Finalize a payroll run

Finalize a payroll run for payment. What happens depends on the run's type.

Employee: moves a PendingApprovals run to Finalized. Approvals close and the amounts lock; no money moves yet, and the run is paid on its schedule. An account can have only one Employee run Finalized or Processing at a time; finalizing another returns 409 until that run is paid.

Contractor: funds the run and starts paying its payables, moving it from Draft to Paid once funding succeeds. The account needs a payroll funding source (payrollSettings.defaultFundingSource, set with PATCH /payments/payer-settings); the account's defaultPaymentMethod does not fund a payroll run, so without a payroll funding source the call returns 422. Payables that are no longer approved, open, or in the run's currency are removed from the run and not paid. Retrying the call is safe; a run that has already moved past Draft returns 409.

Returns 409 when the run is not in a status that can be finalized.

Requires a session with recent MFA step-up for HighRiskWriteAction. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "HighRiskWriteAction", then retry.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json