> This page is for version v2026-01-15.
> For other versions, use one of these documentation indexes:
> - v2026-04-01 (default): https://docs.givechariot.com/v2026-04-01/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.givechariot.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.givechariot.com/_mcp/server.

# Fulfill a Lockbox Request

POST https://api.givechariot.com/v1/lockboxes/fulfill_request
Content-Type: application/json

Notifies Chariot that a new PO box has been provisioned by the lockbox provider.

The `request_id` is a one-time unique value generated by Chariot for each PO box request.

See the [Provisioning guide](/v2026-01-15/guides/lockbox-providers/provisioning) for the full provisioning flow.

Reference: https://docs.givechariot.com/api/mailbox/fulfill-request

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.givechariot.com` (Production, default)
- `https://sandboxapi.givechariot.com` (Sandbox)

## Request

### Body (application/json)

This endpoint expects an object.

- `request_id` (string, required) — The unique request identifier originally provided by Chariot when the PO box was requested.
- `location_id` (string, required) — The identifier of the newly provisioned PO box.
- `address` (Address, required)

## Response

### 200

Indicates the PO box has been successfully provisioned.

## Errors

### 400 Bad Request Error

The request is invalid or contains invalid parameters

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 401 Unauthorized Error

Unauthorized. The request is missing the security (OAuth2 Bearer token) requirements and the server is unable to verify the identify of the caller.

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 403 Forbidden Error

Access denied

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 500 Internal Server Error

Internal Server Error

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

## Types

### Address

- `city` (string, required) — City, district, suburb, town, or village. Maximum length: 255 characters.
- `country` (string, required) — Two-letter country code (https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2)
- `line1` (string, required) — Address line 1 (e.g. street, PO Box, or company name). Maximum length: 255 characters.
- `postal_code` (string, required) — ZIP or postal code. Maximum length: 40 characters.
- `state` (string, required) — State, county, province, or region
- `line2` (string, optional) — Address line 2 (e.g. apartment, suite, unit, or building). Maximum length: 255 characters.

## Examples

**Request**

```json
{
  "request_id": "123456789",
  "location_id": "po_9876",
  "address": {
    "city": "New York",
    "country": "US",
    "line1": "123 Main St.",
    "postal_code": "12345",
    "state": "NY"
  }
}
```

**Response**

```json
{}
```