Update Workflow
PUT/api/automation/workflows/:workflow
Update a workflow's name, description, category, graph, or settings. When nodes are submitted, the trigger type and trigger configuration are re-derived from the graph.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Body fields (all optional): name (string, max 128), description, category (string, max 50), nodes (array - each node requires id (string, max 64), type (string, max 100), position.x/position.y (numeric), data (object, required per node), optional label), edges (array - each edge requires id, source, target; optional sourceHandle, targetHandle, label, branchLabel), viewport, settings, preview_mode (boolean).
Path param: workflow = workflow id.
Preview mode: preview_mode (optional, boolean, default false). While a workflow is in preview mode every run — triggered, manual, or replayed — executes triggers, conditions, and lookups for real but skips every step that would change something (all Action and Integration nodes: emails, Slack messages, webhooks, spreadsheet writes, order updates). Skipped steps are recorded in the execution with the input they would have used, so a preview run reads exactly like a real one. Read-only actions are exempt and still run.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Validation failed — the body is a field → messages map (Laravel shape) or the platform envelope with a stable machine-readable code. Fix the payload and resubmit.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.