curl --request PATCH \
--url https://app.thinnest.ai/api/v1/codes/templates/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expiryMinutes": 5
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({expiryMinutes: 5})
};
fetch('https://app.thinnest.ai/api/v1/codes/templates/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/codes/templates/{id}"
payload = { "expiryMinutes": 5 }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "5e1d8c3b-7a2f-4d96-b4e0-9c6a2f1d8e73",
"name": "login_code",
"language": "en",
"status": "draft",
"reviewNote": null,
"settings": {
"expiryMinutes": 5,
"securityRecommendation": true,
"button": "copy_code",
"apps": []
},
"preview": {
"body": "*123456* is your verification code. For your security, do not share this code.",
"footer": "Expires in 5 minutes."
},
"agent": "ag_2c7e9a14-5b3d-4f8e-a1c6-7d9b0e3f5a21",
"createdAt": "2026-10-06T10:02:17.904Z"
}{
"error": "One-tap needs your Android app's package name and signing hash."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "One-time codes need a plan with WhatsApp. Pay as you go has no monthly fee."
}{
"error": "That template was not found."
}{
"error": "That template has already been sent for review, so it can no longer be edited."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Update Code Template
Changes any of a draft’s fields; the ones you leave out keep their values. Once a template has been submitted, WhatsApp has the text and it can no longer be edited — make a new one instead. A build key may do this.
curl --request PATCH \
--url https://app.thinnest.ai/api/v1/codes/templates/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expiryMinutes": 5
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({expiryMinutes: 5})
};
fetch('https://app.thinnest.ai/api/v1/codes/templates/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/codes/templates/{id}"
payload = { "expiryMinutes": 5 }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"id": "5e1d8c3b-7a2f-4d96-b4e0-9c6a2f1d8e73",
"name": "login_code",
"language": "en",
"status": "draft",
"reviewNote": null,
"settings": {
"expiryMinutes": 5,
"securityRecommendation": true,
"button": "copy_code",
"apps": []
},
"preview": {
"body": "*123456* is your verification code. For your security, do not share this code.",
"footer": "Expires in 5 minutes."
},
"agent": "ag_2c7e9a14-5b3d-4f8e-a1c6-7d9b0e3f5a21",
"createdAt": "2026-10-06T10:02:17.904Z"
}{
"error": "One-tap needs your Android app's package name and signing hash."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "One-time codes need a plan with WhatsApp. Pay as you go has no monthly fee."
}{
"error": "That template was not found."
}{
"error": "That template has already been sent for review, so it can no longer be edited."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Path Parameters
The template's id — a bare uuid, as the list gives it.
Body
Any subset of the create fields. Fields left out keep their values.
Lowercase letters, digits and underscores.
512^[a-z0-9_]{1,512}$A WhatsApp template language code.
en, hi, mr, bn, ta, te, kn, ml, gu, pa, ur, ar, es, pt_BR, fr, de, it, nl, ru, tr, id, ms, th, vi, fil, ja, ko, zh_CN, zh_TW, he, sw, en_GB, en_US How long the code lasts.
1 <= x <= 90Adds "For your security, do not share this code."
How the code gets into your app.
copy_code, one_tap The Android apps a one_tap code is handed to. Replaces the list.
Show child attributes
Show child attributes
Response
The draft as saved.
The template's id (a bare uuid).
The template's name — what template on Send One-Time Code takes.
Its language code.
draft: yours to change. pending: with WhatsApp for review. approved: sends. rejected: see reviewNote. paused: WhatsApp paused it.
draft, pending, approved, rejected, paused WhatsApp's reason, when it gave one.
The three choices. Null only for a template saved before these settings existed.
Show child attributes
Show child attributes
What the customer reads, in WhatsApp's words, with a sample code.
Show child attributes
Show child attributes
The agent the template belongs to (ag_…).
When it was created.