curl --request PATCH \
--url https://app.thinnest.ai/api/v1/agents/{id}/actions/{actionId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enabled": true
}
'{
"id": "act_9b2f4e17-6c3a-4d81-b5e2-7a0c9d3f1e46",
"agent": "ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34",
"name": "get_appointment",
"description": "Look up a patient's next appointment by their phone number before answering anything about timings.",
"method": "GET",
"url": "https://api.sunrisedental.in/appointments?phone={{phone}}",
"parameters": [
{
"name": "phone",
"description": "The patient's mobile number with country code, e.g. +919876543210",
"required": true
}
],
"bodyTemplate": null,
"headerNames": [
"Authorization"
],
"speakBefore": "One moment, let me check the diary.",
"speakAfter": null,
"enabled": true,
"createdAt": "2026-10-05T09:41:00.210Z",
"updatedAt": "2026-10-05T10:02:44.517Z"
}Update Action
Change any field, or switch it on or off with enabled. The action is validated as it will be saved, so a new url is checked against the parameters already there. Leaving headers out keeps the saved credential; sending any replaces the whole set. enabled: true makes it callable from every conversation at once. A build key may do this.
curl --request PATCH \
--url https://app.thinnest.ai/api/v1/agents/{id}/actions/{actionId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"enabled": true
}
'{
"id": "act_9b2f4e17-6c3a-4d81-b5e2-7a0c9d3f1e46",
"agent": "ag_3f6a9c21-7d4e-4b58-9a1f-0c2e8b7d5a34",
"name": "get_appointment",
"description": "Look up a patient's next appointment by their phone number before answering anything about timings.",
"method": "GET",
"url": "https://api.sunrisedental.in/appointments?phone={{phone}}",
"parameters": [
{
"name": "phone",
"description": "The patient's mobile number with country code, e.g. +919876543210",
"required": true
}
],
"bodyTemplate": null,
"headerNames": [
"Authorization"
],
"speakBefore": "One moment, let me check the diary.",
"speakAfter": null,
"enabled": true,
"createdAt": "2026-10-05T09:41:00.210Z",
"updatedAt": "2026-10-05T10:02:44.517Z"
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Path Parameters
The agent's id (ag_…).
The action's id (act_…).
Body
Any field POST takes, plus enabled. Send at least one. The result is validated as it will be saved: a new url is checked against the parameters already there.
The tool name the agent sees; same rules as on create.
3 - 40When the agent should call it (at least 10 characters).
10An https:// address with {{placeholders}}.
The HTTP method.
GET, POST, PUT, PATCH, DELETE Replaces the whole list.
20Show child attributes
Show child attributes
The JSON body; null removes it.
8000Leave it out (or send {}) to keep the saved headers. Sending any replaces the whole set, so include every header the call needs. There is no way to remove all headers short of deleting the action.
Show child attributes
Show child attributes
What the agent says while your API is called; null clears it.
200What the agent says afterwards; null clears it.
200true puts the action within reach of every conversation the agent has; false takes it away.
Response
The action as saved.
The action's id (act_…).
The agent it belongs to (ag_…).
The tool name the agent sees.
When the agent should call it.
The HTTP method used.
GET, POST, PUT, PATCH, DELETE The https:// address, with {{placeholders}}.
What the agent fills in.
Show child attributes
Show child attributes
The JSON body sent, with quoted placeholders; null for none.
The names of the headers sent. Their values are write-only and never returned.
On calls, what the agent says while your API is being called.
On calls, what the agent says while it turns your answer into a reply.
Whether the agent may call it. A new action is always false.
When it was made.
When it last changed.