> ## Documentation Index
> Fetch the complete documentation index at: https://docs.passlet.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a pass

> Changes an issued pass and queues the update to wallet passes already installed on devices. Send only what changes: `label`, `variables` (merged over the stored values, where `null` removes one), and `templateVersion` to move the pass to a newer published version of its template. The change is validated against the template version the pass will render and lands as one new `revision`; a request that changes nothing leaves the pass as it is. With `dryRun=true` the response shows the pass as the change would leave it, and nothing is saved. To change the pass only if nobody else has, send the `ETag` of your last read in `If-Match`: if the pass has changed since, the request fails with `412` (`PRECONDITION_FAILED`).

Requires the `passes:write` scope on the access token.



## OpenAPI

````yaml /api-reference/openapi.json patch /v1/passes/{id}
openapi: 3.1.0
info:
  title: Passlet API (Public)
  version: 0.3.0
  description: >-
    Public integration API for Passlet. Every route is callable with a `plt_*`
    access token, and each operation lists the required access-token scope.
  license:
    name: UNLICENSED
    identifier: UNLICENSED
servers:
  - url: https://api.passlet.io
    description: Production
security: []
paths:
  /v1/passes/{id}:
    patch:
      tags:
        - passes
      summary: Update a pass
      description: >-
        Changes an issued pass and queues the update to wallet passes already
        installed on devices. Send only what changes: `label`, `variables`
        (merged over the stored values, where `null` removes one), and
        `templateVersion` to move the pass to a newer published version of its
        template. The change is validated against the template version the pass
        will render and lands as one new `revision`; a request that changes
        nothing leaves the pass as it is. With `dryRun=true` the response shows
        the pass as the change would leave it, and nothing is saved. To change
        the pass only if nobody else has, send the `ETag` of your last read in
        `If-Match`: if the pass has changed since, the request fails with `412`
        (`PRECONDITION_FAILED`).


        Requires the `passes:write` scope on the access token.
      operationId: patchV1PassesId
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            pattern: >-
              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          description: Pass identifier
        - name: dryRun
          in: query
          required: false
          schema:
            type: boolean
          description: >-
            Validate the change and return the pass as it would be, without
            saving it or updating wallets.
        - name: If-Match
          in: header
          required: false
          schema:
            type: string
          description: >-
            The pass `revision` you last read, as an entity tag (`"4"`). If the
            pass has changed since, nothing is written and the request fails
            with `412` (`PRECONDITION_FAILED`).
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PublicUpdatePassRequest'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicCreatePassResponse'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '412':
          description: Precondition failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '429':
          description: Rate limited
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
        '503':
          description: Service unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
      security:
        - bearerAuth: []
components:
  schemas:
    PublicUpdatePassRequest:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        label:
          description: New pass holder display name
          type: string
          minLength: 1
          maxLength: 255
        variables:
          description: >-
            Variables to change, merged over the stored values: supplied keys
            replace their values, omitted keys keep theirs, and `null` removes a
            value so the variable falls back to its template default.
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        templateVersion:
          description: >-
            Template version to render the pass with: a published version number
            of the pass’s template, or `latest` for its newest published
            version. Passes only move forward; the version the pass already
            renders changes nothing.
          anyOf:
            - type: integer
              exclusiveMinimum: 0
              maximum: 9007199254740991
            - type: string
              const: latest
              example: latest
      additionalProperties: false
    PublicCreatePassResponse:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
          description: Pass identifier
        externalPassId:
          type: string
          minLength: 1
          maxLength: 255
          description: External system pass ID
        label:
          type: string
          minLength: 1
          maxLength: 255
          description: Pass holder display name
        status:
          type: string
          enum:
            - QUEUED
            - ISSUING
            - ISSUED
            - VOID
            - FAILED
            - EXPIRED
          example: QUEUED
        version:
          type: integer
          exclusiveMinimum: 0
          maximum: 9007199254740991
          deprecated: true
          description: 'Deprecated: use `revision`. Internal change counter of the pass.'
        templateVersionId:
          anyOf:
            - type: string
              format: uuid
              pattern: >-
                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
            - type: 'null'
          description: >-
            Template version the pass currently renders with. Pinned at issue
            time; only changes via an explicit template upgrade to a newer
            published version of the same template.
        templateId:
          anyOf:
            - type: string
              format: uuid
              pattern: >-
                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
              description: Template identifier
            - type: 'null'
          description: Template identifier this pass was issued from
        projectId:
          anyOf:
            - type: string
              format: uuid
              pattern: >-
                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
            - type: 'null'
          description: Project the pass lives in
        variables:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
          description: Stored pass variables
        redemption:
          anyOf:
            - type: object
              properties:
                windows:
                  minItems: 1
                  maxItems: 366
                  type: array
                  items:
                    type: object
                    properties:
                      start:
                        type: string
                        pattern: >-
                          ^\d{4}-(0[1-9]|1[0-2])-(0[1-9]|[12]\d|3[01])T([01]\d|2[0-3]):[0-5]\d(:[0-5]\d(\.\d+)?)?(Z|[+-]([01]\d|2[0-3]):[0-5]\d)$
                      end:
                        type: string
                        pattern: >-
                          ^\d{4}-(0[1-9]|1[0-2])-(0[1-9]|[12]\d|3[01])T([01]\d|2[0-3]):[0-5]\d(:[0-5]\d(\.\d+)?)?(Z|[+-]([01]\d|2[0-3]):[0-5]\d)$
                      maxUses:
                        type: integer
                        minimum: 1
                        maximum: 100000
                    additionalProperties: false
                maxUses:
                  type: integer
                  minimum: 1
                  maximum: 100000
                autoVoidOnExhaustion:
                  type: boolean
                perPeriod:
                  type: object
                  properties:
                    unit:
                      type: string
                      enum:
                        - day
                        - week
                        - month
                      example: day
                    count:
                      type: integer
                      minimum: 1
                      maximum: 100000
                    timezone:
                      type: string
                      pattern: >-
                        ^(?:UTC|GMT|[A-Za-z_]+\/[A-Za-z0-9_+-]+(?:\/[A-Za-z0-9_+-]+)?)$
                      description: IANA timezone identifier
                  required:
                    - unit
                    - count
                    - timezone
                  additionalProperties: false
                minIntervalMinutes:
                  type: integer
                  minimum: 1
                  maximum: 527040
                activation:
                  type: object
                  properties:
                    basis:
                      type: string
                      const: firstScan
                      example: firstScan
                    validForHours:
                      type: integer
                      minimum: 1
                      maximum: 87840
                  required:
                    - basis
                    - validForHours
                  additionalProperties: false
              additionalProperties: false
            - type: 'null'
          description: Resolved redemption policy enforced at scan time
        expiresAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
              description: ISO 8601 timestamp
            - type: 'null'
          description: Pass expiration timestamp
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
          description: ISO 8601 timestamp
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
          description: ISO 8601 timestamp
        revision:
          type: integer
          exclusiveMinimum: 0
          maximum: 9007199254740991
          description: >-
            Revision of the pass, as shown in the console. Increases with every
            change to its label, variables, or template version. Send it in
            `If-Match` to update the pass only if it is unchanged.
        templateVersion:
          anyOf:
            - type: integer
              exclusiveMinimum: 0
              maximum: 9007199254740991
            - type: 'null'
          description: Version number of the template version the pass renders
        latestTemplateVersion:
          anyOf:
            - type: integer
              exclusiveMinimum: 0
              maximum: 9007199254740991
            - type: 'null'
          description: >-
            Newest published version number of the pass’s template. Greater than
            `templateVersion` when an upgrade is available; `null` when the
            template was deleted.
        hostedLinks:
          type: object
          properties:
            apple:
              anyOf:
                - type: string
                  format: uri
                - type: 'null'
              description: Apple Wallet add link
            google:
              anyOf:
                - type: string
                  format: uri
                - type: 'null'
              description: Google Wallet add link
            smart:
              anyOf:
                - type: string
                  format: uri
                - type: 'null'
              description: >-
                Smart link: detects the visitor’s platform and redirects to the
                Apple or Google link for this pass. Falls back to a page
                offering both when the platform is undetermined.
          required:
            - apple
            - google
            - smart
          additionalProperties: false
          description: Hosted add-to-wallet links
      required:
        - id
        - externalPassId
        - label
        - status
        - version
        - templateVersionId
        - templateId
        - projectId
        - variables
        - redemption
        - expiresAt
        - createdAt
        - updatedAt
        - revision
        - templateVersion
        - latestTemplateVersion
        - hostedLinks
      additionalProperties: false
    ApiError:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        errorCode:
          type: string
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - SCANNER_OFFLINE_DISABLED
            - TOKEN_EXPIRED
            - TOKEN_INVALID
            - CSRF_TOKEN_INVALID
            - TENANT_EXPIRED
            - TENANT_NOT_FOUND
            - ORGANIZATION_REQUIRED
            - TENANT_SUSPENDED
            - VALIDATION_ERROR
            - INVALID_INPUT
            - MISSING_REQUIRED_FIELD
            - INVALID_FORMAT
            - SYSTEM_VARIABLE_READONLY
            - NOT_FOUND
            - PASS_NOT_FOUND
            - TEMPLATE_NOT_FOUND
            - WEBHOOK_NOT_FOUND
            - NOTIFICATION_NOT_FOUND
            - PASS_NOTIFICATION_NOT_FOUND
            - PASS_NOTIFICATION_BROADCAST_NOT_FOUND
            - CONFLICT
            - VERSION_CONFLICT
            - PRECONDITION_FAILED
            - DUPLICATE_PASS
            - IDEMPOTENCY_CONFLICT
            - SCANNER_SNAPSHOT_STALE
            - TEMPLATE_VERSION_NOT_NEWER
            - WEBHOOK_MANAGED_EXTERNALLY
            - WEBHOOK_SUBSCRIPTION_OWNERSHIP_CONFLICT
            - TEMPLATE_PASS_TYPE_LOCKED
            - PASS_ALREADY_ISSUED
            - PASS_ALREADY_VOIDED
            - PASS_NOT_ISSUED
            - PASS_ISSUING_FAILED
            - PASS_NOTIFICATION_ALREADY_SENT
            - PASS_NOTIFICATION_BROADCAST_ALREADY_DISPATCHED
            - APPLE_SIGNING_FAILED
            - APPLE_APNS_FAILED
            - GOOGLE_API_FAILED
            - GOOGLE_JWT_FAILED
            - PROVIDER_UNAVAILABLE
            - LINK_REVOKED
            - LINK_INVALID
            - TOKEN_SIGNATURE_INVALID
            - TOKEN_CLOCK_SKEW
            - RATE_LIMITED
            - TOO_MANY_REQUESTS
            - PASS_NOTIFICATION_RATE_LIMITED
            - INTERNAL_ERROR
            - SERVICE_UNAVAILABLE
            - JOB_FAILED
          description: Machine-readable error code
          example: UNAUTHORIZED
        message:
          type: string
          description: Human-readable error message
        correlationId:
          type: string
          description: Request correlation ID for debugging
        details:
          description: Additional error details
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        fieldErrors:
          description: >-
            Field-level problems, one entry per offending field, on invalid
            requests
          type: array
          items:
            type: object
            properties:
              field:
                type: string
                description: >-
                  Dot-separated path to the offending field, e.g.
                  `variables.seat` or `passes.0.label`; empty when the problem
                  concerns the request part as a whole
              message:
                type: string
                description: Human-readable description of the problem
              code:
                type: string
                enum:
                  - UNAUTHORIZED
                  - FORBIDDEN
                  - SCANNER_OFFLINE_DISABLED
                  - TOKEN_EXPIRED
                  - TOKEN_INVALID
                  - CSRF_TOKEN_INVALID
                  - TENANT_EXPIRED
                  - TENANT_NOT_FOUND
                  - ORGANIZATION_REQUIRED
                  - TENANT_SUSPENDED
                  - VALIDATION_ERROR
                  - INVALID_INPUT
                  - MISSING_REQUIRED_FIELD
                  - INVALID_FORMAT
                  - SYSTEM_VARIABLE_READONLY
                  - NOT_FOUND
                  - PASS_NOT_FOUND
                  - TEMPLATE_NOT_FOUND
                  - WEBHOOK_NOT_FOUND
                  - NOTIFICATION_NOT_FOUND
                  - PASS_NOTIFICATION_NOT_FOUND
                  - PASS_NOTIFICATION_BROADCAST_NOT_FOUND
                  - CONFLICT
                  - VERSION_CONFLICT
                  - PRECONDITION_FAILED
                  - DUPLICATE_PASS
                  - IDEMPOTENCY_CONFLICT
                  - SCANNER_SNAPSHOT_STALE
                  - TEMPLATE_VERSION_NOT_NEWER
                  - WEBHOOK_MANAGED_EXTERNALLY
                  - WEBHOOK_SUBSCRIPTION_OWNERSHIP_CONFLICT
                  - TEMPLATE_PASS_TYPE_LOCKED
                  - PASS_ALREADY_ISSUED
                  - PASS_ALREADY_VOIDED
                  - PASS_NOT_ISSUED
                  - PASS_ISSUING_FAILED
                  - PASS_NOTIFICATION_ALREADY_SENT
                  - PASS_NOTIFICATION_BROADCAST_ALREADY_DISPATCHED
                  - APPLE_SIGNING_FAILED
                  - APPLE_APNS_FAILED
                  - GOOGLE_API_FAILED
                  - GOOGLE_JWT_FAILED
                  - PROVIDER_UNAVAILABLE
                  - LINK_REVOKED
                  - LINK_INVALID
                  - TOKEN_SIGNATURE_INVALID
                  - TOKEN_CLOCK_SKEW
                  - RATE_LIMITED
                  - TOO_MANY_REQUESTS
                  - PASS_NOTIFICATION_RATE_LIMITED
                  - INTERNAL_ERROR
                  - SERVICE_UNAVAILABLE
                  - JOB_FAILED
                description: Machine-readable reason, e.g. `MISSING_REQUIRED_FIELD`
                example: UNAUTHORIZED
            required:
              - field
              - message
              - code
            additionalProperties: false
      required:
        - errorCode
        - message
        - correlationId
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: plt_<secret>
      description: >-
        Passlet access token (`plt_*`) sent as `Authorization: Bearer <token>`
        or `X-API-Key`. Authorized scopes are listed per operation under
        `x-required-scopes`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.