---
title: "Update app"
method: PUT
path: "/api/apps/{app_id}"
---

# Update app

`PUT /api/apps/{app_id}`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Changes the app's details and settings. That covers its name and description, who can open it, how people sign in, and a few display settings.

Send only the fields you want to change. A field you leave out keeps its value, and so does a login method you leave out of `auth_config`.

Renaming doesn't change the app's address. Change that with [Change app slug](/api-reference/change-app-slug).

A new `public_settings` value applies to the published app right away, and so does whether others can remix the app. Changes to `auth_config`, the Base44 badge, and `hide_entity_created_by` take effect on the published app once you [deploy the app](/api-reference/deploy-an-app), or sooner if a `public_settings` change carries them along.

<Warning>This endpoint also accepts other app fields, but only the fields documented here are part of this API. Don't send anything else. Other fields aren't covered by the contract and can change or be rejected without notice.</Warning>

## Path parameters

- `app_id` unknown, required

## Request body

- object
  - `name` string — New name for the app.
  - `user_description` string, nullable — New description for the app, or `null` to remove it.
  - `public_settings` 'public_without_login' | 'public_with_login' | 'workspace_with_login' | 'private_with_login' — Who can open the published app. `public_without_login` lets anyone in, unless the workspace enforces SSO for apps, in which case visitors must log in. `public_with_login` lets anyone in who logs in, `workspace_with_login` admits only logged-in members of the workspace, and `private_with_login` admits only users who were granted access. Switching to `workspace_with_login` or `private_with_login` needs a paid plan, and a workspace policy can restrict which values you can choose. An agent app always stays `private_with_login`.
  - `auth_config` object — Which login methods the app's login page offers. Send only the methods you want to change. If the workspace enforces SSO for apps, the login page offers only SSO, whatever these are set to. Set up the app's own SSO provider with [Update app SSO settings](/api-reference/update-app-sso-settings).
    - `enable_username_password` boolean — `true` lets people sign in with an email and password, and `false` removes that option.
    - `enable_google_login` boolean — `true` lets people sign in with a Google account, and `false` removes that option.
    - `enable_microsoft_login` boolean — `true` lets people sign in with a Microsoft account, and `false` removes that option.
    - `enable_facebook_login` boolean — `true` lets people sign in with a Facebook account, and `false` removes that option.
    - `enable_apple_login` boolean — `true` lets people sign in with an Apple account, and `false` removes that option.
  - `is_remixable` boolean — `true` shows the Base44 badge on the published app and lets others remix it. The badge only shows while the app is `public_with_login` or `public_without_login`. `false` hides the badge and turns remixing off, which needs a paid plan on the app's workspace.
  - `hide_entity_created_by` boolean — `true` leaves the email of the user who created each record (`created_by`) out of the app's entity records, and `false` includes it. `created_by_id` is always included. Newer apps always leave the email out and ignore this field.
  - `dev_environment_enabled` boolean — `true` turns on test data. The app gets a test database next to its live one, so you can try changes in the preview without touching live data. Turning it on needs a Builder plan or higher on the app's workspace. `false` turns it off.

## Response `200`

The app, with its new details.

- AppSummary — An app in a workspace, limited to the properties the caller requested.
  - `id` string, nullable — ID of the app.
  - `name` string, nullable — Display name of the app.
  - `slug` string, nullable — URL slug for the app, auto generated from the name and app ID or set to a custom value, or `null` if the app has no slug yet. The published URL is built from it.
  - `user_description` string, nullable — Description of the app, or `null` if none was set. An app created without a `name` gets a generated description once a build turn changes it.
  - `created_by` string, nullable — Email of the user who created the app.
  - `created_date` string, date-time, nullable — Time the app was created, as a UTC timestamp in ISO 8601 format.
  - `updated_date` string, date-time, nullable — Time the app document was last written, as a UTC timestamp in ISO 8601 format.
  - `status` AppStatusResponse — The app's current build status.
    - `state` 'ready' | 'processing' | 'error', required — Where the app is in its build lifecycle. Ready means idle with no build in progress, processing means the app is being generated or modified, and error means the last build failed. This tracks building, not publishing.
    - `details` string, nullable — Human readable note about the current state, such as what is being processed or why it failed, or `null` when there is nothing to report.
    - `request_id` string, nullable — ID of the request that last changed the status, or `null` if the status has never changed. Useful when reporting an issue.
    - `last_updated_date` string, date-time, nullable — Time the status was last updated, as a UTC timestamp in ISO 8601 format.
    - `error_source` string, nullable — Where the failure originated when `state` is `error`, or `null` otherwise. A value of `paywall` means the work was blocked because the app's workspace has no credits left.
    - `paywall_context` PaywallStatusContextResponse
      - `billing_organization_id` string, required — ID of the billing organization the paywall was evaluated against.
      - `user_id` string, required — ID of the user the paywall was evaluated for.
      - `evaluated_at` string, date-time, required — Time the paywall condition was evaluated, as a UTC timestamp in ISO 8601 format.
  - `last_deployed_at` string, date-time, nullable — Time the app was last published, as a UTC timestamp in ISO 8601 format, or `null` if it has never been published.
  - `screenshot_url` string, nullable — URL of a screenshot of the published app. Captured shortly after each publish, so it can briefly lag or be `null` right after publishing.
  - `preview_screenshot_url` string, nullable — URL of a preview screenshot taken before publishing, distinct from `screenshot_url`, or `null` if none has been captured.
  - `main_branch_protected` boolean, nullable — Whether the app's main branch is protected, so changes to main must go through a branch that's merged back. Change it with [Set main branch protection](/api-reference/set-main-branch-protection).
  - `organization_id` string, nullable — ID of the workspace the app belongs to.
  - `owner_id` string, nullable — ID of the user who owns the app. It starts as the creator and changes when ownership is transferred.
  - `app_type` string, nullable — Kind of app, set when it's created. One of `user_app` (a web app), `user_agent` (an AI agent), `mobile_app` (a native mobile app), `user_game` (a game), `slide` (a presentation), or `imported_app` (an app imported from an existing code repository). List apps returns it as stored, so an older agent app can report `agent` instead of `user_agent`, and some older apps don't include it. Get app always returns one of the values above.
  - `public_settings` 'public_without_login' | 'public_with_login' | 'workspace_with_login' | 'private_with_login', nullable — Who can open the published app. Each value is described under [Update app](/api-reference/update-app), which also changes it.
  - `auth_config` AppLoginMethods
    - `enable_username_password` boolean, nullable — Whether people can sign in to the app with an email and password.
    - `enable_google_login` boolean, nullable — Whether people can sign in to the app with a Google account.
    - `enable_microsoft_login` boolean, nullable — Whether people can sign in to the app with a Microsoft account.
    - `enable_facebook_login` boolean, nullable — Whether people can sign in to the app with a Facebook account.
    - `enable_apple_login` boolean, nullable — Whether people can sign in to the app with an Apple account.
  - `is_remixable` boolean, nullable — Whether others can remix the app. While it's `true`, the published app also shows the Base44 badge if `public_settings` is `public_with_login` or `public_without_login`.
  - `hide_entity_created_by` boolean, nullable — Whether the app's entity records leave out the email of the user who created each one (`created_by`). Newer apps always leave the email out, whatever this is set to.
  - `dev_environment_enabled` boolean, nullable — Whether test data is on, which gives the app a test database next to its live one.
  - `logo_url` string, nullable — URL of the app's logo, or `null` if it has none. Set it with [Set app logo](/api-reference/set-app-logo) or [Generate app logo](/api-reference/generate-app-logo).
  - `social_image_url` string, nullable — URL of the image shown when the app is shared on social platforms, or `null` if none was set, in which case the logo is shown instead. Set it with [Set social image](/api-reference/set-social-image).
  - `is_unpublished` boolean, nullable — Whether the app was taken offline with [Unpublish app](/api-reference/unpublish-app) and hasn't been published again since. While it's `true`, the published URL is offline and `last_deployed_at` still shows the last publish.

## Other responses

- `400` — The app is an agent, and `public_settings` isn't `private_with_login`.
- `401` — Missing or invalid credentials.
- `402` — The app's workspace plan doesn't include the `public_settings` value you sent, or you're turning on test data and the plan doesn't include it.
- `403` — You don't have access to this app, it doesn't exist, or your API key is read-only. Also returned when the workspace policy doesn't allow the `public_settings` value you sent, or when you set `is_remixable` to `false` without a paid plan.
- `422` — A field has the wrong type, or `public_settings` isn't one of its allowed values.

## Changes

- **2026-09-30** `e2a6a9f1fe4c` — 1 warning
  - removed the optional property `first_prompt_model_comparison` from the response with the `200` status
- **2026-09-29** `347e2afcf94a` — 1 breaking, 18 info
  - removed the media type `application/json` for the response with the status `422`
  - added the new optional request property `auth_config`
  - added the new optional request property `dev_environment_enabled`
  - added the new optional request property `hide_entity_created_by`
  - …15 more
- **2026-09-27** `7d0af6c5afcc` — 1 info
  - added the optional property `main_branch_protected` to the response with the `200` status
- **2026-09-25** `cf164639a9bf` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/idealspot/apis/base44-app-management-api/changes/api/apps/:app_id/put.md)

---

[API](https://skmtc.dev/idealspot/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/idealspot/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/idealspot/apis/base44-app-management-api/revisions/e2a6a9f1fe4c?raw)
