> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update one retailer product listing

> Correct a single listing's own scalar columns — SKU, active flag, attributes, source reference. Only the fields present in the body are written.

**Badges and per-property URLs are not writable here.** Both are synced as a whole set by `POST /retailers/{retailer_id}/listings`, under invariants that span a join (a badge belongs to its own retailer; a URL attaches to an active storefront of its own retailer). Send the listing through the upsert to change them.

`attributes` replaces the stored dict rather than merging into it, which is what the upsert does with the same field — a merge would make removing a key impossible.

Authorization is identical to creating a listing for this retailer: an organization-private retailer requires OWNER or MANAGER on the organization that owns it; a canonical (Closient-curated) retailer requires a staff account or the catalog-import service account. Whoever may upsert a listing may correct and retire it.



## OpenAPI

````yaml /openapi/openapi-retailers.json patch /retailers/api/v1/retailers/{retailer_id}/listings/{listing_id}
openapi: 3.1.0
info:
  title: Retailers API
  version: 1.0.0
  description: >
    Manage retailers, in-store offers, and online offers.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
tags:
  - name: Retailers
    description: Manage retailers (canonical and org-private).
  - name: In-store Offers
    description: Per-store physical offers (aisle, on-hand quantity, pickup).
  - name: Online Offers
    description: Per-storefront online offers (URL, delivery, fulfillment).
  - name: In-store Offer Promotions
    description: Time-windowed promotional pricing on in-store offers.
  - name: Online Offer Promotions
    description: Time-windowed promotional pricing on online offers.
  - name: Retailer Stores
    description: >-
      Physical storefront upsert, reconciled against existing stores by store
      number, then proximity, then normalised address — a match enriches in
      place rather than creating a near-duplicate.
  - name: Retailer Listings
    description: >-
      Retailer-scoped product listings (SKU, badges, per-property URLs,
      extensible attributes) and the web properties those URLs attach to.
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /retailers/api/v1/retailers/{retailer_id}/listings/{listing_id}:
    patch:
      tags:
        - Retailer Listings
      summary: Update one retailer product listing
      description: >-
        Correct a single listing's own scalar columns — SKU, active flag,
        attributes, source reference. Only the fields present in the body are
        written.


        **Badges and per-property URLs are not writable here.** Both are synced
        as a whole set by `POST /retailers/{retailer_id}/listings`, under
        invariants that span a join (a badge belongs to its own retailer; a URL
        attaches to an active storefront of its own retailer). Send the listing
        through the upsert to change them.


        `attributes` replaces the stored dict rather than merging into it, which
        is what the upsert does with the same field — a merge would make
        removing a key impossible.


        Authorization is identical to creating a listing for this retailer: an
        organization-private retailer requires OWNER or MANAGER on the
        organization that owns it; a canonical (Closient-curated) retailer
        requires a staff account or the catalog-import service account. Whoever
        may upsert a listing may correct and retire it.
      operationId: apps_retailers_api_listing_catalog_update_retailer_listing
      parameters:
        - in: path
          name: retailer_id
          schema:
            description: Unique identifier of the retailer this listing belongs to.
            format: shortuuid
            maxLength: 22
            minLength: 22
            pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
            title: Retailer Id
            type: string
          required: true
          description: Unique identifier of the retailer this listing belongs to.
        - in: path
          name: listing_id
          schema:
            description: Unique identifier of the listing to update.
            format: shortuuid
            maxLength: 22
            minLength: 22
            pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
            title: Listing Id
            type: string
          required: true
          description: Unique identifier of the listing to update.
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ListingUpdateIn'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListingOut'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '401':
          description: Unauthorized
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '403':
          description: Forbidden
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '422':
          description: Unprocessable Content
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
      security:
        - APIKeyHeaderAuth: []
        - OAuthTokenAuth: []
        - CookieGatedSessionAuth: []
components:
  schemas:
    ListingUpdateIn:
      additionalProperties: false
      description: |-
        Fields a ``PATCH`` may change on an existing listing.

        Every field is optional; only the ones present in the request body are
        written. ``badges`` and ``urls`` are deliberately absent — see this
        module's docstring.
      examples:
        - is_active: true
          sku: SEPH-2311456
      properties:
        sku:
          default: ''
          description: The retailer's internal SKU for this product.
          maxLength: 100
          title: Sku
          type: string
        is_active:
          default: false
          description: >-
            Set false to drop the product from the catalog (the same effect as
            `DELETE`), true to re-list it.
          title: Is Active
          type: boolean
        attributes:
          additionalProperties:
            anyOf:
              - type: string
              - type: integer
              - type: number
              - type: boolean
              - items:
                  anyOf:
                    - type: string
                    - type: integer
                    - type: number
                    - type: boolean
                    - type: 'null'
                type: array
              - type: 'null'
          description: >-
            Retailer-scoped facts with no typed column yet. **Replaces** the
            stored dict rather than merging into it, so a key can be removed.
            Bounded: at most 200 keys and 8000 characters per value — the same
            bounds the import boundary applies, because the column has no
            database-level shape and this would otherwise be the one path that
            can turn a staging area into a document store.
          title: Attributes
          type: object
        source_reference:
          default: ''
          description: The retailer's own product identifier in the source feed.
          maxLength: 255
          title: Source Reference
          type: string
      title: ListingUpdateIn
      type: object
    ListingOut:
      description: One retailer product listing as the catalog holds it.
      examples:
        - attributes:
            categoryIds:
              - cat130042
            sephoraDescription: A lightweight serum.
          badges:
            - is_active: true
              label: Clean at Sephora
              slug: clean-at-sephora
          created: '2026-01-15T10:00:00Z'
          gtin: '00812345678901'
          id: b2c3d4e5f60718293a4b5c6d7e
          is_active: true
          modified: '2026-02-01T09:30:00Z'
          product_id: 9a8b7c6d5e4f30211a2b3c4d5e
          retailer_id: f47ac10b58cc4372a5670e02b2
          sku: SEPH-2311456
          source_reference: P442501
          urls:
            - is_active: true
              store_url: https://www.sephora.ca
              storefront_id: c3d4e5f6789012345abcdef012
              url: https://www.sephora.ca/product/P442501
      properties:
        id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Id
          type: string
        retailer_id:
          description: >-
            URL-safe 22-character shortuuid encoding of the row's UUID primary
            key. Stable across the row's lifetime; suitable for sharing in URLs,
            log lines, and external SDK clients. Accepted on input as either the
            shortuuid form or the canonical UUID form
            (``xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx``).
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Retailer Id
          type: string
        product_id:
          description: Identifier of the shared product this listing points at.
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Product Id
          type: string
        gtin:
          description: >-
            GTIN of the listed product. The key the listing upsert accepts,
            echoed here so a caller can reconcile this row against its own feed
            without a second lookup.
          title: Gtin
          type: string
        sku:
          description: >-
            The retailer's own SKU for this product across its whole catalog.
            Distinct from an offer's SKU, which is the SKU at one specific store
            or storefront.
          title: Sku
          type: string
        is_active:
          description: >-
            False once the retailer drops the product from its catalog. `DELETE`
            clears this flag rather than removing the row.
          title: Is Active
          type: boolean
        attributes:
          additionalProperties: true
          description: >-
            Retailer-scoped facts that have no typed column yet — a staging
            area, not a permanent home. A key that proves useful is promoted to
            a real column.
          title: Attributes
          type: object
        source_reference:
          default: ''
          description: >-
            The retailer's own product identifier in the source feed (e.g. a
            Sephora productId).
          title: Source Reference
          type: string
        badges:
          description: >-
            Designations this retailer applies to this product. Change them
            through `POST /retailers/{retailer_id}/listings`, which syncs the
            whole set.
          items:
            $ref: '#/components/schemas/ListingBadgeOut'
          title: Badges
          type: array
        urls:
          description: >-
            One product URL per retailer web property. Change them through `POST
            /retailers/{retailer_id}/listings`, which syncs the whole set.
          items:
            $ref: '#/components/schemas/ListingURLOut'
          title: Urls
          type: array
        created:
          description: When this listing row was first written.
          format: date-time
          title: Created
          type: string
        modified:
          description: When this listing row last changed.
          format: date-time
          title: Modified
          type: string
      required:
        - id
        - retailer_id
        - product_id
        - gtin
        - sku
        - is_active
        - created
        - modified
      title: ListingOut
      type: object
    ErrorOut:
      description: |-
        RFC 9457 Problem Details response.

        All API errors are returned in this format with Content-Type:
        application/problem+json.
      examples:
        - detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          status: 404
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Not Found
          type: https://closient.com/docs/errors/not_found
        - detail: Validation error.
          details:
            - loc:
                - body
                - name
              msg: Field required
              type: missing
          error_code: validation_error
          retryable: false
          status: 422
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Validation Error
          type: https://closient.com/docs/errors/validation_error
        - detail: Rate limit exceeded. Please try again later.
          error_code: rate_limited
          retry_after: 31
          retryable: true
          status: 429
          timestamp: '2026-03-31T12:00:00+00:00'
          title: Rate Limited
          type: https://closient.com/docs/errors/rate_limited
      properties:
        type:
          description: URI reference identifying the error type.
          title: Type
          type: string
        title:
          description: Short human-readable summary of the error.
          title: Title
          type: string
        status:
          description: HTTP status code.
          title: Status
          type: integer
        detail:
          description: Human-readable explanation of this specific occurrence.
          title: Detail
          type: string
        error_code:
          description: Machine-readable error code (e.g. not_found, unauthorized).
          title: Error Code
          type: string
        retryable:
          default: false
          description: Whether retrying the same request can succeed.
          title: Retryable
          type: boolean
        timestamp:
          description: ISO 8601 timestamp of when the error occurred.
          title: Timestamp
          type: string
        retry_after:
          anyOf:
            - type: integer
            - type: 'null'
          description: Seconds to wait before retrying (when applicable).
          title: Retry After
        owner_action_required:
          anyOf:
            - type: boolean
            - type: 'null'
          description: Whether the error requires account owner intervention.
          title: Owner Action Required
        details:
          description: Additional context (validation errors, etc.).
          title: Details
      required:
        - type
        - title
        - status
        - detail
        - error_code
        - timestamp
      title: ErrorOut
      type: object
    ListingBadgeOut:
      description: >-
        One designation this retailer applies to this product.


        A badge is the *retailer's* editorial opinion, never a fact about the

        product and never a certification — which is why it is published
        attached

        to the listing rather than to the product.
      examples:
        - is_active: true
          label: Clean at Sephora
          slug: clean-at-sephora
      properties:
        slug:
          description: Stable per-retailer key for the badge.
          title: Slug
          type: string
        label:
          description: Badge text as the retailer words it.
          title: Label
          type: string
        is_active:
          description: False once the retailer stops applying this badge.
          title: Is Active
          type: boolean
      required:
        - slug
        - label
        - is_active
      title: ListingBadgeOut
      type: object
    ListingURLOut:
      description: This listing's product URL on one of the retailer's web properties.
      examples:
        - is_active: true
          store_url: https://www.sephora.ca
          storefront_id: c3d4e5f6789012345abcdef012
          url: https://www.sephora.ca/product/P442501
      properties:
        storefront_id:
          description: Identifier of the storefront this URL lives on.
          format: shortuuid
          maxLength: 22
          minLength: 22
          pattern: ^[23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz]{22}$
          title: Storefront Id
          type: string
        store_url:
          description: Root URL of that storefront — the value the upsert keys on.
          title: Store Url
          type: string
        url:
          description: Product page on that storefront.
          title: Url
          type: string
        is_active:
          description: >-
            False when a later feed stopped listing this property, rather than
            the row being deleted.
          title: Is Active
          type: boolean
      required:
        - storefront_id
        - store_url
        - url
        - is_active
      title: ListingURLOut
      type: object
  securitySchemes:
    APIKeyHeaderAuth:
      type: apiKey
      in: header
      name: X-API-Key
    OAuthTokenAuth:
      type: http
      scheme: bearer
    CookieGatedSessionAuth:
      type: apiKey
      in: cookie
      name: sessionid

````