> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Update external API call
> Update one external API call step.
Updates one external API call record. The wire-format object is still called [`Data Step`](/en/api-reference/actions-and-attributes#data-step-object). All fields are optional; send only what you want to change.
<Note>
Sensitive header and body values are preserved when you echo the masked `"********"` back. Send a new string to replace a secret. See [Sensitive values and masking](/en/api-reference/actions-and-attributes#sensitive-values-and-masking).
</Note>
## Headers
<ParamField header="Authorization" type="string" required>
Bearer token containing your Fini workspace API key. Format: `Bearer fini_...` The key needs `write` scope.
</ParamField>
<ParamField header="Content-Type" type="string" required>
`application/json`
</ParamField>
## Path parameters
<ParamField path="id" type="string" required>
External API call step ID to update.
</ParamField>
## Body parameters
<ParamField body="name" type="string">
Updated step name.
</ParamField>
<ParamField body="requestUrl" type="string">
Updated request URL. Supports `${fieldName}` interpolation from inputs and `${stepId.responseMappingKey}` interpolation from earlier external API calls. `{{placeholder}}` syntax is not supported.
</ParamField>
<ParamField body="requestMethod" type="string">
Updated HTTP verb.
</ParamField>
<ParamField body="requestHeaders" type="object">
Updated request headers. Echo the masked value back to keep a stored secret.
</ParamField>
<ParamField body="requestBody" type="object">
Updated request body, with the same masking behavior as headers.
</ParamField>
<ParamField body="responseMapping" type="ResponseMapping">
Updated output mapping. See [ResponseMapping](/en/api-reference/actions-and-attributes#responsemapping-object).
</ParamField>
## Response
Returns the updated [`Data Step`](/en/api-reference/actions-and-attributes#data-step-object) with sensitive values masked.
<RequestExample>
~~~bash cURL theme={null}
curl --request PATCH \
--url 'https://api-prod.usefini.com/v2/api-function-configs/4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3/public' \
--header 'Authorization: Bearer fini_your_api_key' \
--header 'Content-Type: application/json' \
--data '{
"name": "Refund policy",
"requestUrl": "https://help.example.com/refunds",
"requestMethod": "GET",
"requestHeaders": {
"name": "Example",
"value": "message"
},
"requestBody": {
"name": "Example",
"value": "message"
},
"responseMapping": "4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3"
}'
~~~
~~~javascript Node.js theme={null}
const response = await fetch('https://api-prod.usefini.com/v2/api-function-configs/4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3/public', {
method: 'PATCH',
headers: {
Authorization: 'Bearer fini_your_api_key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
'name': 'Refund policy',
'requestUrl': 'https://help.example.com/refunds',
'requestMethod': 'GET',
'requestHeaders': {
'name': 'Example',
'value': 'message'
},
'requestBody': {
'name': 'Example',
'value': 'message'
},
'responseMapping': '4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3'
}
)
});
const data = await response.json();
~~~
~~~python Python theme={null}
import requests
response = requests.patch(
"https://api-prod.usefini.com/v2/api-function-configs/4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3/public",
headers={"Authorization": "Bearer fini_your_api_key", "Content-Type": "application/json"},
json={
"name": "Refund policy",
"requestUrl": "https://help.example.com/refunds",
"requestMethod": "GET",
"requestHeaders": {
"name": "Example",
"value": "message"
},
"requestBody": {
"name": "Example",
"value": "message"
},
"responseMapping": "4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3"
},
)
data = response.json()
~~~
</RequestExample>
<ResponseExample>
~~~json 200 OK theme={null}
{
"id": "4f5ef695-d03b-4d56-8fef-7f2bd5c17ef3",
"name": "Lookup customer",
"method": "GET",
"url": "https://api.example.com/customers/{customerId}",
"headers": {
"Authorization": "Bearer ${apiToken}"
},
"saveFromResponse": {
"plan": "customer.plan",
"status": "customer.status"
},
"createdAt": "2026-07-28T08:55:32.000Z",
"updatedAt": "2026-07-28T09:10:18.000Z"
}
~~~
</ResponseExample>
## Errors
<AccordionGroup>
<Accordion title="400 Bad Request" icon="circle-exclamation">
The body is malformed.
</Accordion>
<Accordion title="401 Unauthorized" icon="lock">
The API key is missing, malformed, revoked, or invalid.
</Accordion>
<Accordion title="403 Forbidden" icon="shield-halved">
The API key does not include the `write` scope required for this route.
</Accordion>
<Accordion title="500 Internal Server Error" icon="triangle-exclamation">
Fini failed while updating the Data Step, for example when the ID does not exist.
</Accordion>
</AccordionGroup>
## Related topics
- [Overview](/en/api-reference/actions-and-attributes.md)
- [Test external API call](/en/api-reference/test-data-step.md)
- [Get external API call](/en/api-reference/get-data-step.md)
This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.
External API calls

