Update a flow
curl --request PUT \
--url https://app.sahlfinancial.com/api/v1/flows/{flow_id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Salaried borrower v2"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: 'Salaried borrower v2'})
};
fetch('https://app.sahlfinancial.com/api/v1/flows/{flow_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/flows/{flow_id}"
payload = { "name": "Salaried borrower v2" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"id": "d6a3f9b8-2c5e-4170-b8d1-4e0a7c3f5b29",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"name": "Salaried borrower v2",
"description": null,
"use_case": "lending",
"kind": "kyc",
"country": "MA",
"nodes": [
{
"id": "start",
"type": "start",
"position": {
"x": 0,
"y": 0
},
"data": {
"label": "Start"
}
},
{
"id": "end",
"type": "end",
"position": {
"x": 240,
"y": 0
},
"data": {
"label": "End"
}
}
],
"edges": [
{
"id": "e1",
"source": "start",
"target": "end"
}
],
"version": 2,
"is_published": false,
"status": "draft",
"environment": "sandbox",
"created_at": "2026-10-07T09:14:22Z",
"updated_at": "2026-10-07T09:14:22Z",
"published_at": null,
"country_support": null
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Flow not found"
}{
"detail": {
"message": "Flow failed validation",
"errors": [
"Flow has no Start node."
]
}
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Update a flow
Who can call it: tenant_admin, tenant_reviewer, tenant_api_manager or platform_admin. A tenant_viewer is read-only and gets 403.
Saves name, description, graph. Each save bumps version. A flow that is the Partner API’s KYC policy can be changed by an admin only (403).
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
Update a flow
curl --request PUT \
--url https://app.sahlfinancial.com/api/v1/flows/{flow_id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Salaried borrower v2"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: 'Salaried borrower v2'})
};
fetch('https://app.sahlfinancial.com/api/v1/flows/{flow_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/flows/{flow_id}"
payload = { "name": "Salaried borrower v2" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"id": "d6a3f9b8-2c5e-4170-b8d1-4e0a7c3f5b29",
"tenant_id": "0b6f5a3e-7c1d-4e0a-9d2f-3a1c5e8b7f10",
"name": "Salaried borrower v2",
"description": null,
"use_case": "lending",
"kind": "kyc",
"country": "MA",
"nodes": [
{
"id": "start",
"type": "start",
"position": {
"x": 0,
"y": 0
},
"data": {
"label": "Start"
}
},
{
"id": "end",
"type": "end",
"position": {
"x": 240,
"y": 0
},
"data": {
"label": "End"
}
}
],
"edges": [
{
"id": "e1",
"source": "start",
"target": "end"
}
],
"version": 2,
"is_published": false,
"status": "draft",
"environment": "sandbox",
"created_at": "2026-10-07T09:14:22Z",
"updated_at": "2026-10-07T09:14:22Z",
"published_at": null,
"country_support": null
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Flow not found"
}{
"detail": {
"message": "Flow failed validation",
"errors": [
"Flow has no Start node."
]
}
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Authorizations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.
Path Parameters
Body
application/json
Response
OK
Available options:
kyc, kyb "ga", "beta" (CI, SN, TN, EG, SA) or None for the flow's country.