Edit an action
https://api.granska.cloud/v1/actions/:idEdits a follow-up action this organisation owns, and publishes or unpublishes it. What the request omits keeps the value it had, status included.
/v1/actions writes actions; POST /v1/action, without the s, runs
one. This endpoint changes an action your organisation owns, and is where a draft is published.
What the request omits keeps its value
Send only what changes. { "name": "…" } renames the action and leaves everything else as it was,
status included: an edit that says nothing about status leaves a published action published.
sections, when sent, replaces the stored list.
Publishing
status takes three values:
PUBLISHEDputs the action in your organisation's menu, where your people can run it from the app andPOST /v1/actioncan run it — nobody has to open the admin panel.DRAFTtakes it back out.UPCOMINGshows it as coming.
Anything else is a 400 naming the three. POST /v1/actions does not
take status: an action is created as a draft and published here.
curl -X PATCH https://api.granska.cloud/v1/actions/action_begaran_om_komplettering_k4m2 \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{ "status": "PUBLISHED" }'{
"success": true,
"actionId": "action_begaran_om_komplettering_k4m2",
"status": "PUBLISHED"
}Only an action you own
The id is the one GET /v1/actions lists and
POST /v1/actions answered. Two refusals are deliberate:
- An action you inherit from the platform is a
403. Editing it would create a private copy that takes the original's place in your menu and stops receiving later improvements to it, so it is refused instead of copied silently. Copy it into your organisation in the admin panel if you want a version of your own. - No such action is a
404, and so is another organisation's: a refusal never confirms that someone else holds an action of that id.
How long the brief may be
instructions may be at most 20,000 characters, counted as Unicode code points, and a longer
one is a 400 with details.refusal "action-instructions-too-long". An action already stored
with a longer brief may be sent back as long as it is, and no longer, so nobody is forced to shorten
an existing action to edit it.
Request
| Parameter | Description |
|---|---|
idstring·path·required | The action to edit, as GET /v1/actions and POST /v1/actions returned it. Must be one this organisation owns. |
namestring·body | The action's name, as your organisation's menu shows it. Omit to keep the stored one. |
instructionsstring·body·maxLength 20000 | The brief for the whole document: what the action is for and how it should read, at most 20000 characters. It goes into the model's prompt on every run. Omit to keep the stored one.Longer than 20000 characters is a 400 with details.refusal "action-instructions-too-long", unless the stored brief is already longer: then it may be sent back as long as it is, and no longer. |
sectionsActionSection[]·body | The sections the document is written in, in order. Each is { key, label, type, instructions, variant? }: key a non-empty string unique to this action, label and instructions strings, type one of TEXT, LIST, FLAW_MAPPED_LIST, and variant, optional, one of STANDARD, QUOTE, SUCCESS_BOX, WARNING_BOX. Sending it replaces the stored list. |
taglinestring·body | One line under the name in the menu. Omit to keep the stored one. |
descriptionstring·body | A short description of what the action produces. Omit to keep the stored one. |
longDescstring·body | A longer description, shown where the action is explained in full. Omit to keep the stored one. |
warningMessagestring·body | A reservation the reader sees before running the action, such as what it does not do. Omit to keep the stored one. |
iconstring·body | The name of the icon the menu draws beside the action. Omit to keep the stored one. |
categorystring·body | The heading the action is filed under in your organisation's menu. Omit to keep the stored one. |
sortOrdernumber·body | Where the action sorts within its category, lowest first. Omit to keep the stored one. |
jurisdictionsstring[]·body | The legal orders the action is written for, as codes such as SE. Each must be open on this platform; when sent, at least one. Omit to keep the stored one. |
practiceAreasstring[]·body | The practice areas the action fits, each one of CHILD_WELFARE, FAMILY_LAW, DISABILITY_SUPPORT, CRIMINAL_LAW, SOCIAL_INSURANCE, HEALTHCARE, EMPLOYMENT, PLANNING_AND_BUILDING, STATE_LIABILITY, ASSOCIATION_LAW, INFORMATION_SECURITY, GENERAL; when sent, at least one. Omit to keep the stored one. |
fitsProfileIdsstring[]·body | The profiles the action is written for, as the ids GET /v1/profiles returns. GET /v1/actions?profileId= lists it under each of them; left out, nobody has decided and it is listed for every profile. Omit to keep the stored one. |
outputLanguagestring·body | The language the document is written in — one of Swedish, Norwegian (Bokmål), Danish and English. Left out, the document follows the language of the profile the analysis ran with, then your organisation's. Omit to keep the stored one. |
statusstring·body | Send "PUBLISHED" to put the action in your organisation's menu, "DRAFT" to take it back to a draft, or "UPCOMING" to show it as coming. Omit it and the stored status stands.Anything but those three is a 400 naming them. POST /v1/actions does not take this field — an action is created as a draft and published here. |
What will be refused
- A field the server owns.
idin the body (the action is the one in the path),tenantId,publishedAt,offerable,instructionsUpdatedAtand the authorship fields are each a400naming the field. - A field this endpoint does not have. Sent at all, it is a
400listing what is accepted. - A field or section of the wrong shape, a jurisdiction that is malformed or not open on this
platform, or a practice area or
outputLanguagethis API does not carry.
Errors
| Error | When |
|---|---|
400BAD_REQUEST | A field the server owns was sent (id in the body, tenantId, authorship, publishedAt, offerable, instructionsUpdatedAt), a field this route does not accept was sent at all, status is not DRAFT, PUBLISHED or UPCOMING, a field or section is malformed, a jurisdiction is malformed or not open on this platform, a practice area or outputLanguage is not one this API carries, or instructions is changed to something longer than 20000 characters — that one carries details { refusal: "action-instructions-too-long", field: "instructions", length, limit }. Not probed: every spelling of it needs a body, and NOT_FOUND below proves the same route with none. |
401UNAUTHORIZED | The Authorization header is missing, is not a readable bearer token, or names no tenant. |
401TOKEN_EXPIRED | The access token was issued by this gateway and has since expired. Not probed: it needs a token older than its own lifetime. |
403FORBIDDEN | The action is one this organisation only inherits from the platform. Editing it here would create a private copy that takes the original's place and stops receiving later changes, so it is refused instead. The platform credential is refused here too. Not probed: it needs an inherited action id. |
404NOT_FOUND | No action with that id that this organisation owns or inherits. Another organisation's action is answered the same way, so a refusal never confirms it exists. |
429TOO_MANY_REQUESTS | The organisation has spent its hourly configuration-write floor. Not probed: reaching it would mean sending sixty writes. |
500INTERNAL_ERROR | An unexpected server-side failure. Not probable from outside — reaching it means something is wrong. |
This costs no runs, but it is metered
Writing configuration never spends an analysis from your quota. It ticks the same hourly floor the
other configuration writes tick, reported by the X-RateLimit-* headers on this route and by
GET /v1/quotas.