# history.rollback.apply

Roll back one change from History using the previewFingerprint from history.rollback.preview, a reason and an idempotencyKey. Every step runs as the person through the same checks as doing it by hand (role, revision, closed periods), and is itself recorded in History, so a rollback can be rolled back too. A change made since the preview stops it with a conflict; preview again.

`POST /api/v1/accounting/history.rollback.apply`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required · Destructive: confirm with a person first

MCP tool: `accounting_history_rollback_apply`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | string | Yes | The record's ID. Matches ^([0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}\|sig-[0-9]{1,19})$. |
| `previewFingerprint` | string | Yes | SHA-256 hash as 64 lowercase hex characters. |
| `reason` | string | Yes | A short note saying why, kept in the record's history. 3–1000 characters. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/history.rollback.apply \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "11111111-1111-1111-1111-111111111111",
  "previewFingerprint": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c",
  "reason": "Synthetic example from the docs"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/history.rollback.apply
