Update programme configuration
/v1/programs/{id}Requires an API client bearer token.
Updates mutable programme config. Requires an Idempotency-Key header. Restricted to programme admins of this programme, org admins, and org-wide API clients; programme members without the programme_admin role receive 403. `delegated_auth_url`, `sponsor_acs_url` and `delegated_mtls_pinned_ca` are per-mode: they apply to the face for the mode this request is authenticated in, and sending null clears them. Clearing the pinned CA disables the programme’s delegated authorization path. `delegated_auth_url` and `sponsor_acs_url` ARE echoed in the response body (both are on the console representation); `delegated_mtls_pinned_ca` is NOT — it carries no console field. `dpa_accepted_at` is the opposite on both counts: it is mode-agnostic (one data processing agreement covers the programme) and it IS returned in the response body. Sending null revokes the acceptance, which also disables the programme’s delegated authorization path. `three_ds_config` (the 3DS challenge policy) is mode-agnostic like `dpa_accepted_at` and sending null clears it, reverting every consumer to its own built-in default. Disabling the ledger module while the programme's cardholders hold balances (in either mode) is rejected 409; if the ledger cannot be reached to check, the disable is refused 503 rather than permitted. Changing `modules.managed_authorization` — flipping between managed and delegated authorization — on a programme that has approved a non-zero amount in either mode is rejected 409 `authorization_switch_locked`, naming the modes that hold the lock; if no mode could be shown to hold it and a mode could not be read, the change is refused 503 `authorization_unreachable` rather than permitted.
Parameters
Path parameters
| Name | Required | Description |
|---|---|---|
| id | required |
Header parameters
| Name | Required | Description |
|---|---|---|
| Idempotency-Key | required | Client-chosen. An identical retry with the same key returns the stored response; reusing the key with a different payload returns 409. |
Request body
Non-toggleable keys are accepted but persisted false
+ show properties− hide properties
true = M2 (we decide); false = M2b delegated
Per-mode platform settlement account a refund credit is drawn from. Absent ⇒ refunds decline.
+ show properties− hide properties
+ show properties− hide properties
Allowed WebAuthn origins, each the BARE origin a browser sends in its Origin header — scheme://host with a port only when it is not the default, and no path, trailing slash, query, fragment or userinfo. Each origin's host must be passkey_rp_id or a subdomain of it, or the browser refuses the ceremony. `http` is accepted only for localhost.
Example
curl -X PATCH https://api.rigid.fi/v1/programs/{id} \
-H "Authorization: Bearer $RIGID_API_TOKEN" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"name": "string",
"modules": {
"ledger": true,
"managed_authorization": true,
"kyc": true,
"fraud": true,
"three_ds": true,
"tokenization": true
},
"delegated_auth_url": "uri",
"sponsor_acs_url": "uri",
"delegated_mtls_pinned_ca": "string",
"refund_float_accounts": {
"test": "string",
"live": "string"
}
}'Responses
200Updated programme.
+ show properties− hide properties
Per-mode platform settlement account a refund credit is drawn from. Absent ⇒ refunds decline.
+ show properties− hide properties
+ show properties− hide properties
Allowed WebAuthn origins, each the BARE origin a browser sends in its Origin header — scheme://host with a port only when it is not the default, and no path, trailing slash, query, fragment or userinfo. Each origin's host must be passkey_rp_id or a subdomain of it, or the browser refuses the ceremony. `http` is accepted only for localhost.
400Validation error
401Authentication required
403Forbidden
404Programme not found
409Module has dependencies (`module_has_dependencies`); the programme has approved a non-zero amount, so who decides its authorizations can no longer be changed through this route (`authorization_switch_locked`, naming the modes that hold the lock); or the Idempotency-Key was reused with a different payload.
500Internal server error
503The ledger could not be reached to check for cardholder balances, so disabling the ledger module is refused (`ledger_unreachable`); or the authorization service could not be read to check for approvals and no mode was shown to hold the switch lock, so changing `managed_authorization` is refused (`authorization_unreachable`). Distinct from 409: nobody knows whether the blocking fact exists, so retry once the dependency is back.