Operation CategoriesUpdate assignment values (new version)

Update assignment values (new version)

Value patch (merged; null clears). Requires the edit capability. If approvalScope ∈ {edit, assign_and_edit} → approval request (202, D4) with an optimistic lock.

curl -X PATCH "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/operations/transfer/example_string/categories/example_string" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "values": {},
  "changeNote": "example_string"
}'
{
  "id": "cmr3f41z20001psp7phmyapw3",
  "vaultId": "example_string",
  "operationType": "deposit",
  "operationId": "example_string",
  "categoryId": "example_string",
  "category": {
    "id": "example_string",
    "key": "example_string",
    "name": "John Doe"
  },
  "values": {},
  "redactedFields": [
    "example_string"
  ],
  "version": 42,
  "status": "active",
  "createdById": "example_string",
  "updatedById": "example_string",
  "createdAt": "2026-07-02T11:25:15.134000Z",
  "updatedAt": "2026-07-02T11:25:15.134000Z"
}
PATCH
/api/v1/vaults/{code}/operations/{type}/{id}/categories/{assignmentId}
PATCH
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Session token. Mobile/services. The web uses a cookie.

Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
Required

API key (sent in cookie)

Content-Typestring
Required

The media type of the request body

Options: application/json
valuesobject
Required

Value patch (merged; null clears the key). required fields remain required

changeNotestring
Max length: 500
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Session token. Mobile/services. The web uses a cookie.

path
parameterstring
Required

API Key for authentication. Provide your API key in the cookie.

Path Parameters

codestring
Required

Unique Vault code (slug)

Example:
demo_vault
typestring
Required
Allowed values:transferdeposit

Body

application/json
valuesobject
Required

Value patch (merged; null clears the key). required fields remain required

Responses

idstring
Required

cuid

vaultIdstring
Required
operationTypestring
Required
Allowed values:deposittransfer
operationIdstring
Required
categoryIdstring
Required
categoryobject

Lightweight category card

valuesobject
Required

Field values { fieldKey: value }; sensitive without access → null

redactedFieldsstring[]
Required

Keys of hidden (sensitive) fields that the caller can't access

versioninteger
Required
statusstring
Required
Allowed values:activeremoved
createdByIdstring
Required
updatedByIdstring
Required
createdAtstring
Required
updatedAtstring
Required