Update a scoring policy
curl --request PUT \
--url https://app.sahlfinancial.com/api/v1/scoring/policies/{policy_id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Standard 2026",
"weights": {
"income_stability": 0.35,
"debt_ratio": 0.3,
"bank_behaviour": 0.2,
"documents": 0.15
},
"approve_threshold": 720,
"refuse_threshold": 500
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Standard 2026',
weights: {income_stability: 0.35, debt_ratio: 0.3, bank_behaviour: 0.2, documents: 0.15},
approve_threshold: 720,
refuse_threshold: 500
})
};
fetch('https://app.sahlfinancial.com/api/v1/scoring/policies/{policy_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/scoring/policies/{policy_id}"
payload = {
"name": "Standard 2026",
"weights": {
"income_stability": 0.35,
"debt_ratio": 0.3,
"bank_behaviour": 0.2,
"documents": 0.15
},
"approve_threshold": 720,
"refuse_threshold": 500
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"id": "2f8c1d5a-7b3e-4e96-8a4d-0c6b9e1f3d72",
"path": "kyc",
"country": "MA",
"name": "Standard 2026",
"description": "Default thresholds",
"weights": {
"income_stability": 0.3,
"debt_ratio": 0.3,
"bank_behaviour": 0.2,
"documents": 0.2
},
"approve_threshold": 720,
"refuse_threshold": 500,
"dti_cap_pct": 40,
"require_cnss": true,
"require_domiciliation": false,
"gds_cap_pct": null,
"tds_cap_pct": null,
"min_bureau_score": null,
"is_active": false
}{
"detail": "Weights sum to 1.3000; must lie in [0.95, 1.05] (re-normalised to 1.0 on save)"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Policy not found"
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Update a scoring policy
Who can call it: tenant_admin or platform_admin.
Replaces name, description, weights and thresholds. path and country in the body are ignored. Cases already scored keep their breakdown.
Auth: dashboard session (Authorization: Bearer <access token>). Not available with a partner API key.
Update a scoring policy
curl --request PUT \
--url https://app.sahlfinancial.com/api/v1/scoring/policies/{policy_id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Standard 2026",
"weights": {
"income_stability": 0.35,
"debt_ratio": 0.3,
"bank_behaviour": 0.2,
"documents": 0.15
},
"approve_threshold": 720,
"refuse_threshold": 500
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'Standard 2026',
weights: {income_stability: 0.35, debt_ratio: 0.3, bank_behaviour: 0.2, documents: 0.15},
approve_threshold: 720,
refuse_threshold: 500
})
};
fetch('https://app.sahlfinancial.com/api/v1/scoring/policies/{policy_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.sahlfinancial.com/api/v1/scoring/policies/{policy_id}"
payload = {
"name": "Standard 2026",
"weights": {
"income_stability": 0.35,
"debt_ratio": 0.3,
"bank_behaviour": 0.2,
"documents": 0.15
},
"approve_threshold": 720,
"refuse_threshold": 500
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"id": "2f8c1d5a-7b3e-4e96-8a4d-0c6b9e1f3d72",
"path": "kyc",
"country": "MA",
"name": "Standard 2026",
"description": "Default thresholds",
"weights": {
"income_stability": 0.3,
"debt_ratio": 0.3,
"bank_behaviour": 0.2,
"documents": 0.2
},
"approve_threshold": 720,
"refuse_threshold": 500,
"dti_cap_pct": 40,
"require_cnss": true,
"require_domiciliation": false,
"gds_cap_pct": null,
"tds_cap_pct": null,
"min_bureau_score": null,
"is_active": false
}{
"detail": "Weights sum to 1.3000; must lie in [0.95, 1.05] (re-normalised to 1.0 on save)"
}{
"detail": "Invalid or expired token"
}{
"detail": "Insufficient permissions"
}{
"detail": "Policy not found"
}{
"detail": [
{
"type": "missing",
"loc": [
"body",
"bank_code"
],
"msg": "Field required",
"input": {}
}
]
}{
"code": "rate_limit_exceeded",
"message": "Too many requests. Please slow down."
}Authorizations
The access token (JWT) of a signed-in console user, from POST /v1/auth/login. It lasts 30 minutes. It is not an API key: a partner API key is refused here. There is no cookie.
Path Parameters
Body
application/json
Required string length:
1 - 120Show child attributes
Show child attributes
Response
OK
Show child attributes
Show child attributes