> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kintra.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a reward

> Updates a reward in place. Every field is optional: send `title`, `description`, `xp_cost`, `is_active`, `metadata`, `min_tier_id` or `status`, and leave out what you are not changing. This is the route that moves a reward from `initialized` to `published`, and the route that flips `is_active`. Publishing is a one-way move: once a reward is `published`, `is_active` is the only field still mutable and it has to be the only field in the body, so an update that carries anything else returns 400 `REWARD_PUBLISHED`. The response `data` carries `success`. Returns 404 when no reward with that id belongs to your tenant. `X-Idempotency-Key` is required: a missing key returns 400 `IDEMPOTENCY_KEY_REQUIRED`, and a replay returns the stored response. Reusing a key with a different request returns 422 `IDEMPOTENCY_KEY_CONFLICT`, and replaying a key whose first request is still in flight returns 409 with the same code. A first request that never recorded a response keeps returning 409 until the key ages out, so send a fresh key rather than retrying that one.



## OpenAPI

````yaml /openapi/kintra-gateway.json put /gateway/rewards/{rewardId}
openapi: 3.0.0
info:
  description: >-
    Server-to-server API for the Kintra loyalty platform. Requests are
    authenticated with a tenant API key and a request signature; the tenant
    comes from the key.
  title: Kintra Gateway API
  version: 1.0.0
servers:
  - description: Production environment
    url: https://api.kintra.io/api/v1
security: []
paths:
  /gateway/rewards/{rewardId}:
    put:
      tags:
        - Rewards
      summary: Update a reward
      description: >-
        Updates a reward in place. Every field is optional: send `title`,
        `description`, `xp_cost`, `is_active`, `metadata`, `min_tier_id` or
        `status`, and leave out what you are not changing. This is the route
        that moves a reward from `initialized` to `published`, and the route
        that flips `is_active`. Publishing is a one-way move: once a reward is
        `published`, `is_active` is the only field still mutable and it has to
        be the only field in the body, so an update that carries anything else
        returns 400 `REWARD_PUBLISHED`. The response `data` carries `success`.
        Returns 404 when no reward with that id belongs to your tenant.
        `X-Idempotency-Key` is required: a missing key returns 400
        `IDEMPOTENCY_KEY_REQUIRED`, and a replay returns the stored response.
        Reusing a key with a different request returns 422
        `IDEMPOTENCY_KEY_CONFLICT`, and replaying a key whose first request is
        still in flight returns 409 with the same code. A first request that
        never recorded a response keeps returning 409 until the key ages out, so
        send a fresh key rather than retrying that one.
      operationId: UpdateReward
      parameters:
        - in: path
          name: rewardId
          required: true
          schema:
            type: string
        - description: >-
            Hex HMAC-SHA256 of the timestamp, the uppercase method, the url as
            sent and the request body, keyed by the signing secret.
          in: header
          name: X-Tenant-Signature
          required: true
          schema:
            type: string
        - description: Unix seconds. Checked before the signature.
          in: header
          name: X-Tenant-Timestamp
          required: true
          schema:
            type: string
        - description: >-
            Unique key for this write. A replay returns the stored response; the
            same key with a different body conflicts.
          in: header
          name: X-Idempotency-Key
          required: true
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IRewardUpdateDto'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse__success-boolean__'
          description: ''
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_null_'
          description: Unauthorized
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_null_'
          description: Tenant not found
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_null_'
          description: Internal server error
      security:
        - tenant_api_key: []
      x-codeSamples:
        - label: cURL
          lang: bash
          source: >
            # Export KINTRA_API for your environment first; the base URL is on
            the introduction page.

            KEY="YOUR_TENANT_KEY_ID"

            SECRET="YOUR_SIGNING_SECRET"


            # The signature covers the path and query exactly as sent, so both
            are split

            # off the base URL and reused for the request line below.

            API_PATH="/${KINTRA_API#*://*/}"

            API_HOST="${KINTRA_API%"$API_PATH"}"

            METHOD="PUT"

            PATH_AND_QUERY="$API_PATH/gateway/rewards/YOUR_REWARD_ID"


            # One compact line, signed and sent unchanged. The server signs a

            # re-serialization of the body it parsed, so reformatting this fails
            with a 401.

            BODY='{"title":"YOUR_TITLE","description":"YOUR_DESCRIPTION","xp_cost":0,"is_active":false,"metadata":{},"status":"initialized","min_tier_id":"YOUR_MIN_TIER_ID"}'


            TIMESTAMP="$(date +%s)"

            SIGNATURE="$(printf '%s' "$TIMESTAMP$METHOD$PATH_AND_QUERY$BODY" \
              | openssl dgst -sha256 -hmac "$SECRET" | awk '{print $NF}')"

            curl -sS -w '\n%{http_code}' -X "$METHOD" "$API_HOST$PATH_AND_QUERY"
            \
              -H "X-Tenant-Key: $KEY" \
              -H "X-Tenant-Timestamp: $TIMESTAMP" \
              -H "X-Tenant-Signature: $SIGNATURE" \
              -H "Content-Type: application/json" \
              -H "X-Idempotency-Key: YOUR_IDEMPOTENCY_KEY" \
              --data-binary "$BODY"
        - label: TypeScript
          lang: typescript
          source: >
            import { createHmac } from 'node:crypto'


            // Export KINTRA_API for your environment first; the base URL is on
            the introduction page.

            const { origin, pathname } = new URL(process.env.KINTRA_API ?? '')

            const key = 'YOUR_TENANT_KEY_ID'

            const secret = 'YOUR_SIGNING_SECRET'


            const method = 'PUT'

            // The signature covers the path and query as sent, starting at the
            API prefix.

            const pathAndQuery = `${pathname}/gateway/rewards/YOUR_REWARD_ID`


            // Serialized once and used twice. The server signs a
            re-serialization of the

            // body it parsed, so the bytes signed and the bytes sent have to be
            identical.

            const body = JSON.stringify({
              "title": "YOUR_TITLE",
              "description": "YOUR_DESCRIPTION",
              "xp_cost": 0,
              "is_active": false,
              "metadata": {},
              "status": "initialized",
              "min_tier_id": "YOUR_MIN_TIER_ID"
            })


            const timestamp = Math.floor(Date.now() / 1000).toString()

            const signature = createHmac('sha256',
            secret).update(`${timestamp}${method}${pathAndQuery}${body}`).digest('hex')


            const response = await fetch(`${origin}${pathAndQuery}`, {
              method,
              headers: {
                'X-Tenant-Key': key,
                'X-Tenant-Timestamp': timestamp,
                'X-Tenant-Signature': signature,
                'Content-Type': 'application/json',
                'X-Idempotency-Key': 'YOUR_IDEMPOTENCY_KEY'
              },
              body
            })


            console.log(response.status, await response.json())
components:
  schemas:
    IRewardUpdateDto:
      additionalProperties: false
      properties:
        description:
          type: string
        is_active:
          description: >-
            Visibility/redeemability flag. This is the only reward field mutable
            after publish.
          type: boolean
        metadata:
          $ref: '#/components/schemas/Record_string.unknown_'
          description: >-
            Freeform reward metadata (full-replace of the jsonb on update). May
            carry a tenant-scoped

            `image_key`; any client-supplied `image_url` is rejected — the URL
            is derived on read.
        min_tier_id:
          description: >-
            Tier gate — UUID of the minimum tier, or `''`/`null` to clear (all
            tiers).
          nullable: true
          type: string
        status:
          $ref: '#/components/schemas/RewardStatus'
        title:
          type: string
        xp_cost:
          format: double
          type: number
      type: object
    ApiResponse__success-boolean__:
      additionalProperties: false
      properties:
        data:
          properties:
            success:
              type: boolean
          required:
            - success
          type: object
        errors:
          items:
            properties:
              message:
                type: string
              path:
                type: string
            required:
              - path
              - message
            type: object
          type: array
        message:
          type: string
        success:
          type: boolean
      required:
        - success
      type: object
    ApiResponse_null_:
      additionalProperties: false
      properties:
        data:
          enum:
            - null
          nullable: true
          type: number
        errors:
          items:
            properties:
              message:
                type: string
              path:
                type: string
            required:
              - path
              - message
            type: object
          type: array
        message:
          type: string
        success:
          type: boolean
      required:
        - success
      type: object
    Record_string.unknown_:
      additionalProperties: {}
      description: Construct a type with a set of properties K of type T
      properties: {}
      type: object
    RewardStatus:
      enum:
        - initialized
        - published
      type: string
  securitySchemes:
    tenant_api_key:
      description: Tenant API key
      in: header
      name: x-tenant-key
      type: apiKey

````