> ## Documentation Index
> Fetch the complete documentation index at: https://autorender.io/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Update source

> Partially update a source by its id.

<Note>
  **Key type:** requires a private key. A public key returns `403` here, because it may only
  upload — see [key types and scope](/docs/api-reference/introduction#key-types-and-scope). Call
  this from your server, never from browser code.
</Note>

<RequestExample>
  ```bash cURL theme={null}
  curl --request PATCH \
    --url 'https://upload.autorender.io/api/v1/sources/974628c2-9b55-4ce4-adf1-9b63edff6baa' \
    --header 'Authorization: Bearer YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{
    "name": "renamed_source"
  }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "success": true,
    "data": {
      "id": "974628c2-9b55-4ce4-adf1-9b63edff6baa",
      "name": "renamed_source",
      "type": "image_source",
      "configuration": {
        "base_url": "https://cdn.example.com",
        "forward_header": true
      },
      "is_active": true,
      "created_at": "2026-03-27T14:58:53.795Z",
      "updated_at": "2026-03-28T09:03:11.402Z"
    }
  }
  ```

  ```json 404 theme={null}
  {
    "error": "Source not found"
  }
  ```

  ```json 409 theme={null}
  {
    "error": "Origin name already exists in this workspace"
  }
  ```
</ResponseExample>

## Overview

Partially updates the source identified by **`sourceId`**. Both fields are optional — send only what changes. When **`configuration`** is provided, its fields are merged into the existing configuration rather than replacing it, and previously-masked secret fields you send back unchanged (e.g. `"****"`) are left untouched.

## Path parameters

| Parameter  | Description                |
| ---------- | -------------------------- |
| `sourceId` | Source id (UUID) to update |

## Request body

| Field           | Type   | Required | Description                                                                                  |
| --------------- | ------ | -------- | -------------------------------------------------------------------------------------------- |
| `name`          | string | No       | New name — letters, numbers, underscores, and hyphens only. Must be unique in the workspace. |
| `configuration` | object | No       | Fields to merge into the existing configuration                                              |

## Response

The updated source, wrapped as `{ "success": true, "data": { ... } }`.

## Next steps

<CardGroup cols={2}>
  <Card title="Source details" icon="circle-info" iconType="solid" href="/docs/api-reference/get-source-details">
    Fetch the current state of a source.
  </Card>

  <Card title="Delete source" icon="trash" iconType="solid" href="/docs/api-reference/delete-source">
    Permanently remove a source from your workspace.
  </Card>
</CardGroup>


## OpenAPI

````yaml api-reference/openapi.json PATCH /api/v1/sources/{sourceId}
openapi: 3.0.0
info:
  title: AutoRender Public API
  description: >-
    REST API for uploading, managing, and serving media assets. All endpoints
    require an API key via the x-api-key header or Authorization: Bearer <key>.
  version: 1.0.0
  contact:
    name: AutoRender Support
    email: support@autorender.io
servers:
  - url: https://app-api.autorender.io
    description: Production server
security:
  - apiKey: []
tags:
  - name: Uploads
    description: Upload endpoints (API key required)
  - name: Files
    description: File management endpoints (API key required)
  - name: Folders
    description: Folder management endpoints (API key required)
  - name: Sources
    description: Source management endpoints (API key required)
paths:
  /api/v1/sources/{sourceId}:
    patch:
      tags:
        - Sources
      summary: Update source
      description: Partially update a source. Configuration fields are merged.
      operationId: updateSource
      parameters:
        - schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          in: path
          name: sourceId
          required: true
          description: Source ID
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 255
                  pattern: ^[a-zA-Z0-9_-]+$
                configuration:
                  description: Fields to merge into the existing configuration
                  type: object
                  properties: {}
                  additionalProperties:
                    x-stainless-any: true
      responses:
        '200':
          description: Updated source
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      name:
                        type: string
                      type:
                        type: string
                        enum:
                          - s3
                          - azure
                          - google_cloud
                          - image_source
                      configuration:
                        type: object
                        properties: {}
                        additionalProperties:
                          x-stainless-any: true
                      is_active:
                        type: boolean
                      created_at:
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                      updated_at:
                        nullable: true
                        type: string
                        format: date-time
                        pattern: >-
                          ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
                    required:
                      - id
                      - name
                      - type
                      - configuration
                      - is_active
                      - created_at
                      - updated_at
                    additionalProperties: false
                required:
                  - success
                  - data
                additionalProperties: false
                description: Updated source
        '400':
          description: Invalid payload
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
                description: Invalid payload
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
                  - message
                additionalProperties: false
                description: Unauthorized
        '403':
          description: Private API key required
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
                  - message
                additionalProperties: false
                description: Private API key required
        '404':
          description: Source not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
                description: Source not found
        '409':
          description: Source name already exists
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
                description: Source name already exists
        '429':
          description: Rate limit exceeded
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                  retryAfterSeconds:
                    type: number
                required:
                  - error
                  - message
                additionalProperties: false
                description: Rate limit exceeded
      security:
        - apiKey: []
components:
  securitySchemes:
    apiKey:
      type: apiKey
      name: x-api-key
      in: header
      description: >-
        API key for public endpoints. Can also be provided via Authorization:
        Bearer <key>

````