Update a flow via the flows sub-agent
{id} is the flow NAME, not the row id. The change is applied by the flows sub-agent; flow JSON is never hand-edited. Consumes credits.
A 200 does not mean the update landed. As with POST /v1/flows, the body is either the full result or a bail-out { "success": false, "error": … } — an unknown flow name, unparseable stored JSON, or a cancelled run all return 200 in that shape. Check success and the presence of flow_name before reading the rest.
Required scope: flows:write
Authorizations
Project API key issued in Settings → API keys. Send it as Authorization: Bearer pk_live_….
Headers
Target project id, for an MCP OAuth bearer (mcp_at_…) attached to more than one project — get ids from GET /v1/projects. Matched case-insensitively.
Omit it and a READ falls back to the connection's default project; a mutation (any non-GET) on a connection with 2+ projects is rejected with 400 project_required — a write is never defaulted to a guessed project. A connection with exactly one project never needs the header.
Scopes are checked against the SELECTED project only, never a union across the connection.
For a pk_ API key the header selects nothing — one key is one project's context — but it IS validated: omit it and the key's own project is used, send it and it must name that project, otherwise the call is rejected with 403 project_not_attached (a blank value is 400 invalid_project_header, as above).
Path Parameters
Body
Natural-language description of the change to make to the flow.
1 - 5000