# contractorOps.taxInfo.update

Add or replace a contractor's tax number (taxNumber: kind sin, bn, itn or foreign, the value, and country for a foreign number) or remove one (removeTaxNumber: the kind), with expectedRevision once that kind was saved before; and/or set the mailing address their slips go to (mailingAddress: line1 street, line2 unit, city, region province or state, postalCode, country) with expectedProfileRevision. A SIN must pass the check-digit test, a business number has 9 digits and an optional program account like RT0001, and a Canadian postal code looks like K1A 0B6. Numbers are stored encrypted and only ever returned masked; the audit log records that one changed, never the value. Finance can change a contractor's tax numbers at most 5 times an hour, and 50 times an hour across the organization (429 with Retry-After); a contractor's own portal saves have a separate budget, so neither can use up the other's. Nothing is returned about other contractors' numbers, except that an administrator in the dashboard saving a SIN or ITN is told who else has the same one (sameNumberAs).

`POST /api/v1/accounting/contractorOps.taxInfo.update`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required · Send `expectedRevision`

Not available over MCP: The warning that another contractor already has the same SIN or ITN would let a client test numbers against everyone else's.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `contractorId` | string (ID) | Yes | The ID of a contractor, from contractors.list. |
| `taxNumber` | object |  | No other fields. |
| `taxNumber.kind` | enum | Yes | Which kind of record or job this is. One of: `sin`, `bn`, `itn`, `foreign`. |
| `taxNumber.value` | string | Yes | 1–40 characters. |
| `taxNumber.country` | string or null |  |  |
| `removeTaxNumber` | enum |  | One of: `sin`, `bn`, `itn`, `foreign`. |
| `expectedRevision` | integer |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `mailingAddress` | object |  | No other fields. |
| `mailingAddress.line1` | string |  | at most 200 characters. |
| `mailingAddress.line2` | string |  | at most 200 characters. |
| `mailingAddress.city` | string |  | at most 120 characters. |
| `mailingAddress.region` | string |  | at most 120 characters. |
| `mailingAddress.postalCode` | string |  | at most 20 characters. |
| `mailingAddress.country` | string |  | Matches ^([A-Za-z]{2})?$. |
| `usTaxForm` | enum or null |  | One of: `w9`, `w8ben`, `w8bene`, `unsure`. |
| `usTaxClassification` | enum or null |  | One of: `individual`, `c_corporation`, `s_corporation`, `partnership`, `trust_estate`, `llc_c`, `llc_s`, `llc_p`, `other`. |
| `expectedProfileRevision` | integer |  | The related record's current revision, from the last time you read it. at most 9007199254740991; greater than 0. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.taxInfo.update \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "contractorId": "4d5e6f7a-8b9c-4d0e-8f1a-2b3c4d5e6f7a",
  "taxNumber": {
    "kind": "sin",
    "value": "example"
  }
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractorOps.taxInfo.update
