Skip to main content
PATCH
Error

Authorizations

Authorization
string
header
required

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Headers

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Path Parameters

id
string<uuid>
required

Body

application/json
name
string
Maximum string length: 120
definition
object

A conjunction of groups; within a group, a disjunction of conditions — (A OR B) AND C. Two levels and no more: arbitrary nesting is a precedence question and a form nobody can draw.

What it refuses. A condition this engine cannot state exactly is refused rather than approximated, and two of those refusals are decisions rather than gaps. A custom contact attribute (attributes.tier) has no store behind it — the contact columns are the profile and the first-touch attribution — so matching one would mean matching something else. An entitlement is resolved by the entitlements engine, with overrides that replace rather than maximise, an expiry, a dunning grace, and a status that can honestly answer "cannot tell"; a segment targets the plan instead, which is a row. An activity metric in a test environment is refused too: the meter never records test, so the condition could only ever match nobody.

Example:
archived
boolean

true archives, false restores.

Response

The segment as it now stands.

segment
object

An audience, defined declaratively. Every engagement module takes its recipients from one of these rather than growing a filter of its own.