Uptimeify Docs
Websites

Update Website

Updates a website. Supports both partial updates (only sent fields are changed) and full updates (all required fields must be present).

PATCH /api/websites/:websitePublicId

A request is treated as a full update when customerId, name, and url are all present in the body. Otherwise, it is treated as a partial update.

Example (cURL): Partial update

BASE_URL="https://uptimeify.io"
TOKEN="<your-api-token>"

curl -X PATCH "$BASE_URL/api/websites/9a3d4d4d-7a4b-4f37-a9df-2a6f6d9d7a10" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json" \
  -d '{
    "name": "Updated Website Name",
    "checkInterval": 5,
    "timeoutSeconds": 10
  }'

Example (cURL): Full update with HTTP configuration

curl -X PATCH "$BASE_URL/api/websites/9a3d4d4d-7a4b-4f37-a9df-2a6f6d9d7a10" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json" \
  -d '{
    "customerId": 5,
    "name": "API Endpoint Monitor",
    "url": "https://api.deinkunde.com/health",
    "httpMethod": "POST",
    "customHeaders": { "X-API-Key": "abc123", "Content-Type": "application/json" },
    "requestBody": "{\"check\": true}",
    "followRedirects": false,
    "cookieHandling": "jar",
    "mtlsEnabled": true,
    "mtlsClientCert": "<PEM-encoded client certificate>",
    "mtlsClientKey": "<PEM-encoded private key>"
  }'

Request Body

For a full update, customerId, name and url are required; every other field is optional.

A partial update applies these fields: name, url, status, managementType, checkInterval, timeoutSeconds, expectedStatusCodes, searchTerm, checkExpectedResponseEnabled, expectedResponseMatchType, expectedResponseValue, expectedResponseJsonPath, heartbeatGracePeriodMinutes, connectHost, connectPort, connectTlsInsecure, the six check fields, checkDomainExpiryEnabled, sslNoticeDays, sslErrorDays, domainExpiryNoticeDays, domainExpiryErrorDays, minPageSize and maxPageSize. Everything else in the tables below (monitoringType, allowedCheckCountryCodes, customFields, the authentication, HTTP request, mTLS and Playwright fields, and dnsConfig) is applied by a full update only: sent on its own it is ignored, without an error. Send customerId, name and url alongside it, or use the dedicated endpoints where they exist.

Core fields

FieldTypeDescription
customerIdnumber|stringCustomer public ID (preferred) or legacy numeric ID
namestringDisplay name (1-255 chars)
urlstringURL to monitor (max 2048 chars). HTTP monitors need a full URL including protocol; DNS monitors take a bare hostname (no protocol, no path).
monitoringTypestringcombined, http_status, ssl_check, playwright, heartbeat, dns
statusstringactive, inactive, maintenance (paused → inactive)
checkIntervalnumberCheck interval in minutes. 1-1440 (24 hours) for actively scheduled monitors, 1-43200 (30 days) for heartbeat monitors. The ceiling follows the monitor's type, taking monitoringType from the request when sent and the stored type otherwise.
timeoutSecondsnumberRequest timeout in seconds (1-60)
expectedStatusCodesstringComma-separated expected HTTP status codes
allowedCheckCountryCodesstring[]|nullArray of 2-letter country codes, or null to reset to org default
searchTermstring|nullKeyword to search for (null clears it)
customFieldsobject|nullCustom field values
managementTypestringOwnership class: managed or self_service: see Managed vs. Self-Service. Changing the class is organization-admin-only; flipping to self_service requires allowSelfService and free quota.

Authentication

FieldTypeDescription
authModestringnone, authorization_header, basic. Setting to none clears auth credentials.
authorizationHeaderstring|nullRequired when authMode is authorization_header. Encrypted at rest.
basicAuthUsernamestring|nullRequired when authMode is basic.
basicAuthPasswordstring|nullRequired when authMode is basic. Encrypted at rest.

HTTP Request Configuration

FieldTypeDescription
httpMethodstringGET, QUERY, POST, PUT, PATCH, DELETE, HEAD, OPTIONS
customHeadersobject|nullCustom HTTP headers (keys: 1-100 chars, values: max 8192 chars). Null clears them. Encrypted at rest.
requestBodystring|nullRequest body, max 100KB. Sent with every method except GET and HEAD. Null clears it. Encrypted at rest.
followRedirectsbooleanWhether to follow HTTP redirects
cookieHandlingstringnone or jar (maintain cookie jar across redirects)

Connect target (Ersatzziel)

FieldTypeDescription
connectHoststring|nullConnects to this host/IP instead of the one in url; URL, path, Host header and TLS SNI stay unchanged. Host only, or host with port; IPv6 in brackets. null clears the connect target and also resets connectTlsInsecure to false. Private, loopback, link-local and otherwise blocked addresses are rejected (connectHostNotPublic).
connectPortnumber|nullPort to use with connectHost (1-65535). Only applied when connectHost is sent in the same request; sending it alone has no effect.
connectTlsInsecurebooleanSkips certificate verification for connectHost. Only valid together with a connectHost that is set (connectTlsInsecureWithoutHost otherwise).

Applies on a partial update as well as a full update. Not available for playwright scenarios or heartbeat monitors: both bypass the HTTP/SSL check pipeline connectHost plugs into. If checkHttpsRedirectEnabled is on, the http-to-https redirect probe follows connectHost too, so it measures the origin - a WAF-owned redirect can then turn the monitor red even though the public site redirects correctly.

mTLS (Mutual TLS)

FieldTypeDescription
mtlsEnabledbooleanEnable mutual TLS authentication. Setting to false clears cert and key.
mtlsClientCertstring|nullClient certificate (max 100KB). Required when mtlsEnabled is true. Encrypted at rest.
mtlsClientKeystring|nullClient private key (max 100KB). Required when mtlsEnabled is true. Encrypted at rest.

Playwright Monitoring

FieldTypeDescription
playwrightScriptstring|nullRequired when monitoringType is playwright (1-100000 chars)
playwrightEnvobject|nullEnvironment variables (max 50, keys must match ^[A-Z_][A-Z0-9_]*$)
playwrightDevicestring|nullDevice emulation preset
playwrightViewportWidthnumber|nullViewport width (1-3840). Must be set with playwrightViewportHeight.
playwrightViewportHeightnumber|nullViewport height (1-3840). Must be set with playwrightViewportWidth.
playwrightRetriesnumber|nullRetries (0-5)
playwrightTimeoutMsnumber|nullTimeout in milliseconds (1000-180000)

Expected Response Validation

FieldTypeDescription
checkExpectedResponseEnabledbooleanEnable response body validation
expectedResponseMatchTypestring|nullcontains, equals, json_path_equals
expectedResponseValuestring|nullValue to match (max 10000 chars). Required when enabled.
expectedResponseJsonPathstring|nullJSON path (max 500 chars). Required when json_path_equals.

Check Configuration

FieldTypeDescription
checkSslEnabledbooleanEnable SSL checks (disabled for Playwright)
checkHttpsRedirectEnabledbooleanCheck HTTPS redirect (disabled for Playwright)
checkStatusEnabledbooleanCheck HTTP status (disabled for Playwright)
checkSizeEnabledbooleanCheck response size (disabled for Playwright)
checkResponseTimeEnabledbooleanCheck response time (disabled for Playwright)
checkKeywordEnabledbooleanEnable keyword search (disabled for Playwright)

An omitted check field leaves the stored value unchanged. Your organization's package may forbid a given check: sending true for a check the package does not allow is only clamped back to false when the check is not already running; a check already stored as true is never turned off by the package, on this or any other update.

SSL & Domain Thresholds

FieldTypeDescription
sslNoticeDaysnumberSSL notice threshold (1-365, must be ≥ sslErrorDays)
sslErrorDaysnumberSSL error threshold (0-365)
checkDomainExpiryEnabledbooleanEnable domain expiry checks (disabled for Playwright)
domainExpiryNoticeDaysnumberDomain expiry notice threshold (1-365)
domainExpiryErrorDaysnumberDomain expiry error threshold (0-365)

Page Size & Other

FieldTypeDescription
minPageSizenumber|nullMinimum page size in bytes (must be ≤ maxPageSize)
maxPageSizenumber|nullMaximum page size in bytes
dnsConfigobjectDNS query configuration (only for dns monitoring type)
heartbeatGracePeriodMinutesnumberHeartbeat grace period (1-10080)

Response

Returns the updated website record. Encrypted fields are never included in responses.

{
  "id": 101,
  "customerId": 1,
  "name": "Updated Website Name",
  "url": "https://deinkunde.com",
  "status": "active",
  "monitoringType": "combined",
  "checkInterval": 5,
  "timeoutSeconds": 10,
  "httpMethod": "POST",
  "followRedirects": false,
  "cookieHandling": "jar",
  "mtlsEnabled": true,
  "connectHost": null,
  "connectPort": null,
  "connectTlsInsecure": false,
  "updatedAt": "2026-02-26T12:34:56.000Z"
}

Common errors

  • 400 Website public ID (UUID) is required when :websitePublicId is missing
  • 401 Unauthorized when you are not logged in
  • 403 Forbidden when you cannot write to the website (e.g. readonly/global supporter)
  • 403 Forbidden (managed_by_organization) when a customer-scoped caller edits a managed monitor without the canEditManaged exception
  • 403 Forbidden (managementTypeOrgOnly) when a non-org-admin tries to change managementType
  • 403 Forbidden (selfServiceQuotaReached) when flipping to self_service would exceed the customer's quota
  • 404 Customer not found when customerId does not resolve to an existing customer
  • 400 Invalid check configuration (invalidCheckConfig) when a partial update sends a check field outside its range (e.g. sslNoticeDays: 400)
  • 400 Bad Request (connectHostInvalid) when connectHost is not a valid host, or carries a protocol or a path
  • 400 Bad Request (connectHostNotPublic) when connectHost resolves to a private, loopback, link-local or otherwise blocked address
  • 400 Bad Request (connectTlsInsecureWithoutHost) when the resulting connectTlsInsecure is true while the resulting connectHost is empty
  • 500 Failed to update website on server errors

On this page