# Cancel order

`DELETE /orders/{orderId}`

Cancels a pending order and releases whatever it had reserved.

- The order must still be `active`; one that has already executed or been cancelled answers `403`.
- Allowed while the account is locked by the managed capital limit — that lock only stops orders that would grow a position.
- The market must not be paused.

## Authorization

bearer: http · bearer (required). Personal API key, prefixed with `usk_`.

## Parameters

- path: orderId (string · uuid; required). Identifier of the order to cancel.

Type: string · uuid

format: uuid

## Example · cURL

```bash
curl --request DELETE 'https://api.upscale.trade/orders/{orderId}' \
  --header 'Accept: application/json' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

## Example · JavaScript

```javascript
const response = await fetch("https://api.upscale.trade/orders/{orderId}", {
  method: "DELETE",
  headers: {
    "Accept": "application/json",
    "Authorization": "Bearer YOUR_API_KEY"
  },
});
console.log(response.status, await response.text());
```

## Example · Python

```python
import requests

response = requests.request(
    "DELETE",
    "https://api.upscale.trade/orders/{orderId}",
    headers={"Accept":"application/json","Authorization":"Bearer YOUR_API_KEY"},
    timeout=30,
)
print(response.status_code, response.text)
```

## Response 204

**204**  — Order cancelled

## Response 401

**401**  — Unauthorized

## Response 403

**403**  — The order is no longer active. The account belongs to another user (`account_access_denied`), or the request is authenticated with an API key while `api_trading` is disabled on the account (`api_trading_not_enabled`). Trading on the account is over in its current status (`challenge_closed`), or the account is locked by the managed capital limit (`funded_limit_trading_locked`). The market is paused (`market_paused`) or accepts closing orders only (`market_close_only`).

## Response 404

**404**  — No order with this identifier.

## Response 429

**429**  — Rate limit of the API key exceeded (`api_key_rate_limit_exceeded`). `Retry-After` says when to come back; the body carries the bucket (`read` / `write`), the window that tripped, its limit and `retryAt`.