> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a Provider Configuration

> Use this endpoint to update an existing provider configuration. If the configuration payload changes, it is re-validated against the provider's JSON Schema.



## OpenAPI

````yaml en/openapi/v3-current/flowker.yaml patch /v1/provider-configurations/{id}
openapi: 3.1.0
info:
  description: >-
    Complete API reference for Flowker workflow orchestration services including
    catalog management, workflow definitions, executor configurations, provider
    configurations, and workflow executions.
  title: Flowker API
  version: 1.2.0
servers:
  - url: https://flowker.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - name: Catalog API
    description: >-
      Browse built-in providers, executors, and triggers available in the
      Flowker catalog.
  - name: Workflows API
    description: >-
      Create, update, activate, deactivate, clone, and delete workflow
      definitions.
  - name: Executions API
    description: Start workflow executions and track their status and results.
  - name: Executor Configurations API
    description: >-
      List, inspect, update, and delete the executor configuration records a
      deployment holds.
  - name: Provider Configurations API
    description: >-
      Create, update, enable, and disable the provider configurations that
      workflow nodes call through.
  - name: Dashboard API
    description: >-
      Retrieve aggregated summaries of workflows and executions for operational
      dashboards.
  - name: Webhooks API
    description: >-
      Receive webhook callbacks from external systems to trigger workflow
      executions.
  - name: Schedule API
    description: >-
      Inspect a workflow's upcoming, skipped, and parked scheduled occurrences,
      and run or discard the parked ones.
  - name: Schema Registry API
    description: >-
      Publish global OpenAPI specification versions for native services and pin
      the version each tenant resolves against.
  - name: OpenAPI Schemas API
    description: >-
      Upload, inspect, and delete the tenant's external OpenAPI schemas, and
      derive the contract of a single operation.
  - name: XSD Schemas API
    description: >-
      Upload, inspect, and delete the tenant's XSD schemas used to validate XML
      webhook payloads.
paths:
  /v1/provider-configurations/{id}:
    patch:
      tags:
        - Provider Configurations API
      summary: Update a Provider Configuration
      description: >-
        Use this endpoint to update an existing provider configuration. If the
        configuration payload changes, it is re-validated against the provider's
        JSON Schema.
      operationId: updateProviderConfiguration
      parameters:
        - description: Unique identifier of the provider configuration.
          in: path
          name: id
          required: true
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateProviderConfigurationInput'
        description: Request body containing the updated provider configuration details.
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProviderConfigurationOutput'
          description: >-
            Indicates that the request was successful and the response contains
            the requested data.
        '400':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Indicates that the request was malformed or contained invalid
            parameters.
        '404':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Indicates that the requested resource could not be found.
        '409':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Indicates that the request could not be completed due to a conflict
            with the current state of the resource.
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Indicates that the request was well-formed but contains semantic
            errors that prevent processing.
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: >-
            Indicates an unexpected internal error. If this persists, please
            contact support.
components:
  schemas:
    UpdateProviderConfigurationInput:
      properties:
        allowedHosts:
          description: >-
            Replaces the outbound allow-list. Omit the field to leave the stored
            list unchanged. Send an empty list to clear it, and a non-empty list
            to replace it. The new list must satisfy the same rules as on
            create, including the base-URL coverage check and the generic HTTP
            provider rule.
          items:
            maxLength: 253
            type: string
          maxItems: 100
          type: array
          example:
            - api.acme.com
            - .kyc-provider.io
        allowedPrivateHosts:
          description: >-
            Replaces the named private-host allowance. Omit the field to leave
            the stored set unchanged. Send an empty list to clear it, and a
            non-empty list to replace it. Entries follow the same format as on
            create.
          items:
            maxLength: 253
            type: string
          maxItems: 100
          type: array
          example:
            - nginx.pix-inline.internal
        config:
          additionalProperties:
            type: object
          description: Updated provider-specific configuration.
          type: object
        description:
          description: Updated description.
          example: ClearSale anti-fraud — updated with new API version
          maxLength: 500
          type: string
        metadata:
          additionalProperties:
            type: object
          description: Updated metadata.
          type: object
        name:
          description: Updated name.
          example: ClearSale Production v2
          maxLength: 100
          minLength: 1
          type: string
        schemaBindings:
          description: >-
            Replaces the schema bindings. Omit the field to leave the stored
            bindings unchanged. Send an empty list to remove them all, and a
            non-empty list to replace the set. Flowker checks every entry
            against the stored schemas before it saves anything.
          items:
            $ref: '#/components/schemas/SchemaBindingInput'
          maxItems: 100
          type: array
      type: object
    ProviderConfigurationOutput:
      example:
        id: c3d4e5f6-a7b8-9012-cdef-345678901234
        name: ClearSale Production
        description: ClearSale anti-fraud for Pix transactions
        providerId: clearsale
        kind: catalog
        config:
          baseUrl: https://api.clearsale.com.br
          environment: production
        allowedHosts:
          - api.clearsale.com.br
        schemaBindings: []
        status: active
        metadata:
          team: risk
        createdAt: '2026-03-17T14:00:00Z'
        updatedAt: '2026-03-17T14:00:00Z'
      properties:
        allowedHosts:
          description: >-
            Outbound allow-list of destination hostnames. The field is absent
            when the configuration declares no allow-list.
          items:
            maxLength: 253
            type: string
          maxItems: 100
          type: array
          example:
            - api.clearsale.com.br
        allowedPrivateHosts:
          description: >-
            Named private hosts this configuration may reach, managed by your
            operations team. The field is absent when the set is empty.
          items:
            maxLength: 253
            type: string
          maxItems: 100
          type: array
          example:
            - nginx.pix-inline.internal
        config:
          additionalProperties:
            type: object
          description: Provider-specific configuration.
          example:
            baseUrl: https://api.clearsale.com.br
            environment: production
          type: object
        createdAt:
          description: Timestamp when the configuration was created.
          example: '2026-03-17T14:00:00Z'
          format: date-time
          type: string
        description:
          description: Human-readable description.
          example: ClearSale anti-fraud for Pix transactions
          type: string
        id:
          description: Unique identifier of the configuration.
          example: c3d4e5f6-a7b8-9012-cdef-345678901234
          format: uuid
          type: string
        kind:
          description: >-
            Connection kind of this configuration: `catalog` targets a provider
            published in the catalog, and `external_openapi` targets an OpenAPI
            document registered for your tenant.
          enum:
            - catalog
            - external_openapi
          example: catalog
          type: string
        metadata:
          additionalProperties:
            type: object
          description: Custom metadata.
          example:
            environment: production
            team: risk
          type: object
        name:
          description: Name of the configuration.
          example: ClearSale Production
          type: string
        providerId:
          description: >-
            ID of the catalog provider this configuration targets. A
            configuration of kind `external_openapi` created without one carries
            the reserved id `external.openapi` instead.
          example: clearsale
          type: string
        schemaBindings:
          description: >-
            Stored schemas this configuration binds to. The field is always
            present, and it is an empty list when the configuration binds no
            schema.
          items:
            $ref: '#/components/schemas/SchemaBindingOutput'
          type: array
        status:
          description: 'Current status: `active` or `disabled`.'
          enum:
            - active
            - disabled
          example: active
          type: string
        updatedAt:
          description: Timestamp of the last update.
          example: '2026-03-17T14:00:00Z'
          format: date-time
          type: string
      required:
        - config
        - createdAt
        - id
        - kind
        - name
        - providerId
        - schemaBindings
        - status
        - updatedAt
      type: object
    ErrorResponse:
      properties:
        code:
          description: Stable, machine-readable Flowker error code.
          example: FLK-0001
          type: string
        detail:
          description: >-
            Human-readable explanation of this occurrence. Responses with a
            status of 500 or above carry a fixed generic message.
          example: name is a required field
          type: string
        errors:
          description: Per-field entries for a request that failed validation.
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type: array
        instance:
          description: URI reference identifying this specific occurrence.
          example: /v1/workflows
          format: uri
          type: string
        status:
          description: HTTP status code.
          example: 400
          type: integer
        title:
          description: >-
            Standard HTTP reason phrase for the status. It does not change per
            error code.
          example: Bad Request
          type: string
        type:
          description: >-
            URI reference identifying the error. Always the error catalog base
            followed by the code.
          example: https://errors.lerian.studio/v1/FLK-0001
          format: uri
          type: string
      type: object
    SchemaBindingInput:
      description: One binding between a provider configuration and a stored schema.
      properties:
        operations:
          description: >-
            Restricts an OpenAPI binding to the listed operations. Omit it, or
            send null, to bind the whole document. Only a binding of type
            "openapi" accepts operations.
          items:
            $ref: '#/components/schemas/SchemaBindingOperationInput'
          maxItems: 100
          type:
            - array
            - 'null'
        schemaId:
          description: Identifier of the stored schema, as a UUID.
          example: 018f3e2a-1c4d-7b9e-a1b2-c3d4e5f6a7b8
          type: string
        type:
          description: Which schema registry the binding points at.
          enum:
            - xsd
            - openapi
          example: openapi
          type: string
      required:
        - schemaId
        - type
      type: object
    SchemaBindingOutput:
      description: One binding between a provider configuration and a stored schema.
      properties:
        operations:
          description: >-
            The operations an OpenAPI binding is restricted to. The field is
            absent when the binding covers the whole document.
          items:
            $ref: '#/components/schemas/SchemaBindingOperationOutput'
          type: array
        schemaId:
          description: Identifier of the stored schema, as a UUID.
          example: 018f3e2a-1c4d-7b9e-a1b2-c3d4e5f6a7b8
          type: string
        type:
          description: Which schema registry the binding points at.
          enum:
            - xsd
            - openapi
          example: openapi
          type: string
      required:
        - schemaId
        - type
      type: object
    ErrorDetail:
      properties:
        location:
          description: Where the problem is, such as body.nodes or path.id.
          example: body.nodes
          type: string
        message:
          description: Description of the field-level problem.
          example: expected array length >= 1
          type: string
        value:
          description: The value that caused the error, when it is safe to echo.
      type: object
    SchemaBindingOperationInput:
      description: One operation of a bound OpenAPI document.
      properties:
        method:
          description: >-
            HTTP method of the operation. One of GET, PUT, POST, DELETE,
            OPTIONS, HEAD, PATCH or TRACE. Flowker uppercases the value.
          example: POST
          maxLength: 10
          type: string
        path:
          description: Path of the operation. It must start with a slash.
          example: /payments
          maxLength: 2048
          type: string
      required:
        - method
        - path
      type: object
    SchemaBindingOperationOutput:
      description: One operation of a bound OpenAPI document.
      properties:
        method:
          description: HTTP method of the operation, in upper case.
          example: POST
          type: string
        path:
          description: Path of the operation.
          example: /payments
          type: string
      required:
        - method
        - path
      type: object
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT bearer token issued by the identity provider. Send it in the
        Authorization header as `Bearer <token>`.

````