---
title: "Update pending invitee"
method: PUT
path: "/api/apps/{app_id}/access-requests/{request_id}"
---

# Update pending invitee

`PUT /api/apps/{app_id}/access-requests/{request_id}`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Sets custom `User` fields on someone who hasn't joined the app yet. When they join, the values are copied onto their user record.

The fields you send are merged into the stored ones, and a field you leave out keeps its value. Built-in fields such as `email`, `full_name`, `role` and `id` are ignored. Field-level security rules on the `User` entity apply, and a value over 20,000 characters is refused. Once the person has joined, change them with [Update app user](/api-reference/update-app-user) instead, because this endpoint returns a 404 for them.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `request_id` string, required — ID of the access request, as `id` in the response of [List access requests](/api-reference/list-access-requests).
- `app_id` string, required — ID of the app.

## Request body

- UpdateAccessRequestPayload
  - `data` object, required — Custom `User` fields to set on the invitation, as field names and values.

## Response `200`

The invitation's custom fields after the update.

- UpdatedInvitation — Doc-only: the handler returns a plain dict with exactly these keys.
  - `success` boolean, required — Always `true`. An update that doesn't happen returns an error instead.
  - `data` object, required — The invitation's custom `User` fields after the update, limited by the `User` entity's field-level read rules.

## Other responses

- `400` — A field value is over 20,000 characters.
- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app, a field-level security rule refuses a field you're changing, or your API key is read-only.
- `404` — App not found, or the app has no pending invitation with this ID, including one the person already accepted.
- `422` — `data` is missing, or isn't a JSON object.

## Changes

> 18 revisions in range; 1 not diffed.

- **2026-09-28** `28fc82924122` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/access-requests/:request_id/put.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/28fc82924122?raw)
