> For the complete documentation index, see [llms.txt](https://www.boxhero.io/docs/llms.txt). Every page is available as Markdown by appending `.md` to its URL; this page is [Markdown](https://www.boxhero.io/docs/de/developers/api/reference/bundles/update-bundle-by-sku.md).

# Update a bundle by SKU

> Looks up a bundle by SKU (case-sensitive) and applies the same partial update as PUT /bundles/{bundle_id}.

`PUT https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}`

## Autorisierung

- `Authorization` (string, erforderlich): Bearer-Authentifizierungsheader im Format `Bearer <token>`, wobei `<token>` Ihr [API-Token](https://www.boxhero.io/docs/de/developers/api/authentication) ist.

## Pfadparameter

- `sku` (string, min length 1, max length 255, erforderlich): Bundle SKU (case-sensitive). URL-encode special characters such as `#`, `%`, `/`, or spaces.

## Anfragetext

- `name` (string, min length 1, max length 255): Bundle display name.
- `sku` (string, min length 1, max length 255): Stock Keeping Unit. Must be unique across active bundles in the team.
- `barcode` (string, max length 255): Primary bundle barcode.
- `photo_url` (string, max length 2048): Public URL of the bundle photo.
- `memo` (string, max length 2000): Free-text memo.
- `cost` (string): Cost per bundle, as a decimal string.
- `price` (string): Selling price per bundle, as a decimal string.
- `components` (array of object): Component list. When provided on update, this replaces the full component list.

  - `item_id` (integer, minimum 0, maximum 2147483647): Component item id. Mutually exclusive with item_sku.
  - `item_sku` (string, min length 1, max length 255): Component item SKU (case-insensitive). Mutually exclusive with item_id.
  - `quantity` (number, erforderlich): Quantity of this item required per bundle.

## Antworten

**200** The updated bundle's id.

- `id` (integer, minimum 0, maximum 2147483647, erforderlich): Id of the updated bundle.

**400** Request validation failed.

- `id` (string, erforderlich): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, erforderlich): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  Mögliche Werte: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, erforderlich): Human-readable summary of the error, in English.
- `correlationID` (string, erforderlich): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, erforderlich): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, erforderlich)
  - `message` (string, erforderlich)

**401** Missing or invalid API token.

- `id` (string, erforderlich): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, erforderlich): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  Mögliche Werte: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, erforderlich): Human-readable summary of the error, in English.
- `correlationID` (string, erforderlich): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, erforderlich): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, erforderlich)
  - `message` (string, erforderlich)

**404** No bundle with the given SKU was found in this team.

- `id` (string, erforderlich): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, erforderlich): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  Mögliche Werte: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, erforderlich): Human-readable summary of the error, in English.
- `correlationID` (string, erforderlich): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, erforderlich): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, erforderlich)
  - `message` (string, erforderlich)

**429** Rate limit exceeded. Check `RateLimit`, `Retry-After`, and `X-RateLimit-*` response headers before retrying.

- `id` (string, erforderlich): Unique exception id (`ex_` followed by 32 lowercase hex chars, no dashes — e.g. `ex_8f5c0c8e0e0a4a3c9b3f4f2c4f6c8d2a`). Quote this in support tickets so we can find the request in our logs.
- `type` (string, erforderlich): Stable, machine-readable error code (RFC 7807-style URI fragment). Branch your error handling on this, not on `title`.

  Mögliche Werte: `/errors/not-found`, `/errors/invalid-request`, `/errors/invalid-team-mode`, `/errors/tokens/invalid`, `/errors/tokens/required`, `/errors/too-many-requests`, `/errors/core/usage-limit-exceeded`, `/errors/core/forbidden`, `/errors/core/unhandled`, `/errors/unhandled`
- `title` (string, erforderlich): Human-readable summary of the error, in English.
- `correlationID` (string, erforderlich): Request correlation id (`rq_` followed by 32 lowercase hex chars, no dashes — e.g. `rq_01abf3...`). Identical to the `X-Correlation-Id` response header. Pass an `X-Correlation-Id` request header to thread your trace through to ours.
- `instance` (string, erforderlich): Pointer to the specific failing resource (e.g. `/items/12345`). Path-only, no `/v1` version prefix.
- `code` (string): Sub-reason code surfaced from upstream BoxHero core (on core-mapped 4xx) or from the gateway itself (e.g. `not-available-for-api-token` on 403). Use this for fine-grained branching after dispatching on `type`.
- `errors` (array of object): Field-level error details. Present on `/errors/invalid-request` (400) responses. Each entry locates a single failure via JSONPath-like `path` segments and a human-readable `message`.

  - `path` (array of string | number, erforderlich)
  - `message` (string, erforderlich)

Anfrage

**cURL**

```bash
curl --request PUT \
  --url 'https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}' \
  --header "Authorization: Bearer $BOXHERO_API_TOKEN" \
  --header 'Content-Type: application/json' \
  --data '{
    "name": "Starter kit v2",
    "components": [
      {
        "item_id": 14290445,
        "quantity": 1
      },
      {
        "item_id": 14290446,
        "quantity": 1
      }
    ]
  }'
```

**JavaScript**

```javascript
const response = await fetch("https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}", {
  method: "PUT",
  headers: {
    Authorization: `Bearer ${process.env.BOXHERO_API_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "name": "Starter kit v2",
    "components": [
      {
        "item_id": 14290445,
        "quantity": 1
      },
      {
        "item_id": 14290446,
        "quantity": 1
      }
    ]
  }),
});
const data = await response.json();
```

**Python**

```python
import os
import requests

response = requests.put(
    "https://rest.boxhero-app.com/v1/bundles/by-sku/{sku}",
    headers={
        "Authorization": "Bearer " + os.environ["BOXHERO_API_TOKEN"],
    },
    json={
        "name": "Starter kit v2",
        "components": [
            {
                "item_id": 14290445,
                "quantity": 1,
            },
            {
                "item_id": 14290446,
                "quantity": 1,
            },
        ],
    },
)
data = response.json()
```

**HTTP**

```http
PUT /v1/bundles/by-sku/{sku} HTTP/1.1
Host: rest.boxhero-app.com
Authorization: Bearer <token>
Content-Type: application/json

{
  "name": "Starter kit v2",
  "components": [
    {
      "item_id": 14290445,
      "quantity": 1
    },
    {
      "item_id": 14290446,
      "quantity": 1
    }
  ]
}
```

Antwort

**200**

```json
{
  "id": 4042
}
```

**400**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/invalid-request",
  "title": "Request validation failed.",
  "instance": "/bundles/by-sku/SKU-123"
}
```

**401**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/tokens/required",
  "title": "Missing API token. Provide a Bearer token in the Authorization header.",
  "example": "Bearer wqnot0dlysdg5vymubzi4kiv"
}
```

**404**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/not-found",
  "title": "No bundle with the given SKU was found in this team.",
  "instance": "/bundles/by-sku/SKU-123"
}
```

**429**

```json
{
  "id": "ex_8f5c0c8e-0e0a-4a3c-9b3f-4f2c4f6c8d2a",
  "correlationID": "01J9X8K9XZ4ZWV9T8MQ8B7H7C2",
  "type": "/errors/too-many-requests",
  "title": "Too many requests.",
  "instance": "/bundles/by-sku/SKU-123",
  "retryAfter": 60
}
```
