curl --request PATCH \
--url https://api.gigstack.io/v2/documents/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"complianceStatus": "valid",
"complianceNotes": "Revisado por el área fiscal, cumple con el requisito de materialidad.",
"tags": [
"contrato",
"acme",
"revisado"
]
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
complianceStatus: 'valid',
complianceNotes: 'Revisado por el área fiscal, cumple con el requisito de materialidad.',
tags: ['contrato', 'acme', 'revisado']
})
};
fetch('https://api.gigstack.io/v2/documents/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/documents/{id}"
payload = {
"complianceStatus": "valid",
"complianceNotes": "Revisado por el área fiscal, cumple con el requisito de materialidad.",
"tags": ["contrato", "acme", "revisado"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"success": true,
"data": {
"id": "doc_1234567890",
"document_type": "contract",
"name": "Contrato de servicios 2026 — Cliente ACME",
"description": "Contrato marco de prestación de servicios",
"file_url": "https://firebasestorage.googleapis.com/v0/b/gigstackpro.appspot.com/o/teams%2Fteam_123%2Fdocuments%2Fcontrato-acme.pdf?alt=media&token=9f1c7d84-3b2e-4a56-8c0d-1e7f5b9a2c43",
"file_name": "contrato-acme.pdf",
"file_size": 284913,
"mime_type": "application/pdf",
"linked_entities": [
{
"entity_type": "client",
"entity_id": "client_1234567890",
"linked_at": 1767225600000
}
],
"compliance_status": "valid",
"compliance_notes": "Revisado por el área fiscal, cumple con el requisito de materialidad.",
"valid_from": 1767225600000,
"valid_until": 1798761600000,
"ai_extraction": null,
"tags": [
"contrato",
"acme"
],
"metadata": null,
"created_at": 1767225600000,
"created_by": "user_1234567890",
"updated_at": 1767312000000,
"livemode": true
},
"message": "Document updated successfully",
"timestamp": 1767225600000
}Update document
Availability: This operation has no configured public API gateway route and is not available through the documented base URL.
Update a document’s metadata and compliance review state. Only fields explicitly present in the body are written; omitted fields are left untouched.
The file itself (fileUrl, storagePath, fileName, documentType) is immutable —
those keys are not part of the update schema and are rejected as unknown.
curl --request PATCH \
--url https://api.gigstack.io/v2/documents/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"complianceStatus": "valid",
"complianceNotes": "Revisado por el área fiscal, cumple con el requisito de materialidad.",
"tags": [
"contrato",
"acme",
"revisado"
]
}
'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
complianceStatus: 'valid',
complianceNotes: 'Revisado por el área fiscal, cumple con el requisito de materialidad.',
tags: ['contrato', 'acme', 'revisado']
})
};
fetch('https://api.gigstack.io/v2/documents/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/documents/{id}"
payload = {
"complianceStatus": "valid",
"complianceNotes": "Revisado por el área fiscal, cumple con el requisito de materialidad.",
"tags": ["contrato", "acme", "revisado"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"success": true,
"data": {
"id": "doc_1234567890",
"document_type": "contract",
"name": "Contrato de servicios 2026 — Cliente ACME",
"description": "Contrato marco de prestación de servicios",
"file_url": "https://firebasestorage.googleapis.com/v0/b/gigstackpro.appspot.com/o/teams%2Fteam_123%2Fdocuments%2Fcontrato-acme.pdf?alt=media&token=9f1c7d84-3b2e-4a56-8c0d-1e7f5b9a2c43",
"file_name": "contrato-acme.pdf",
"file_size": 284913,
"mime_type": "application/pdf",
"linked_entities": [
{
"entity_type": "client",
"entity_id": "client_1234567890",
"linked_at": 1767225600000
}
],
"compliance_status": "valid",
"compliance_notes": "Revisado por el área fiscal, cumple con el requisito de materialidad.",
"valid_from": 1767225600000,
"valid_until": 1798761600000,
"ai_extraction": null,
"tags": [
"contrato",
"acme"
],
"metadata": null,
"created_at": 1767225600000,
"created_by": "user_1234567890",
"updated_at": 1767312000000,
"livemode": true
},
"message": "Document updated successfully",
"timestamp": 1767225600000
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Path Parameters
Document id.
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789
Body
Partial update. Every field is optional and only the keys present in the body are
written. The file itself (documentType, fileUrl, storagePath, fileName) is
immutable and those keys are rejected as unknown.
"Contrato de servicios 2026 — Cliente ACME (v2)"
Compliance review state. Always pending_review when a document is created; change it
with PATCH /v2/documents/{id}.
pending_review, valid, requires_update, expired, rejected "pending_review"
"Revisado por el área fiscal."
1767225600000
1798761600000
["contrato", "revisado"]
Response
Document updated.
Standardized success envelope emitted by sendSuccessResponse.
true true
A document as returned by the documents endpoints (snake_case).
Show child attributes
Show child attributes
Server time in epoch milliseconds (Luxon.now().toMillis()).
1767225600000
Human-readable summary. Present only when the handler supplies one.
"Operation completed successfully"