> ## Documentation Index
> Fetch the complete documentation index at: https://docs-pos.solya.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Deactivate (close) a store

> Soft-closes a store by flipping its `active` flag to `false` — never a physical delete (historic sales, transfers and fiscal reports still reference it), so the store still reads back as inactive and can be reopened with an update. This is the safe way to take a location out of the trading network: a closed store must not be routed sales or transfers, and tills, transfers and reporting all read the flag. Idempotent: deactivating an already-closed store is a no-op that returns it unchanged. 404s for an unknown store. PERMISSION TRAP (see solya-pos#950): the route guard accepts `pos.settings.manage`, but the use-case additionally asserts the kernel `config:manage` permission and NO `pos.settings.*` scope maps to it, so a principal authenticated by scopes alone clears the guard and then 403s inside the use-case.



## OpenAPI

````yaml /openapi.json post /v1/stores/{storeId}/deactivate
openapi: 3.0.3
info:
  title: Solya POS API
  version: 1.0.0
  description: >-
    The Solya POS backend HTTP surface. Every documented operation is
    agent-ready: it carries an `operationId`, an agent-facing `description`, the
    `pos.*` scopes it enforces (`x-required-permissions`) and an `x-agent-tier`.
    Success responses return the payload as raw JSON; failures return the
    `ErrorResponse` envelope (`{ error: { code, message, statusCode } }`).
servers:
  - url: /
    description: The backend, relative to its deployed origin.
security: []
paths:
  /v1/stores/{storeId}/deactivate:
    post:
      tags:
        - Network
      summary: Deactivate (close) a store
      description: >-
        Soft-closes a store by flipping its `active` flag to `false` — never a
        physical delete (historic sales, transfers and fiscal reports still
        reference it), so the store still reads back as inactive and can be
        reopened with an update. This is the safe way to take a location out of
        the trading network: a closed store must not be routed sales or
        transfers, and tills, transfers and reporting all read the flag.
        Idempotent: deactivating an already-closed store is a no-op that returns
        it unchanged. 404s for an unknown store. PERMISSION TRAP (see
        solya-pos#950): the route guard accepts `pos.settings.manage`, but the
        use-case additionally asserts the kernel `config:manage` permission and
        NO `pos.settings.*` scope maps to it, so a principal authenticated by
        scopes alone clears the guard and then 403s inside the use-case.
      operationId: deactivateStore
      parameters:
        - schema:
            type: string
            minLength: 1
          in: path
          name: storeId
          required: true
      responses:
        '200':
          description: 'The closed store directory record (`active: false`).'
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    minLength: 1
                  name:
                    type: string
                    minLength: 1
                  city:
                    type: string
                    minLength: 1
                  region:
                    type: string
                    minLength: 1
                  active:
                    type: boolean
                required:
                  - id
                  - name
                  - city
                  - region
                  - active
                additionalProperties: false
                description: 'The closed store directory record (`active: false`).'
                example:
                  id: store-rivoli
                  name: Boutique Rivoli
                  city: Paris 1er
                  region: Île-de-France
                  active: false
        '400':
          description: >-
            The request failed schema validation; `error.fieldErrors` lists the
            fields.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
        '401':
          description: No valid credential was presented — send a bearer token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: The actor is authenticated but lacks the required `pos.*` scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: No resource matches the addressed identifier.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: The request is well-formed but violates a domain rule.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: An unexpected server error — safe to retry idempotent requests.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ValidationErrorResponse:
      type: object
      required:
        - error
      additionalProperties: false
      description: >-
        A `VALIDATION_FAILED` envelope carrying the offending fields in
        `fieldErrors`.
      properties:
        error:
          type: object
          required:
            - code
            - message
            - statusCode
          additionalProperties: false
          properties:
            code:
              type: string
              enum:
                - VALIDATION_FAILED
            message:
              type: string
            statusCode:
              type: integer
            fieldErrors:
              type: array
              description: >-
                One entry per rejected field: the field path and why it was
                rejected.
              items:
                type: object
                required:
                  - field
                  - message
                additionalProperties: false
                properties:
                  field:
                    type: string
                    description: Dot-path of the offending field.
                  message:
                    type: string
                    description: Why the field was rejected.
    ErrorResponse:
      type: object
      required:
        - error
      additionalProperties: false
      description: The uniform failure envelope every non-2xx response returns.
      properties:
        error:
          type: object
          required:
            - code
            - message
            - statusCode
          additionalProperties: false
          properties:
            code:
              type: string
              enum:
                - VALIDATION_FAILED
                - UNAUTHORIZED
                - FORBIDDEN
                - NOT_FOUND
                - CONFLICT
                - BUSINESS_RULE_VIOLATION
                - INTERNAL_ERROR
              description: >-
                Machine-readable kernel `ResultCode` — branch on this, not on
                `message`.
            message:
              type: string
              description: >-
                Human-readable explanation. Safe to surface; never leaks server
                internals.
            statusCode:
              type: integer
              description: >-
                The HTTP status, mirrored into the body so a client need not
                read headers.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        `Authorization: Bearer <token>`. Accepts EITHER a Keycloak access token
        (scopes-in-token) OR an opaque POS session token; both resolve to the
        same `pos.*` scope vocabulary the route guards enforce.

````