> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update product document metadata

> Update a document's title / description. Only supplied fields change. To replace the file itself, upload a new document instead. Requires the ``organization.contribute_organization`` permission on the membership.



## OpenAPI

````yaml /openapi/openapi-dashboard.json patch /dashboard/api/v1/trade-items/{organization_id}/{gtin}/documents/{document_id}
openapi: 3.1.0
info:
  title: Brand Dashboard API (Internal)
  version: 1.0.0
  description: >
    Internal endpoints powering the brand dashboard UI. Not intended for
    external integrations — use the Products, Brands, and other public APIs
    instead.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /dashboard/api/v1/trade-items/{organization_id}/{gtin}/documents/{document_id}:
    patch:
      tags:
        - Documents
      summary: Update product document metadata
      description: >-
        Update a document's title / description. Only supplied fields change. To
        replace the file itself, upload a new document instead. Requires the
        ``organization.contribute_organization`` permission on the membership.
      operationId: apps_dashboard_api_documents_update_document
      parameters:
        - in: path
          name: organization_id
          schema:
            description: UUID of the organization that owns the product.
            format: shortuuid
            maxLength: 22
            minLength: 22
            pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
            title: Organization Id
            type: string
          required: true
          description: UUID of the organization that owns the product.
        - in: path
          name: gtin
          schema:
            description: >-
              GTIN-8/12/13/14 of the target product. Normalized to GTIN-14 by
              zero-padding before lookup.
            pattern: ^\d{8,14}$
            title: Gtin
            type: string
          required: true
          description: >-
            GTIN-8/12/13/14 of the target product. Normalized to GTIN-14 by
            zero-padding before lookup.
        - in: path
          name: document_id
          schema:
            description: >-
              UUID (or 22-char shortuuid) of the document row. Must belong to
              the targeted product.
            title: Document Id
            type: string
          required: true
          description: >-
            UUID (or 22-char shortuuid) of the document row. Must belong to the
            targeted product.
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ProductDocumentPatch'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProductDocumentOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - SessionAuth: []
components:
  schemas:
    ProductDocumentPatch:
      description: >-
        Request body for updating a document's metadata. Only supplied fields
        change.


        File replacement is not done here — upload a new document instead. This
        keeps

        the update path a plain JSON body (Django doesn't populate
        ``request.FILES``

        for PATCH multipart without extra middleware).
      examples:
        - description: Updated SDS
          title: Safety Data Sheet (rev 4)
      properties:
        title:
          anyOf:
            - maxLength: 255
              type: string
            - type: 'null'
          description: New caption for the document. Omit to leave unchanged.
          title: Title
        description:
          anyOf:
            - type: string
            - type: 'null'
          description: New description. Omit to leave unchanged.
          title: Description
      title: ProductDocumentPatch
      type: object
    ProductDocumentOut:
      description: A single PDF document attached to a product.
      examples:
        - created: '2025-07-01T14:00:00Z'
          description: SDS revision 3
          display_title: Safety Data Sheet
          file_size_bytes: 210433
          file_url: https://cdn.closient.com/products/00012345678905/sds.pdf
          id: keATfB8VP2gSjcnTbsMNQL
          page_count: 4
          thumbnail_url: https://cdn.closient.com/products/00012345678905/sds-thumb.png
          title: Safety Data Sheet
      properties:
        id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        title:
          description: Caption entered for the document. Empty string when not set.
          examples:
            - Safety Data Sheet
          maxLength: 255
          title: Title
          type: string
        description:
          description: Free-text description of the document. Empty string when not set.
          title: Description
          type: string
        display_title:
          description: >-
            Best available title: the entered ``title``, else the PDF's embedded
            title, else the filename.
          examples:
            - Safety Data Sheet
          title: Display Title
          type: string
        file_url:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Absolute URL of the stored PDF. Null only when the underlying file
            is missing.
          examples:
            - https://cdn.closient.com/products/00012345678905/sds.pdf
          format: uri
          title: File Url
        page_count:
          anyOf:
            - minimum: 0
              type: integer
            - type: 'null'
          description: >-
            Number of pages, extracted asynchronously after upload. Null until
            the PDF-processing task has run.
          title: Page Count
        file_size_bytes:
          anyOf:
            - minimum: 0
              type: integer
            - type: 'null'
          description: Size of the stored file in bytes. Null when not yet computed.
          title: File Size Bytes
        thumbnail_url:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            URL of the first-page thumbnail, generated asynchronously. Empty
            string / null until processing has run.
          format: uri
          title: Thumbnail Url
        created:
          description: ISO-8601 UTC timestamp of when the document was uploaded.
          format: date-time
          title: Created
          type: string
      required:
        - id
        - title
        - description
        - display_title
        - created
      title: ProductDocumentOut
      type: object
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    SessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````