Let the transaction tell you
Every transaction publishes the operations it accepts right now, so your code reads the answer instead of working it out.
Your answers so far
Choose one
What to build
Read the transaction and keep the entries in its allowedActions list that are Void, Reversal, or Refund. Send the one that's left. That list already accounts for settlement, the processor's capabilities, its reversal window, and the merchant's refund setting, and it's the same evaluation the merchant's own screens use, so the API and the screen agree.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- An empty result is an answer, not a failure: nothing about this transaction can be undone. A decline, an already voided payment, and a zero-dollar verification all land there.
- The create response doesn't carry the list. Read the transaction back when you need to know what a payment you just created accepts.
- A batch can close between your read and your request. The refusal is a 409 with OPERATION_NOT_ALLOWED_IN_STATE, and it carries the current allowed actions, so read them off the error and send one of those.