Update a shared file request

Partial update via JSON Merge Patch (RFC 7396), limited to externalId and metadata. No lifecycle or configuration field is writable here: the upload and verification steps own status / fileId / jobs, and the configuration owns title / instructions / acceptedMimeTypes / contextType.

The calling account must be the request's PAYER — externalId is unique per payer account, so a payee write would reserve a value inside the other party's namespace. A payee receives 404, not 403.

Supplying an externalId already in use for this payer account returns 409 ResourceConflict.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required

Unique identifier of a SharedFileRequest.

Body Params

Patch body for a SharedFileRequest. Only the fields supplied are changed.

These two are the only mutable fields, and both belong to the caller rather than to the upload lifecycle. status, fileId, uploadHistory, jobs and every timestamp are written by the upload and verification steps, and title, instructions, acceptedMimeTypes and contextType belong to the configuration the request was opened against.

The calling account must be the request's PAYER. externalId is unique per payer account, so a payee write would reserve a value inside the other party's namespace; a payee receives 404, not 403.

string

Caller-supplied reconciliation id, unique per payer account. A duplicate returns 409 ResourceConflict.

metadata
object

Keys supplied are set; keys left out are left alone. Sending {} is a no-op rather than a clear — there is no way to remove a key once set. A key containing . or $ is rejected with 422.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json