API

Star workflows

Star workflows. This replaces or sets the selected state using the full supplied value.

PUT/api/workflows/{workflowId}/star
Preview

Star workflows. This replaces or sets the selected state using the full supplied value.

Operation ID putapiWorkflowsWorkflowIdStar

Operation details

Purpose

Star workflows. This replaces or sets the selected state using the full supplied value.

When to use it

Use this when the caller has read the current state and is authorised to change the documented fields or lifecycle state.

When not to use it

Do not use this to create an unrelated resource or bypass a purpose built transition, validation, or permission check operation.

Contract

Availability

Product version
Next Product release
Licence
An active Product licence is required except for health, authentication, and licence remediation operations.
Entitlements
workflow.enabled
Service roles
workflow
Deployment
customer managed installation
Feature state
preview

Security

Access

Sign in: Use a session cookie or Bearer session token.

Actor
Authenticated Pūnaha actor authorised for the selected tenant and resource
Permission
workflows.manage
Resource
workflow / update / example workflowid
Tenant rule
Tenant scoped unless the selected actor is performing an explicitly documented platform action. The x organization id header or authenticated session context selects the tenant. It does not grant access.
Explicit deny
An applicable explicit deny overrides an allow. Knowing or supplying a resource identifier never grants access.

Address, query and header fields

FieldLocationPresenceTypeMeaningLimits and example
x-request-idheaderOptionalstringOptional caller supplied correlation identifier. Pūnaha returns the effective value in the response header.Minimum length: 1. Maximum length: 200. Example: example request 001
workflowIdpathRequiredstringThe workflow id that identifies the resource selected by this operation.Minimum length: 1. Example: example workflowid

Request body

This operation does not define a request body.

Responses

StatusMeaning and correction boundaryBody
204The operation completed successfully and intentionally returns no body.No response body
400The operation failed with HTTP 400. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
401The operation failed with HTTP 401. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
402The operation failed with HTTP 402. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
403The operation failed with HTTP 403. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
404The operation failed with HTTP 404. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
409The operation failed with HTTP 409. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
423The operation failed with HTTP 423. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
500The operation failed with HTTP 500. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError
503The operation failed with HTTP 503. Inspect error.code and error.details, apply the documented correction, and retain x request id.application/json, APIError

Effects

Behaviour and other effects

Changes
Validates access and input, then applies the operation specific state change. A failed validation or authorisation check does not intentionally apply the requested change.
Audit events
workflow.starred
Background work
No background work is inferred. The success response represents completion of the HTTP action.
External effects
No external call is inferred from the route name. Operation specific service behaviour remains authoritative.
Transaction boundary
The HTTP success or error describes the synchronous boundary. Background operations have their own observable lifecycle and may outlive the request.

Operation

Reliability

Idempotent
Yes
Retry
A retry is normally safe only with the same resource, body, tenant, and concurrency preconditions. Confirm the first outcome when external effects are possible.
Concurrency
Use documented If Match or resource revision fields where exposed. Otherwise read current state before changing it and handle HTTP 409 conflicts.
Consistency
The response reflects the synchronous operation boundary. Background and provider backed state can converge later and must be read through its status operation.
Timeout
Client timeouts do not cancel completed or already started server work unless the operation explicitly supports cancellation.
Request ID
Send or record x request id and retain the returned value for diagnosis.

Errors and corrections

StatusCodeCauseCorrectionRetryablePartial work
400INVALID_REQUEST_BODYThe request body or supplied field values are invalid.Correct the named field or rule in error.details, then submit a new request. Retrying an unchanged request will not help.No unchanged retryNo requested mutation is expected before this failure boundary.
401AUTHENTICATION_REQUIREDA valid authenticated session or supported token is required.Authenticate again using a supported mechanism and confirm that the credential is current.No unchanged retryNo requested mutation is expected before this failure boundary.
402FEATURE_NOT_LICENSEDThe active licence does not include a required entitlement.Use an operation covered by the active entitlement or ask the System Owner to review the signed licence.No unchanged retryNo requested mutation is expected before this failure boundary.
403PERMISSION_REQUIREDThe authenticated actor does not have the exact permission or resource action.Select the correct tenant and resource, then ask an authorised administrator to grant the exact documented action if appropriate.No unchanged retryNo requested mutation is expected before this failure boundary.
404NOT_FOUNDThe selected resource does not exist in the authorised scope.Obtain the identifier from the related list or create operation and confirm the selected tenant.No unchanged retryNo requested mutation is expected before this failure boundary.
409STATE_CONFLICTCurrent resource state or a dependency prevents the requested change.Read current state, resolve the named dependency or lifecycle conflict, and submit a deliberate new request.No unchanged retryThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.
423LICENCE_REMEDIATION_REQUIREDThe installation is restricted and permits only licence remediation actions.Complete the indicated licence or membership remediation before retrying Product work.No unchanged retryThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.
500INTERNAL_ERRORPūnaha could not complete the operation because of an unexpected internal failure.Retain x request id and the stable error code, avoid blind retries, and investigate the operation or contact support. Code: INTERNAL_ERROR.No unchanged retryThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.
503DEPENDENCY_UNAVAILABLEA required node, database, provider, or service is temporarily unavailable.Retain x request id, check health and the named dependency, then retry with bounded backoff when safe.Yes, with the documented safeguardsThe caller must read current resource or background operation state before retrying because work may have started before the failure became observable.

Code examples

Use a supported credential and synthetic data. Do not disable TLS checks or retry a request that changes state blindly.

cURL example
curl --request PUT "$PUNAHA_URL/api/workflows/example-workflowid/star" \
  --header "Authorization: Bearer $PUNAHA_TOKEN" \
  --header "x-request-id: example-request-001"

Version history

  • Next Product release: Operation documented from the current registered Go route and handler contract.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot