Version
PATCH

Change an installation's settings

/v1/projects/{project}/connectors/{key}/installation/settings in the Connectors API.

curl -X PATCH https://api.subscriby.net/v1/projects/7f3d1c92-8b45-4e6a-9d21-5c8e0a4b6f13/connectors/example/installation/settings \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN" \  -H "Idempotency-Key: $(uuidgen)" \  -H "Content-Type: application/json" \  -d '{"settings": {"greeting": "Welcome aboard"}, "capabilities": {"broadcasts": false}}'

settings is an object keyed by the field names the connector declares in its settings_fields (read them from the card). Every declared rule runs; a key the connector never declared is 422 VALIDATION_FAILED naming it; fields left out keep their value.

capabilities is an object keyed by capability to true or false: the project's switches for what the connector may do on this installation. A project keeps a connector for access alone by switching off messaging, broadcasts, support_relay, native_payments or any recovery_* facet; every core surface asks the switch before it invokes the connector, so a switched-off broadcast is refused before it is queued and a switched-off health check is skipped. A capability the connector does not declare, or one that cannot be switched off (access_control, early_admission_hold, management_surface, portal_login, creator_registration), is 422 VALIDATION_FAILED naming it; switches left out keep their value. At least one of settings and capabilities is required.

Answers 200 with the installation, which never carries the settings themselves because a settings field may be a secret, but does carry capabilities: every capability the connector declares, each with enabled and toggleable. connector.settings_updated fires naming the fields and the switches (capabilities.<key>) that changed, only when something did.

PATCH
/v1/projects/{project}/connectors/{key}/installation/settings

Requires ability

The token must hold this ability, or the call is refused with 403.

Delivered to every endpoint subscribed to it once the change is made.

Runs the same action from an agent, behind the same ability.

Idempotent

Send the header on every call; the same key replays the original response for 24 hours.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Path Parameters

project*string

The project, resolved by the route binder.

Formatuuid
key*string

The connector key from the route.

Header Parameters

Idempotency-Key*string

A key unique to this operation, such as a fresh UUID. The same key replays the original 2xx response for 24 hours (with Idempotent-Replay: true), so a retry after a timeout never repeats the write; the same key with a different body is refused with 409.

Formatuuid

Request body

JSONWhat the request carries

The settings and capability switches to change on an installation. At least one of the two is required; keys left out keep their value.

Responses

200OK

200 with the installation.

400Bad request

Every write needs an Idempotency-Key header. Send a fresh UUID per distinct operation.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description.

404Not found

An id in the path names nothing the token can see. TENANT_MISMATCH: the project sits outside the token's scope:project: allow-list, or the token carries no team scope. Both answer 404 rather than 403 so that existence outside the token's scope cannot be inferred. On this endpoint: RESOURCE_NOT_FOUND: with reason: unknown_connector, or 404 CONNECTOR_NOT_INSTALLED when the project does not run the connector.

409Conflict

The key was already used in the last 24 hours with a different request body.

422Validation failed

The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields. On this endpoint: VALIDATION_FAILED: when both settings and capabilities are missing, a settings key the connector never declared is sent, a declared rule fails, or a capability is undeclared or cannot be switched off; error.fields names the key.

425Too early

The first request with this key is still running; retry in a few seconds and the original response is replayed.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on