ConfigurationUpdate settings

PUT /v1/projects/{project}/scoring/settings

Update a project's pre-rule guards and bot threshold. Changes bust the verdict cache so they take effect promptly.

curl -X PUT https://api.botect.ai/v1/projects/123/scoring/settings \
  -H "Authorization: Bearer YOUR_ACCOUNT_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "allow_verified": true,
    "likely_bot_threshold": 40
  }'
{
  "bot_settings": {
    "allow_verified": true,
    "protect_static": true,
    "logged_in_policy": "observe"
  },
  "likely_bot_threshold": 40
}

Updates the project's guards — who is exempt from being checked — and the likely-bot threshold. Changes apply to verdicts computed from then on; a verdict already cached for a session is served until it expires, so allow up to the verdict cache TTL (60s by default).

This endpoint does not configure enforcement. Blocking and challenging are decided entirely by rules; see Create a rule.

PUT https://api.botect.ai/v1/projects/{project}/scoring/settings

Authentication

Account API token via Authorization: Bearer <token>. The project must belong to the token's account. See Authentication.

Path parameters

Body

All fields are optional — send only what you want to change.

body
allow_verifiedboolean

Verified bots → allow, regardless of score, before any rule is evaluated. Default true.

body
protect_staticboolean

When false, static-resource requests are skipped (allow). Default true.

body
logged_in_policystring

What a logged-in assertion buys at enforcement time: observe (default), never_block, never_challenge, or whitelist. No value shelters the definite or confident_automated bands.

body
likely_bot_thresholdinteger

The bot/human boundary T, 1–99. Default 30. Higher is more suspicious.

block_definite and challenge_likely were removed. Sending either returns 422 — they are not translated silently. Use a rule instead: activate the starter rule that matches (band == "definite" → block, band == "likely_automated" → challenge), or create your own.

Example

Response fields

bot_settingsobject
Required

The project's guards after the update.

likely_bot_thresholdinteger
Required

The threshold T after the update.

Errors

StatuscodeWhen
401UNAUTHENTICATEDMissing / bad account token
403—Project does not belong to the token's account
422INVALID_PAYLOADA guard is non-boolean, likely_bot_threshold is out of range, or a removed enforcement toggle was sent

See Score bands for how bands, guards and rules combine into the verdict action.