> ## Documentation Index
> Fetch the complete documentation index at: https://docs.attaxr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a scan or its schedule

> Updates the caller-writable fields of a scan (metadata), or of the schedule behind the id (name, target, scanType, scheduleType, runAt, cron, recurringInterval, intervalDays, workflowSteps). A schedule cadence change re-arms nextRunAt with the new schedule. Engine-owned fields — scan status and lifecycle timestamps, the stored scope and plan, scheduler bookkeeping — are ignored on update.



## OpenAPI

````yaml /api/openapi.json put /api/scans/{id}
openapi: 3.1.0
info:
  title: Aquila API
  version: 1.0.0
  description: >-
    Event-driven reconnaissance platform API. All /api/* routes except
    /api/public/* require an authenticated session (cookie), an X-Api-Key
    header, or a bearer token. Auth endpoints under /api/auth/* are generated by
    Better Auth.
servers:
  - url: https://aquila.attaxr.com
  - url: http://localhost
security: []
tags:
  - name: AI
  - name: Agents
  - name: Bulk Delete
  - name: Chat
  - name: Constraints
  - name: Dashboard
  - name: Events
  - name: JS
  - name: JS Analysis
  - name: JS Monitoring
  - name: Leads
  - name: MCP Key
  - name: Models
  - name: Notification Channels
  - name: Notification Event Preferences
  - name: Notifications
  - name: OOB
  - name: Provider Keys
  - name: Public Shares
  - name: Reinforcements
  - name: Reports
  - name: Scans
  - name: Schedules
  - name: Shares
  - name: Tools
  - name: User Profiles
  - name: V1
  - name: Vulnerabilities
  - name: Workflows
paths:
  /api/scans/{id}:
    put:
      tags:
        - Scans
      summary: Update a scan or its schedule
      description: >-
        Updates the caller-writable fields of a scan (metadata), or of the
        schedule behind the id (name, target, scanType, scheduleType, runAt,
        cron, recurringInterval, intervalDays, workflowSteps). A schedule
        cadence change re-arms nextRunAt with the new schedule. Engine-owned
        fields — scan status and lifecycle timestamps, the stored scope and
        plan, scheduler bookkeeping — are ignored on update.
      operationId: putApiScansId
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                metadata:
                  type: object
                  propertyNames:
                    type: string
                  additionalProperties: {}
                updatedAt: {}
                name:
                  type: string
                  minLength: 1
                target:
                  type: string
                  minLength: 1
                scanType:
                  type: string
                  enum:
                    - recon
                    - monitoring
                    - email-digest
                scheduleType:
                  type: string
                  enum:
                    - now
                    - once
                    - recurring
                workflowSteps:
                  type: array
                  items:
                    type: object
                    properties:
                      name:
                        type: string
                      tool:
                        type: string
                      args:
                        default: []
                        type: array
                        items:
                          type: string
                      env:
                        default: {}
                        type: object
                        propertyNames:
                          type: string
                        additionalProperties:
                          type: string
                      retryCount:
                        default: 0
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                      timeout:
                        default: 300
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                    required:
                      - name
                      - tool
                runAt: {}
                cron:
                  type: string
                recurringInterval:
                  type: string
                  enum:
                    - daily
                    - weekly
                    - monthly
                    - every_n_days
                    - custom
                intervalDays:
                  type: integer
                  exclusiveMinimum: 0
                  maximum: 9007199254740991
      responses:
        '200':
          description: The updated scan or schedule.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid JSON body or validation failed.
          content:
            application/json:
              schema: {}
        '401':
          description: No valid session cookie or API key.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
        '403':
          description: Email address not verified, or the caller lacks the required role.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
        '404':
          description: No scan or schedule found for this id.
          content:
            application/json:
              schema: {}
        '429':
          description: >-
            Risk-tier rate limit exceeded (writes 20/min, expensive 10/min, bulk
            60/min). Limited responses carry X-RateLimit-Limit,
            X-RateLimit-Remaining, X-RateLimit-Reset and Retry-After.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
                additionalProperties: false
      security:
        - apiKeyCookie: []
        - apiKeyHeader: []
        - bearerAuth: []
components:
  securitySchemes:
    apiKeyCookie:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Browser session cookie set by Better Auth sign-in.
    apiKeyHeader:
      type: apiKey
      in: header
      name: x-api-key
      description: Personal API key (aquila_… prefix; settings → API keys).
    bearerAuth:
      type: http
      scheme: bearer
      description: Personal API key sent as a bearer token.

````