> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kintra.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Lock or unlock a customer XP balance

> Locks or unlocks one customer's XP balance through the Portal API.

See the [Gateway API entry](/api-reference/gateway/customers/lock-or-unlock-a-customer-xp-balance) for the full description.



## OpenAPI

````yaml /openapi/kintra-app.json put /tenant/{tenantId}/customers/{userId}/xp/lock
openapi: 3.0.0
info:
  description: >-
    Tenant portal API for the Kintra loyalty platform. Requests are
    authenticated with an Auth0 bearer token and address a tenant by id in the
    path.
  title: Kintra Portal API
  version: 1.0.0
servers:
  - description: Production environment
    url: https://api.kintra.io/api/v1
security: []
paths:
  /tenant/{tenantId}/customers/{userId}/xp/lock:
    put:
      tags:
        - Customers
      summary: Lock or unlock a customer XP balance
      description: >-
        Locks or unlocks one customer's XP balance through the Portal API.


        See the [Gateway API
        entry](/api-reference/gateway/customers/lock-or-unlock-a-customer-xp-balance)
        for the full description.
      operationId: LockXp
      parameters:
        - in: path
          name: tenantId
          required: true
          schema:
            type: string
        - in: path
          name: userId
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ILockXpDto'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse__success-boolean__'
          description: ''
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_null_'
          description: Unauthorized
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_null_'
          description: Tenant not found
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_null_'
          description: Internal server error
      security:
        - auth0_jwt: []
components:
  schemas:
    ILockXpDto:
      additionalProperties: false
      properties:
        status:
          $ref: '#/components/schemas/XpStatus'
      required:
        - status
      type: object
    ApiResponse__success-boolean__:
      additionalProperties: false
      properties:
        data:
          properties:
            success:
              type: boolean
          required:
            - success
          type: object
        errors:
          items:
            properties:
              message:
                type: string
              path:
                type: string
            required:
              - path
              - message
            type: object
          type: array
        message:
          type: string
        success:
          type: boolean
      required:
        - success
      type: object
    ApiResponse_null_:
      additionalProperties: false
      properties:
        data:
          enum:
            - null
          nullable: true
          type: number
        errors:
          items:
            properties:
              message:
                type: string
              path:
                type: string
            required:
              - path
              - message
            type: object
          type: array
        message:
          type: string
        success:
          type: boolean
      required:
        - success
      type: object
    XpStatus:
      enum:
        - active
        - locked
      type: string
  securitySchemes:
    auth0_jwt:
      bearerFormat: JWT
      description: Auth0 access token
      scheme: bearer
      type: http

````