PUT /v1/projects/{project}/scoring/settings
Update a project's pre-rule guards and bot threshold. Changes bust the verdict cache so they take effect promptly.
curl -X PUT https://api.botect.ai/v1/projects/123/scoring/settings \
-H "Authorization: Bearer YOUR_ACCOUNT_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"allow_verified": true,
"likely_bot_threshold": 40
}'
const res = await fetch('https://api.botect.ai/v1/projects/123/scoring/settings', {
method: 'PUT',
headers: {
Authorization: `Bearer ${process.env.BOTECT_TOKEN}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ allow_verified: true, likely_bot_threshold: 40 }),
});
const settings = await res.json();
import os, requests
r = requests.put(
"https://api.botect.ai/v1/projects/123/scoring/settings",
headers={"Authorization": f"Bearer {os.environ['BOTECT_TOKEN']}"},
json={"allow_verified": True, "likely_bot_threshold": 40},
)
settings = r.json()
{
"bot_settings": {
"allow_verified": true,
"protect_static": true,
"logged_in_policy": "observe"
},
"likely_bot_threshold": 40
}
Updates the project's guards — who is exempt from being checked — and the likely-bot threshold. Changes apply to verdicts computed from then on; a verdict already cached for a session is served until it expires, so allow up to the verdict cache TTL (60s by default).
This endpoint does not configure enforcement. Blocking and challenging are decided entirely by rules; see Create a rule.
PUT https://api.botect.ai/v1/projects/{project}/scoring/settings
Authentication
Account API token via Authorization: Bearer <token>. The project must belong to the token's account. See Authentication.
Path parameters
The project ID.
Body
All fields are optional — send only what you want to change.
Verified bots → allow, regardless of score, before any rule is evaluated. Default true.
When false, static-resource requests are skipped (allow). Default true.
What a logged-in assertion buys at enforcement time: observe (default), never_block, never_challenge, or whitelist. No value shelters the definite or confident_automated bands.
The bot/human boundary T, 1–99. Default 30. Higher is more suspicious.
block_definite and challenge_likely were removed. Sending either returns 422 — they are not translated silently. Use a rule instead: activate the starter rule that matches (band == "definite" → block, band == "likely_automated" → challenge), or create your own.
Example
Response fields
The project's guards after the update.
The threshold T after the update.
Errors
| Status | code | When |
|---|---|---|
401 | UNAUTHENTICATED | Missing / bad account token |
403 | — | Project does not belong to the token's account |
422 | INVALID_PAYLOAD | A guard is non-boolean, likely_bot_threshold is out of range, or a removed enforcement toggle was sent |
See Score bands for how bands, guards and rules combine into the verdict action.