> ## Documentation Index
> Fetch the complete documentation index at: https://api.vitarelay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Post a movement

> Scope `inventory:write` (live keys). `type` is `receive`, `fulfill`, `dispense` or `return`. A `receive` of a new lot
needs `lot_number` and `expiry_date`. A `fulfill` or `dispense` without `lot_number` draws first-expiry-first-out
and may return several transactions. Adjustments, waste, counts and transfers are done in the app by a person.




## OpenAPI

````yaml /pharmacy-api/inventory-openapi.yaml post /inventory/movements
openapi: 3.1.0
info:
  title: Pharmacy Inventory API
  version: 1.0.0
  description: >
    Read stock, scan-resolve barcodes, post movements, reserve stock for orders
    and subscribe to stock events.


    **Authentication.** `Authorization: Bearer vr_live_...`. A key belongs to
    your pharmacy and carries `inventory:read`

    and/or `inventory:write`. Test keys (`vr_test_...`) can read but never
    change stock.


    **Idempotency.** Every write needs an `Idempotency-Key` header (8 to 100
    visible characters). A retry with the same key

    returns the first result (HTTP 200, `idempotent: true`) and posts once.


    **Rules enforced for you.** On-hand never goes negative; orders draw only
    from released, unexpired, unreserved lots,

    first to expire first; every change is one permanent ledger entry. Rule
    failures return a machine-readable `error.code`

    and a plain-English `error.message`: `insufficient_stock` (409);
    `lot_expired`, `lot_not_released`, `lot_expiry_mismatch`,

    `expiry_required` (422); `product_not_found`, `location_not_found`,
    `lot_not_found` (404); `invalid_movement`,

    `lot_required`, `validation_error` (400).


    **Events.** Webhooks are signed: `X-Webhook-Signature: sha256=<hex
    HMAC-SHA256 of the exact request body, keyed with your

    endpoint secret>`. Headers `X-Webhook-Event`, `X-Webhook-Delivery` and
    `X-Webhook-Timestamp` accompany every request.

    Delivery is at least once with exponential backoff for about a day, then
    parked for replay. Deduplicate on

    `X-Webhook-Delivery`. Events: `stock.changed`, `stock.low`,
    `lot.status_changed`, `lot.expiring`, `sku.created`,

    `sku.updated`, `count.approved`, `temperature.excursion`.
servers:
  - url: https://vitarelay.com/api/public/v1
    description: Production
security:
  - bearer: []
paths:
  /inventory/movements:
    post:
      summary: Post a movement
      description: >
        Scope `inventory:write` (live keys). `type` is `receive`, `fulfill`,
        `dispense` or `return`. A `receive` of a new lot

        needs `lot_number` and `expiry_date`. A `fulfill` or `dispense` without
        `lot_number` draws first-expiry-first-out

        and may return several transactions. Adjustments, waste, counts and
        transfers are done in the app by a person.
      parameters:
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 8
            maxLength: 100
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MovementRequest'
      responses:
        '200':
          description: Already posted (same Idempotency-Key)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MovementResult'
        '201':
          description: Posted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MovementResult'
        '409':
          description: insufficient_stock
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: A lot rule failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    MovementRequest:
      type: object
      required:
        - type
        - qty
      properties:
        type:
          type: string
          enum:
            - receive
            - fulfill
            - dispense
            - return
        sku_code:
          type: string
        product_id:
          type: string
          format: uuid
        location:
          type: string
        qty:
          type: integer
          minimum: 1
        lot_number:
          type: string
        expiry_date:
          type: string
          format: date
        status:
          type: string
          enum:
            - released
            - quarantine
        po_number:
          type: string
        reference:
          type: object
          properties:
            type:
              type: string
            id:
              type: string
            rx_number:
              type: string
        scanned_code:
          type: string
        note:
          type: string
      example:
        type: fulfill
        sku_code: SEMA-5MG-2ML
        lot_number: A24117
        location: Main
        qty: 2
        reference:
          type: order
          id: '48213'
          rx_number: RX-901244
    MovementResult:
      type: object
      properties:
        idempotent:
          type: boolean
        transactions:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
              lot_number:
                type: string
              qty:
                type: integer
              balance_after:
                type: integer
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.