Update document metadata
| Method | Path |
|---|---|
PATCH | /document/:id |
Authentication · Access policies · Files and documents
Changes a document's file name, content type or public status, without uploading a new file. To change the file itself, use Replace document file.
Auth: Bearer token. The document is read and updated with your token, so the access policy must allow DocumentReference:read and DocumentReference:update.
Scope: The document must be visible to you in your project (from the token).
Request
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id | string (uuid) | Yes | Document id. |
Body
Every field is optional. Fields you leave out keep their value. Fields that are not listed here are ignored.
| Name | Type | Required | Description |
|---|---|---|---|
fileName | string | No | New name of the file. Stored as the document title and used as the download name. At least 1 character. |
contentType | string | No | New MIME type. Must be one of the types allowed by Create document, matched exactly. |
isPublic | boolean | No | true makes the document public, false makes it private. A JSON boolean here, unlike the string on POST /document. |
Behaviour
fileNamechanges the document title and the name used on download. It does not move or rename the stored file.contentTypechanges the type on the document and asks file storage to change the type of the stored file. If file storage cannot change it, the call still succeeds and the document carries the new type.isPublic: trueon a private document gives it a public token, returned aspublicToken.isPublic: falseon a public document removes the token, so its public links stop working. Setting the state the document already has changes nothing, and the token stays.- An empty body changes nothing and returns the document.
- The response has the same shape as a search entry, without
uploadOptions.
Example
curl -X PATCH 'https://api.sandbox.ovok.com/document/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"fileName": "updated-image.png",
"isPublic": true
}'
Successful response
200 — The updated document.
{
"id": "3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21",
"meta": { "lastUpdated": "2026-10-09T09:31:27.640Z" },
"author": {
"reference": "Practitioner/8c5e7a21-4b9d-4f36-a1c8-0d2e6b9f3a54",
"display": "Alex Lee"
},
"fileName": "updated-image.png",
"contentType": "image/png",
"publicToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyZWZlcmVuY2UiOiJEb2N1bWVudFJlZmVyZW5jZS8zZjFjMmI3ZS04ZDRhLTRjMWUtOWIyZi02YTdkNWU0YzNiMjEiLCJpYXQiOjE3OTE1MDAwMDB9.c2lnbmF0dXJl"
}
| Field | Type | Description |
|---|---|---|
id | string (uuid) | Document id. |
meta.lastUpdated | string | When the document last changed. ISO 8601. |
author | object | First author of the document. Left out when it has none. |
author.reference | string | Author reference, for example Practitioner/<id>. |
author.display | string | Author display name. Left out when not set. |
fileName | string | Current file name. |
contentType | string | Current content type. |
publicToken | string | Public token. Left out unless the document is public. |
Errors
| Status | Meaning |
|---|---|
400 | id is not a UUID, or the body fails validation: fileName is empty, contentType is not an allowed type, or isPublic is not a boolean. message lists each problem as path: message. |
401 | Bearer token is missing, invalid or revoked. |
403 | Your access policy does not allow reading or updating the DocumentReference. |
404 | No document with this id is visible to you, or the document has no file URL. |
410 | The document was deleted. |
429 | You exceeded the rate limit for your user type. |