Skip to main content
Update Notification Preferences
Upserts the acting user’s push notification preferences. The request replaces the whole disabled-types set — send the complete set you want stored, not a delta. Duplicates are collapsed; only valid event type names are accepted. Requires authentication. Acting-user-scoped: an end-user token (Authorization: Bearer <accessToken>) writes its own preferences. A service/master key acts on behalf of a named user via the optional body userId — a service key without userId is rejected, and an end-user token may not name a different user. Requires the push bundle.

Body Parameters

string[]
required
The complete set of event types to disable for push. Each value must be one of the server’s exact event type names (see the event palette) — unknown names are rejected. Pass [] to re-enable everything (all-on).
string
The acting user whose preferences are written. Service/master keys only — a service key must pass it; an end-user token infers it from the auth token and may not name a different user.

Response

Returns 200 with the stored set (deduplicated).

Error Responses

Plain-text Unauthorized, with no JSON body and no code. Returned when the request carries no Authorization header at all.
Plain-text Forbidden, with no JSON body and no code. Returned when the access token is malformed, has the wrong signature, or has expired — the common case, since access tokens live 30 minutes. Refresh the access token and retry.
Returned when an end-user token names a userId other than its own.
Returned when a service/master key omits the required userId (it has no implicit session user).
Returned when disabledTypes contains a value that is not a recognized event type name.
Returned when the push bundle is not installed for this project.
Returned while the push bundle is mid-install. Retry shortly.
Rate limit: 50 requests per 5 minutes per IP. Exceeding it returns 429 with a plain-text message and no code.

See Also