void blocks the customer: the transaction engine rejects them with invalid_customer until the block is lifted. activate lifts the block. Both are idempotent — calling them on a customer already in the target state changes nothing and returns the current record.
Auth:Authorization: Bearer <accessToken>— an organization-scoped token from Authentication. Missing or invalid token returns 401; an organization without an active subscription returnsinvalid_subscription(403).
Path parameters
No request body.
Example
Response
Returns 200 with the customer record;isVoided reflects the new state.
- Voiding does not delete anything: the customer stays visible in list and find, keeps their cards and balances, and can be activated again at any time.
- A voided customer is rejected on POST /v1/transactions/process and validate with
invalid_customer(400). - After
activate,isVoidedisfalsein the response.

