# Undo and dry run

> Preview a change before making it, and revert it after.

## Dry run

Operations that support it take `?dryRun=true` (over MCP: `dryRun: true`). The change is planned and its effect returned — what would be added, moved, changed or deleted — and nothing is written. The [reference](https://api.bymundi.com/docs/reference.md) marks which operations support it.

## Undo

Most writes are recorded as a **change** and answer with a header:

```http
Bymundi-Change-Id: 5b1e…
```

Revert it with:

```bash
curl -X POST https://api.bymundi.com/v1/changes/$CHANGE_ID/revert \
  -H "Authorization: Bearer $BYMUNDI_KEY"
```

A revert is **conditional**: if anything it touched was edited since, it is refused with a `409` rather than overwrite that edit. An already reverted change answers [`change_not_applied`](https://api.bymundi.com/problems/change_not_applied.md). Passenger changes can be reverted for 30 days ([`undo_expired`](https://api.bymundi.com/problems/undo_expired.md)).

List your changes with `GET /v1/changes`. Staff see the same list, with a Undo button, under Integrations → API & MCP → Activity.

Some operations are undone by a matching operation instead: archive a trip → restore it; publish → unpublish; delete a catalog entry → restore it. Each reference page says which.

## Confirmation

Large or permanent changes need a confirmation: deleting more than 5 blocks or 30% of an itinerary, or deleting a quote, a document, a contact or a catalog entry. The first call answers [`422 confirmation_required`](https://api.bymundi.com/problems/confirmation_required.md) with `requiresConfirmation: true`; repeat it with `confirm` set to the exact name the detail asks for.
