> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.coi.co.il/customers/update-customer/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.coi.co.il/_mcp/server. # Update a customer PATCH https://www.your-store.co.il/api/v1/customers/{id} Content-Type: application/json Details, or `active` to approve / lock. Requires `customers:write`. Reference: https://docs.coi.co.il/customers/update-customer ## Authentication - `Authorization` header (bearer token, required) — An API key from the store's admin: חנות > API ומפתחות. Send it as `Authorization: Bearer coi_sk_...` (or `X-Api-Key: coi_sk_...`). Never in the URL - `?apikey=` is refused with 400. ## Request ### Path parameters - `id` (integer, required) ### Body (application/json) This endpoint expects a CustomerInput. - `email` (string, optional) — Required on create. Unique in the store (409 `email_taken`). - `firstName` (string, optional) - `lastName` (string, optional) - `phone` (string, optional) - `newsletter` (boolean, optional) - `notes` (string, optional, nullable) - `active` (boolean, optional) — Update only. true approves a pending customer (it is emailed that it can log in) or unlocks one; false locks it out at once. ## Response ### 200 The updated customer. - `ok` (true, optional) - `data` (Customer, optional) ## Errors ### 400 Bad Request Error The request is not valid - a field of the wrong type, a missing field, a bad parameter. - `ok` (false, optional) - `error` (ErrorError, optional) ### 401 Unauthorized Error Missing, invalid, revoked or expired API key. The same answer for all of them. - `ok` (false, optional) - `error` (ErrorError, optional) ### 403 Forbidden Error The key lacks the permission (`insufficient_scope`), or the site's plan does not include the API (`plan_required`). - `ok` (false, optional) - `error` (ErrorError, optional) ### 404 Not Found Error No such row in this store (ids of another store are never found). - `ok` (false, optional) - `error` (ErrorError, optional) ### 429 Too Many Requests Error More than 120 requests a minute with one key. Wait `Retry-After` seconds. - `ok` (false, optional) - `error` (ErrorError, optional) ## Types ### Customer - `id` (integer, optional) - `email` (string, optional) - `firstName` (string, optional) - `lastName` (string, optional) - `phone` (string, optional, nullable) - `newsletter` (boolean, optional) - `status` (enum, optional) — `pending` = waiting for the owner's approval ("אשר לקוחות ידנית" is on and it never logged in). - Allowed values: `active`, `pending`, `locked` - `notes` (string, optional, nullable) - `registeredAt` (string, optional, nullable) - `lastVisitAt` (string, optional, nullable) ### ErrorError - `code` (string, optional) — Stable, machine-readable: `unauthorized`, `insufficient_scope`, `plan_required`, `invalid_field`, `invalid_parameter`, `invalid_json`, `json_required`, `not_found`, `method_not_allowed`, `nothing_to_update`, `plan_limit`, `email_taken`, `registration_disabled`, `rate_limited`, `too_many_failures`, `https_required`, `key_in_url`, `server_error`. - `message` (string, optional) — What went wrong, in English, for a person. ## Examples **Request** ```json { "active": true } ``` **Response** ```json { "ok": true, "data": { "id": 49, "email": "israel@example.com", "firstName": "ישראל", "lastName": "ישראלי", "phone": "0501234567", "newsletter": true, "status": "active", "notes": null, "registeredAt": "2026-05-04T20:10:00+03:00", "lastVisitAt": "2026-09-23T17:12:00+03:00" } } ``` **SDK Code** ```python Customers_updateCustomer_example import requests url = "https://www.your-store.co.il/api/v1/customers/1" payload = { "active": True } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.patch(url, json=payload, headers=headers) print(response.json()) ``` ```javascript Customers_updateCustomer_example const url = 'https://www.your-store.co.il/api/v1/customers/1'; const options = { method: 'PATCH', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"active":true}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Customers_updateCustomer_example package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://www.your-store.co.il/api/v1/customers/1" payload := strings.NewReader("{\n \"active\": true\n}") req, _ := http.NewRequest("PATCH", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Customers_updateCustomer_example require 'uri' require 'net/http' url = URI("https://www.your-store.co.il/api/v1/customers/1") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Patch.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"active\": true\n}" response = http.request(request) puts response.read_body ``` ```java Customers_updateCustomer_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.patch("https://www.your-store.co.il/api/v1/customers/1") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"active\": true\n}") .asString(); ``` ```php Customers_updateCustomer_example request('PATCH', 'https://www.your-store.co.il/api/v1/customers/1', [ 'body' => '{ "active": true }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp Customers_updateCustomer_example using RestSharp; var client = new RestClient("https://www.your-store.co.il/api/v1/customers/1"); var request = new RestRequest(Method.PATCH); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"active\": true\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Customers_updateCustomer_example import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = ["active": true] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://www.your-store.co.il/api/v1/customers/1")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PATCH" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```