Refund it
The money already moved, so the undo is a credit: a new transaction that sends the amount back.
Your answers so far
Choose one
What to build
Send a Refund on the operations endpoint, for the full amount or for part of it. The response carries a second transaction id, for the Return transaction the refund creates. Read that transaction to learn whether the credit was approved, and watch its settlement to learn when the money left.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- A refund isn't instant and can be declined. Treating the operation response as proof the customer has their money back is the most common reconciliation bug on this path.
- Send an explicit amount on every refund after the first. An omitted amount asks for the original total, not what's left of it, and is refused.
- An empty allowed-actions list on a settled payment usually means the merchant has refunds turned off, not that the payment is in the wrong state.
- Send an idempotency key, so a refund retried after a timeout returns the first refund rather than issuing a second.