Skip to main content
PUT
Update a customer
Updates a customer’s information. All fields are optional — only send what you want to change.
This endpoint takes no organizationId in the URL. Authenticate with either a Supabase Bearer session (send the X-Organization-Id: <org-id> header — the user must be a member of that organization) or an API key (the organization resolves automatically from the key; any X-Organization-Id header sent alongside an API key is ignored).

Authentication

Accepts either:
  • A Supabase Bearer session (Authorization: Bearer <token>) with the X-Organization-Id: <org-id> header — the authenticated user must be a member of that organization.
  • An API key (X-API-Key: sk_...) with the write:customers scope — the organization is resolved from the key itself.

Path Parameters

Request Body

All fields are optional.

Example Request

Example Response

Common Errors

400 Bad Request

Invalid field value (e.g. wrong RFC format or ZIP code), or a missing X-Organization-Id header on a session-authenticated request.

Fiscal validation error (CFDI 4.0)

When taxId, taxSystem, or defaultInvoiceUse are updated, the API re-validates the full taxId + taxSystem + defaultInvoiceUse combination against SAT CFDI 4.0 rules. RFC length determines persona type: 12 characters = persona moral, 13 characters = persona física. The régimen and uso CFDI must both be valid for that persona type, and the (uso, régimen) pair must exist in the SAT compatibility matrix.
Use GET /sat/regimenes-fiscales and GET /sat/usos-cfdi to look up valid codes and compatible combinations.

401 Unauthorized

Missing or invalid Bearer token / API key.

403 Forbidden

The authenticated user is not a member of the organization sent in X-Organization-Id, or the API key does not have the write:customers scope.

404 Not Found

Customer not found.

Authorizations

X-API-Key
string
header
required

API Key for authentication (format: sk_...)

Headers

X-Organization-Id
string

Required for Supabase session auth. Ignored when authenticating with an API key (the organization resolves from the key).

Path Parameters

customerId
string
required

Body

application/json

Customer legal name

Example:

"Dunder Mifflin"

taxId
string

Mexican RFC

Example:

"ABC101010111"

taxSystem
string

SAT tax system code

Example:

"601"

email
string

Customer email

Example:

"email@example.com"

phone
string

Customer phone

Example:

"6474010101"

defaultInvoiceUse
string

Default CFDI use code

Example:

"G01"

addressStreet
string

Street name

addressExterior
string

Exterior number

addressInterior
string

Interior number

addressNeighborhood
string

Neighborhood

addressCity
string

City

addressMunicipality
string

Municipality

addressZip
string

ZIP code

addressState
string

State

addressCountry
string

Country code

Response

id
string
required
Example:

"590ce6c56d04f840aa8438af"

organizationId
string
required
Example:

"org-uuid"

Example:

"Dunder Mifflin"

taxId
string
required
Example:

"ABC101010111"

taxSystem
string
required
Example:

"601"

email
string
required
Example:

"email@example.com"

defaultInvoiceUse
string
required
Example:

"G01"

address
object
required
createdAt
string<date-time>
required
updatedAt
string<date-time>
required
phone
object
Example:

"6474010101"