> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.givechariot.com/v2026-01-15/api/mailbox/fulfill-request/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.givechariot.com/_mcp/server. # Fulfill a Lockbox Request POST https://api.givechariot.com/v1/lockboxes/fulfill_request Content-Type: application/json Notifies Chariot that a new PO box has been provisioned by the lockbox provider. The `request_id` is a one-time unique value generated by Chariot for each PO box request. See the [Provisioning guide](/v2026-01-15/guides/lockbox-providers/provisioning) for the full provisioning flow. Reference: https://docs.givechariot.com/api/mailbox/fulfill-request ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Servers - `https://api.givechariot.com` (Production, default) - `https://sandboxapi.givechariot.com` (Sandbox) ## Request ### Body (application/json) This endpoint expects an object. - `request_id` (string, required) — The unique request identifier originally provided by Chariot when the PO box was requested. - `location_id` (string, required) — The identifier of the newly provisioned PO box. - `address` (Address, required) ## Response ### 200 Indicates the PO box has been successfully provisioned. ## Errors ### 400 Bad Request Error The request is invalid or contains invalid parameters - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 401 Unauthorized Error Unauthorized. The request is missing the security (OAuth2 Bearer token) requirements and the server is unable to verify the identify of the caller. - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 403 Forbidden Error Access denied - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 500 Internal Server Error Internal Server Error - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ## Types ### Address - `city` (string, required) — City, district, suburb, town, or village. Maximum length: 255 characters. - `country` (string, required) — Two-letter country code (https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2) - `line1` (string, required) — Address line 1 (e.g. street, PO Box, or company name). Maximum length: 255 characters. - `postal_code` (string, required) — ZIP or postal code. Maximum length: 40 characters. - `state` (string, required) — State, county, province, or region - `line2` (string, optional) — Address line 2 (e.g. apartment, suite, unit, or building). Maximum length: 255 characters. ## Examples **Request** ```json { "request_id": "123456789", "location_id": "po_9876", "address": { "city": "New York", "country": "US", "line1": "123 Main St.", "postal_code": "12345", "state": "NY" } } ``` **Response** ```json {} ```