# Change a list

`PATCH /api/v1/ip/lists/{listId}`

- Authentication: Secret API key as a bearer token
- Billing: Free.
- Group: IP

Renames a list, changes its kind, or replaces its entries with the ones sent. Send only the fields you are changing; a body that names none of `name`, `kind` and `entries` answers `422` rather than quietly changing nothing, because that is the shape a misspelled field name takes. Entries are canonicalised and deduplicated exactly as on creation, and the change applies from the account's next lookup. A list that belongs to another account answers `404`.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `listId` | path | integer | yes | The list's id from the index. |

## Request body

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | no | At most 100 characters. |
| `kind` | string | no | One of: allow, deny. |
| `entries` | string[] | no | Replaces the list's entries. |

## Example request

```bash
curl -X PATCH https://spaw.co/api/v1/ip/lists/7 \
  -H "Authorization: Bearer sk_live_…" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Office and warehouse egress",
  "entries": [
    "203.0.113.0/24",
    "2001:db8:10::/48",
    "198.51.100.7"
  ]
}'
```

## Responses

### 200 — The list as it now stands.

```json
{
    "success": true,
    "data": {
        "list": {
            "id": 7,
            "name": "Office and warehouse egress",
            "kind": "allow",
            "entry_count": 3,
            "created_at": "2026-09-12T09:00:00+00:00",
            "updated_at": "2026-09-12T11:30:00+00:00",
            "entries": [
                "203.0.113.0/24",
                "2001:db8:10::/48",
                "198.51.100.7"
            ]
        }
    }
}
```

### 401 — The key is missing, malformed, or revoked.

```json
{
    "success": false,
    "error": {
        "code": "UNAUTHENTICATED",
        "message": "Provide a valid API key as a bearer token.",
        "request_id": "req_01m1kgdm4xngzmbmff68g94w0c"
    }
}
```

### 404 — No such record on this account.

```json
{
    "success": false,
    "error": {
        "code": "NOT_FOUND",
        "message": "No record with that id on this account.",
        "request_id": "req_01m1kgdm4xngzmbmff68g94w0c"
    }
}
```

### 422 — The request body could not be validated; `error.errors` lists the fields.

```json
{
    "success": false,
    "error": {
        "code": "VALIDATION_FAILED",
        "message": "The email field is required.",
        "errors": {
            "email": [
                "The email field is required."
            ]
        },
        "request_id": "req_01m1kgdm4xngzmbmff68g94w0c"
    }
}
```

### 429 — Over 5 requests per second for the key. Retry after the limit resets.

```json
{
    "success": false,
    "error": {
        "code": "RATE_LIMITED",
        "message": "Too many requests. Retry after the limit resets.",
        "request_id": "req_01m1kgdm4xngzmbmff68g94w0c"
    }
}
```

## Error codes

- `UNAUTHENTICATED` — https://spaw.co/docs/errors/UNAUTHENTICATED
- `NOT_FOUND` — https://spaw.co/docs/errors/NOT_FOUND
- `VALIDATION_FAILED` — https://spaw.co/docs/errors/VALIDATION_FAILED
- `RATE_LIMITED` — https://spaw.co/docs/errors/RATE_LIMITED

---

Canonical page: https://spaw.co/docs/api/update-ip-list · OpenAPI document: https://spaw.co/openapi.json · All endpoints: https://spaw.co/docs/api
