Agent", "User-Agent")
  .basicAuth("<username>", "<password>")
  .header("Content-Type", "application/json")
  .body("{\n  \"merchantReference\": \"new_merchan_order_id_1234\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment', [
  'body' => '{
  "merchantReference": "new_merchan_order_id_1234"
}',
  'headers' => [
    'Content-Type' => 'application/json',
    'User-Agent' => 'User-Agent',
  ],
    'auth' => ['<username>', '<password>'],
]);

echo $response->getBody();
```

```csharp
using RestSharp;
using RestSharp.Authenticators;

var client = new RestClient("https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment");
client.Authenticator = new HttpBasicAuthenticator("<username>", "<password>");
var request = new RestRequest(Method.PUT);
request.AddHeader("User-Agent", "User-Agent");

request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"merchantReference\": \"new_merchan_order_id_1234\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let credentials = Data("<username>:<password>".utf8).base64EncodedString()

let headers = [
  "User-Agent": "User-Agent",
  "Authorization": "Basic \(credentials)",
  "Content-Type": "application/json"
]
let parameters = ["merchantReference": "new_merchan_order_id_1234"] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://global-api-sandbox.afterpay.com/v1/payments/orderID/environment:environment")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PUT"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```