Update Website
Updates a website. Supports both partial updates (only sent fields are changed) and full updates (all required fields must be present).
PATCH /api/websites/:websitePublicId
A request is treated as a full update when customerId, name, and url are all present in the body. Otherwise, it is treated as a partial update.
Example (cURL): Partial update
BASE_URL="https://uptimeify.io"
TOKEN="<your-api-token>"
curl -X PATCH "$BASE_URL/api/websites/9a3d4d4d-7a4b-4f37-a9df-2a6f6d9d7a10" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{
"name": "Updated Website Name",
"checkInterval": 5,
"timeoutSeconds": 10
}'Example (cURL): Full update with HTTP configuration
curl -X PATCH "$BASE_URL/api/websites/9a3d4d4d-7a4b-4f37-a9df-2a6f6d9d7a10" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{
"customerId": 5,
"name": "API Endpoint Monitor",
"url": "https://api.deinkunde.com/health",
"httpMethod": "POST",
"customHeaders": { "X-API-Key": "abc123", "Content-Type": "application/json" },
"requestBody": "{\"check\": true}",
"followRedirects": false,
"cookieHandling": "jar",
"mtlsEnabled": true,
"mtlsClientCert": "<PEM-encoded client certificate>",
"mtlsClientKey": "<PEM-encoded private key>"
}'Request Body
For a full update, customerId, name and url are required; every other field is optional.
A partial update applies these fields: name, url, status, managementType, checkInterval, timeoutSeconds, expectedStatusCodes, searchTerm, checkExpectedResponseEnabled, expectedResponseMatchType, expectedResponseValue, expectedResponseJsonPath, heartbeatGracePeriodMinutes, connectHost, connectPort, connectTlsInsecure, the six check fields, checkDomainExpiryEnabled, sslNoticeDays, sslErrorDays, domainExpiryNoticeDays, domainExpiryErrorDays, minPageSize and maxPageSize. Everything else in the tables below (monitoringType, allowedCheckCountryCodes, customFields, the authentication, HTTP request, mTLS and Playwright fields, and dnsConfig) is applied by a full update only: sent on its own it is ignored, without an error. Send customerId, name and url alongside it, or use the dedicated endpoints where they exist.
Core fields
| Field | Type | Description |
|---|---|---|
customerId | number|string | Customer public ID (preferred) or legacy numeric ID |
name | string | Display name (1-255 chars) |
url | string | URL to monitor (max 2048 chars). HTTP monitors need a full URL including protocol; DNS monitors take a bare hostname (no protocol, no path). |
monitoringType | string | combined, http_status, ssl_check, playwright, heartbeat, dns |
status | string | active, inactive, maintenance (paused → inactive) |
checkInterval | number | Check interval in minutes. 1-1440 (24 hours) for actively scheduled monitors, 1-43200 (30 days) for heartbeat monitors. The ceiling follows the monitor's type, taking monitoringType from the request when sent and the stored type otherwise. |
timeoutSeconds | number | Request timeout in seconds (1-60) |
expectedStatusCodes | string | Comma-separated expected HTTP status codes |
allowedCheckCountryCodes | string[]|null | Array of 2-letter country codes, or null to reset to org default |
searchTerm | string|null | Keyword to search for (null clears it) |
customFields | object|null | Custom field values |
managementType | string | Ownership class: managed or self_service: see Managed vs. Self-Service. Changing the class is organization-admin-only; flipping to self_service requires allowSelfService and free quota. |
Authentication
| Field | Type | Description |
|---|---|---|
authMode | string | none, authorization_header, basic. Setting to none clears auth credentials. |
authorizationHeader | string|null | Required when authMode is authorization_header. Encrypted at rest. |
basicAuthUsername | string|null | Required when authMode is basic. |
basicAuthPassword | string|null | Required when authMode is basic. Encrypted at rest. |
HTTP Request Configuration
| Field | Type | Description |
|---|---|---|
httpMethod | string | GET, QUERY, POST, PUT, PATCH, DELETE, HEAD, OPTIONS |
customHeaders | object|null | Custom HTTP headers (keys: 1-100 chars, values: max 8192 chars). Null clears them. Encrypted at rest. |
requestBody | string|null | Request body, max 100KB. Sent with every method except GET and HEAD. Null clears it. Encrypted at rest. |
followRedirects | boolean | Whether to follow HTTP redirects |
cookieHandling | string | none or jar (maintain cookie jar across redirects) |
Connect target (Ersatzziel)
| Field | Type | Description |
|---|---|---|
connectHost | string|null | Connects to this host/IP instead of the one in url; URL, path, Host header and TLS SNI stay unchanged. Host only, or host with port; IPv6 in brackets. null clears the connect target and also resets connectTlsInsecure to false. Private, loopback, link-local and otherwise blocked addresses are rejected (connectHostNotPublic). |
connectPort | number|null | Port to use with connectHost (1-65535). Only applied when connectHost is sent in the same request; sending it alone has no effect. |
connectTlsInsecure | boolean | Skips certificate verification for connectHost. Only valid together with a connectHost that is set (connectTlsInsecureWithoutHost otherwise). |
Applies on a partial update as well as a full update. Not available for playwright scenarios or heartbeat monitors: both bypass the HTTP/SSL check pipeline connectHost plugs into. If checkHttpsRedirectEnabled is on, the http-to-https redirect probe follows connectHost too, so it measures the origin - a WAF-owned redirect can then turn the monitor red even though the public site redirects correctly.
mTLS (Mutual TLS)
| Field | Type | Description |
|---|---|---|
mtlsEnabled | boolean | Enable mutual TLS authentication. Setting to false clears cert and key. |
mtlsClientCert | string|null | Client certificate (max 100KB). Required when mtlsEnabled is true. Encrypted at rest. |
mtlsClientKey | string|null | Client private key (max 100KB). Required when mtlsEnabled is true. Encrypted at rest. |
Playwright Monitoring
| Field | Type | Description |
|---|---|---|
playwrightScript | string|null | Required when monitoringType is playwright (1-100000 chars) |
playwrightEnv | object|null | Environment variables (max 50, keys must match ^[A-Z_][A-Z0-9_]*$) |
playwrightDevice | string|null | Device emulation preset |
playwrightViewportWidth | number|null | Viewport width (1-3840). Must be set with playwrightViewportHeight. |
playwrightViewportHeight | number|null | Viewport height (1-3840). Must be set with playwrightViewportWidth. |
playwrightRetries | number|null | Retries (0-5) |
playwrightTimeoutMs | number|null | Timeout in milliseconds (1000-180000) |
Expected Response Validation
| Field | Type | Description |
|---|---|---|
checkExpectedResponseEnabled | boolean | Enable response body validation |
expectedResponseMatchType | string|null | contains, equals, json_path_equals |
expectedResponseValue | string|null | Value to match (max 10000 chars). Required when enabled. |
expectedResponseJsonPath | string|null | JSON path (max 500 chars). Required when json_path_equals. |
Check Configuration
| Field | Type | Description |
|---|---|---|
checkSslEnabled | boolean | Enable SSL checks (disabled for Playwright) |
checkHttpsRedirectEnabled | boolean | Check HTTPS redirect (disabled for Playwright) |
checkStatusEnabled | boolean | Check HTTP status (disabled for Playwright) |
checkSizeEnabled | boolean | Check response size (disabled for Playwright) |
checkResponseTimeEnabled | boolean | Check response time (disabled for Playwright) |
checkKeywordEnabled | boolean | Enable keyword search (disabled for Playwright) |
An omitted check field leaves the stored value unchanged. Your organization's package may forbid a given check: sending true for a check the package does not allow is only clamped back to false when the check is not already running; a check already stored as true is never turned off by the package, on this or any other update.
SSL & Domain Thresholds
| Field | Type | Description |
|---|---|---|
sslNoticeDays | number | SSL notice threshold (1-365, must be ≥ sslErrorDays) |
sslErrorDays | number | SSL error threshold (0-365) |
checkDomainExpiryEnabled | boolean | Enable domain expiry checks (disabled for Playwright) |
domainExpiryNoticeDays | number | Domain expiry notice threshold (1-365) |
domainExpiryErrorDays | number | Domain expiry error threshold (0-365) |
Page Size & Other
| Field | Type | Description |
|---|---|---|
minPageSize | number|null | Minimum page size in bytes (must be ≤ maxPageSize) |
maxPageSize | number|null | Maximum page size in bytes |
dnsConfig | object | DNS query configuration (only for dns monitoring type) |
heartbeatGracePeriodMinutes | number | Heartbeat grace period (1-10080) |
Response
Returns the updated website record. Encrypted fields are never included in responses.
{
"id": 101,
"customerId": 1,
"name": "Updated Website Name",
"url": "https://deinkunde.com",
"status": "active",
"monitoringType": "combined",
"checkInterval": 5,
"timeoutSeconds": 10,
"httpMethod": "POST",
"followRedirects": false,
"cookieHandling": "jar",
"mtlsEnabled": true,
"connectHost": null,
"connectPort": null,
"connectTlsInsecure": false,
"updatedAt": "2026-02-26T12:34:56.000Z"
}Common errors
400 Website public ID (UUID) is requiredwhen:websitePublicIdis missing401 Unauthorizedwhen you are not logged in403 Forbiddenwhen you cannot write to the website (e.g. readonly/global supporter)403 Forbidden(managed_by_organization) when a customer-scoped caller edits amanagedmonitor without thecanEditManagedexception403 Forbidden(managementTypeOrgOnly) when a non-org-admin tries to changemanagementType403 Forbidden(selfServiceQuotaReached) when flipping toself_servicewould exceed the customer's quota404 Customer not foundwhencustomerIddoes not resolve to an existing customer400 Invalid check configuration(invalidCheckConfig) when a partial update sends a check field outside its range (e.g.sslNoticeDays: 400)400 Bad Request(connectHostInvalid) whenconnectHostis not a valid host, or carries a protocol or a path400 Bad Request(connectHostNotPublic) whenconnectHostresolves to a private, loopback, link-local or otherwise blocked address400 Bad Request(connectTlsInsecureWithoutHost) when the resultingconnectTlsInsecureistruewhile the resultingconnectHostis empty500 Failed to update websiteon server errors