# Edit a drip workflow

`PUT /v1/workflows/{id}`

- Authentication: required (Bearer token)
- Required scope: `api.workflows.manage`

Edits a workflow's name, description or `.flow` source. A **partial**
write: an omitted field keeps its current value, so a rename need not
re-send the whole definition. `key` is immutable. On writes `{id}`
resolves as a UUID or, failing that, as the workflow's org-unique key.

Pass `expected_content_hash` — the `content_hash` a previous read
returned — and a concurrent edit is refused with `409 conflict` rather
than overwritten; the conflict body carries the CURRENT `content_hash`,
so the retry is one call rather than two. Omit it and the last writer
wins.

Every update snapshots the previous version first, so a bad edit is
recoverable. In-flight runs are unaffected: each stays pinned to the
version it enrolled under. A source that stops validating parks the row
as `invalid` with its diagnostics, exactly as on create.

Editing an ACTIVE workflow to add its first `send` step does NOT turn
the send-approval gate on by itself over this API. Use
`PUT /v1/workflows/{id}/send-approval` if you want it, or re-activate.

## Path parameters

- `id` (string, required) — The workflow's UUID or, when the value does not parse as a UUID, its org-unique key. Unknown handles read as `404 not_found`. Accepted on every workflow route, read and write alike.

## Request body

Content type: `application/json`

```json
{
  "name": "string",
  "description": "string",
  "source": "string",
  "expected_content_hash": "string"
}
```

## Example request

```bash
curl -X PUT 'https://api.sendops.dev/v1/workflows/string' \
  -H "Authorization: Bearer $SENDOPS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"string","description":"string","source":"string","expected_content_hash":"string"}'
```

## Responses

### 200 — The updated workflow

Content type: `application/json`

```json
{
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "key": "string",
  "description": "string",
  "status": "string",
  "invalid_reason": "string",
  "require_send_approval": true,
  "send_mode": "live",
  "shadow_started_at": "2026-05-17T20:00:00Z",
  "shadow_cohort_list_id": "00000000-0000-0000-0000-000000000000",
  "shadow_cohort": {
    "id": "00000000-0000-0000-0000-000000000000",
    "key": "string",
    "name": "string",
    "member_count": 0
  },
  "current_version": 0,
  "run_counts": {},
  "created_at": "2026-05-17T20:00:00Z",
  "updated_at": "2026-05-17T20:00:00Z",
  "source": "string",
  "content_hash": "string",
  "warnings": [
    "string"
  ],
  "diagnostics": [
    {
      "line": 0,
      "column": 0,
      "severity": "string",
      "message": "string"
    }
  ],
  "requires": [
    {
      "kind": "template",
      "key": "string",
      "status": "ok",
      "detail": "string",
      "fix": "string"
    }
  ]
}
```

### 401 — Missing, malformed, or unknown API key

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 403 — Key lacks the required scope or plan limit violated

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 404 — Resource not found

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 409 — The mutation is rejected by a state rule rather than a bad request. The
`code` is `conflict`.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 422 — A query parameter, path value or body field failed validation.

The body is a `validation_failed` Problem. When the refusal is about a
reference — a segment key, template slug, topic or attribute name the
organization does not have — it additionally carries `validation_code`,
`field`, `line`/`column`, `missing`, `candidates` and `next_step`, so a
client can correct the call without a second round of guessing. See
`ValidationProblem`.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ],
  "validation_code": "invalid_syntax",
  "field": "string",
  "line": 0,
  "column": 0,
  "missing": [
    {
      "kind": "segment",
      "key": "string"
    }
  ],
  "candidates": {},
  "next_step": "string"
}
```

### 429 — Per-org rate limit exceeded

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 500 — Unexpected server-side failure. The `code` is `internal_error`. The
`request_id` field can be quoted to SendOps support to investigate.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```
