---
title: "Update entity records by filter"
method: PATCH
path: "/api/apps/{app_id}/entities/{entity_name}/update-many"
---

# Update entity records by filter

`PATCH /api/apps/{app_id}/entities/{entity_name}/update-many`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Applies the same change to up to 500 records in one of the app's entities that match a filter, and returns how many changed.

Send `query`, a filter written the same way as the `q` parameter of [List entity records](/api-reference/list-entity-records), and `data`, the change written as MongoDB update operators on the entity's field names. For example, `{"query": {"status": "draft"}, "data": {"$set": {"status": "sent"}}}` marks every draft as sent. A field can appear in only one operator per call, and the operators you can use are:
- `$set`, `$unset`, and `$rename`
- `$inc`, `$mul`, `$min`, and `$max`
- `$currentDate`
- `$addToSet`, `$push`, and `$pull`

The values aren't checked against the entity's schema, so a field the schema doesn't declare, or a value of another type, is stored as sent.

Row-level security applies. The filter only reaches records the entity's `rls` update rule lets you change, and the rest are left alone rather than failing the call. If a field-level rule refuses the change on any matching record, the call is rejected and no records change.

When more than 500 records match, 500 of them change and `has_more` is `true`. Call again to change the rest, with a filter that no longer matches the records you've already changed, as the draft filter in the example does. A filter that still matches them changes the same records again.

Repeating `$set`, `$unset`, `$rename`, `$min`, `$max`, `$addToSet`, or `$pull` leaves the records as the first call did, so it's safe to retry. Repeating `$inc`, `$mul`, `$push`, or `$currentDate` applies the change a second time.

Unlike [Update entity record](/api-reference/update-entity-record), this doesn't trigger the app's webhooks, automations, or workflows.

<Note>This endpoint accepts a personal API key belonging to a user with access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app that owns the entity.
- `entity_name` string, required — Name of the entity, exactly as [List entity schemas](/api-reference/list-entity-schemas) reports it. Don't pass `User` here. It doesn't fail, but it reads and writes a separate, disconnected set of records stored under that name, not the app's real user accounts, which are managed through their own endpoints.

## Request body

- object
  - `query` object, required — Filter selecting the records to change, in the same form as `q`. Send `{}` to match every record.
  - `data` object, required — The change, as one or more update operators, each mapping field names to values.

## Response `200`

How many records changed.

- object — How many records a filtered update changed.
  - `success` boolean, required — Always `true`. An update that doesn't happen returns an error instead.
  - `updated` integer, required — Number of matching records the call changed. A record that already held the new values still counts, because its `updated_date` changes, and `0` means no record matched.
  - `has_more` boolean, required — Whether more than 500 records matched, so only 500 of them were changed and more may be left.

## Other responses

- `400` — `data` is empty, uses an operator that isn't supported, isn't an object for each operator, or names a field in more than one operator. Also returned when `query` isn't a filter Base44 can run, for example one with an `id` that isn't a record ID, when an operator doesn't fit the type a field holds, or, on some apps, when a value is over 20,000 characters.
- `401` — Missing or invalid credentials.
- `403` — You don't have access to this app, the entity's `rls` update rule or a field-level rule refuses the change on a matching record, or your API key is read-only.
- `404` — App not found, or the app has no entity with this name.
- `405` — The entity is `User`, whose records can't be updated in bulk.
- `422` — The body is missing `query` or `data`, or one of them isn't a JSON object.
- `429` — Rate limit exceeded. The base limit is 25 requests per minute, and this endpoint shares it with [Update entity records](/api-reference/update-entity-records). See [Rate limits](/developers/references/apps-api/get-started/rate-limits) for the multiplier your plan gets.

## Changes

- **2026-09-30** `e2a6a9f1fe4c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/idealspot/apis/base44-app-management-api/changes/api/apps/:app_id/entities/:entity_name/update-many/patch.md)

---

[API](https://skmtc.dev/idealspot/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/idealspot/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/idealspot/apis/base44-app-management-api/revisions/e2a6a9f1fe4c?raw)
