Create or update one item
Upserts one item of a snapshot and busts the flow's config cache. Admin only: the handler calls requireKYBConfigAdmin, which resolves the caller and then checks Storage.IsAdminAccount. A non-admin gets 403 common.forbidden. Both path segments are validated before the admin check. The server OVERWRITES five fields of the body: flow_id and name from the path, active to TRUE, and created_by / modified_by from the caller. An item therefore cannot be deactivated through this route. The response echoes the amended input struct rather than re-reading the stored row. The cache is ALWAYS invalidated on success, whatever the body carried. The handler hands the item to the repository by pointer and only reads FlowName back afterwards; because it always sets FlowID from the {flow_id} path segment, resolveItemFlowIdentity takes the by-id branch and fillFlowNameFromFlowID writes the name into that same struct before the row is written. The one real caveat is ordering: the invalidation happens AFTER the write and is not rolled back if it fails, so a cache that cannot be reached leaves the write committed and the config stale.
Authorization
bearerAuth In: header
Path Parameters
A flows_config snapshot id. Must parse as a non-nil UUID; the nil UUID is rejected 400.
Step name within the snapshot. Must be non-empty.
Request Body
application/json
Item fields.
TypeScript Definitions
Use the request body type in TypeScript.
REQUEST shape of PUT /v1/kyb/config/flows/{flow_id}/items/{item_name} only. Same properties as KYBItemInput, but name is NOT required: the handler overwrites whatever the body carries with the {item_name} path segment. Use KYBItemInput for the import array, where nothing supplies a name and it therefore is required.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PUT "https://example.com/v1/kyb/config/flows/497f6eca-6276-4993-bfeb-53cbbbba6f08/items/string" \ -H "Content-Type: application/json" \ -d '{ "type": "string", "sort_order": 0 }'{
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"flow_name": "string",
"flow_id": "0746f03b-16cc-49fb-9833-df3713d407d2",
"name": "string",
"type": "string",
"q": {},
"description": {},
"schema": {},
"ui_schema": {},
"form_data": {},
"section": {},
"next": null,
"update_config": {},
"before_submit": {},
"after_submit": {},
"custom_function": {},
"custom_api": {},
"options": {},
"message": {},
"buttons": [
{}
],
"position": {
"x": 0.1,
"y": 0.1
},
"sort_order": 0,
"active": true,
"system": true,
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f"
}{
"status": 400,
"message": "Invalid input",
"code": "common.invalid_input",
"class": "validation"
}{
"status": 401,
"message": "Unauthorized",
"code": "common.unauthorized",
"class": "business"
}{
"status": 403,
"message": "Access denied",
"code": "common.forbidden",
"class": "business"
}{
"status": 404,
"message": "Record not found",
"code": "common.record_not_found",
"class": "business"
}{
"status": 429,
"message": "Rate limit for 203.0.113.7 to POST:/v1/kyb/navigate exceeded.",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Internal server error",
"code": "common.server_error",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Upserts the flows_config row for this flow_name and busts its config cache. Admin only: the handler calls requireKYBConfigAdmin, which resolves the caller and then checks Storage.IsAdminAccount. A non-admin gets 403 common.forbidden. Note the ordering: the path segment is validated BEFORE the admin check, so a non-admin who sends a malformed segment receives 400, not 403. The server OVERWRITES four fields of the body regardless of what was sent: flow_name from the path, active to TRUE, and created_by / modified_by from the caller. A flow therefore cannot be deactivated through this route. The response echoes the input struct as the server amended it — it is not re-read from the database, so any column the repository defaulted is not reflected.
Fetches one stored answer. Requires the record-level read permission for this answer id. A permission refusal is reported as 401 with code common.invalid_input — see the 401 below.