> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firma.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Comprehensive Template Update

> Comprehensive update of template including properties, users, fields, and reminders. Supports user deletion with field reassignment or deletion. All sections are optional but at least one must be provided.



## OpenAPI

````yaml api-reference/v01.01.00/openapi-v01.01.00.json put /templates/{id}
openapi: 3.0.3
info:
  title: Firma Partner API
  description: >-
    RESTful API for document signing and template management.


    **Authentication**: All endpoints require API key authentication via the
    `Authorization` header. Use your API key directly without any prefix (e.g.,
    `your-api-key`). The Bearer prefix is optional but not required.


    **Security Features**:

    - Input validation using Zod schemas with detailed field-level error
    messages

    - RSA-256 signed JWT tokens for embedded template access


    **Rate Limiting**: Rate limits are tiered based on operation type:

    - Read operations (GET): 200 requests per minute

    - Write operations (POST/PUT/PATCH/DELETE): 120 requests per minute

    - Webhook CRUD operations: 60 requests per minute

    - Webhook test: 10 requests per minute

    - API key regeneration/expiration: 1 request per minute

    - Webhook secret rotation: 1 request per minute


    When rate limits are exceeded, the API returns a `429 Too Many Requests`
    response with headers:

    - `X-RateLimit-Limit`: Maximum requests per minute for this endpoint

    - `X-RateLimit-Remaining`: Requests remaining in current window

    - `X-RateLimit-Reset`: Unix timestamp when limit resets

    - `Retry-After`: Seconds until retry is allowed


    **Error Handling**: All errors return structured JSON responses with `error`
    (human-readable message), `code` (machine-readable identifier), and
    `details` (field-level validation errors when applicable).


    **Embedded Template Integration**: The Firma Template Editor can be embedded
    in your application using a standalone JavaScript library.


    ```html

    <!-- Load the Firma Template Editor library -->

    <script
    src="https://api.firma.dev/functions/v1/embed-proxy/template-editor.js"></script>


    <script>

    // Generate JWT token via API first

    fetch('https://api.firma.dev/functions/v1/signing-request-api/generate-template-token',
    {
      method: 'POST',
      headers: {
        'Authorization': 'YOUR_API_KEY',
        'Content-Type': 'application/json'
      },
      body: JSON.stringify({
        companies_workspaces_templates_id: 'template-id'
      })
    })

    .then(res => res.json())

    .then(data => {
      // Initialize editor with JWT token
      window.FirmaTemplateEditor.init({
        container: '#firma-editor-container',
        jwt: data.token,
        templateId: 'template-id',
        theme: 'dark',
        readOnly: false,
        onSave: (savedData) => {
          console.log('Template saved:', savedData);
        },
        onError: (error) => {
          console.error('Editor error:', error);
        },
        onLoad: (template) => {
          console.log('Template loaded:', template);
        }
      });
    });

    ```
  version: 01.01.00
  contact:
    name: API Support
    url: https://firma.com/support
servers:
  - url: https://api.firma.dev/functions/v1/signing-request-api
    description: Production API - Recommended (Current)
  - url: https://api.firma.dev/api/v1
    description: Production API - Planned
security:
  - ApiKeyAuth: []
tags:
  - name: Company
    description: Company information and settings
  - name: Workspaces
    description: Workspace management operations
  - name: Templates
    description: Template management operations
  - name: Signing Requests
    description: Document signing request operations
  - name: Custom Fields
    description: >-
      Custom field definition management for workspaces, templates, and signing
      requests
  - name: Webhooks
    description: Webhook configuration and management
  - name: JWT Management
    description: JWT token generation and revocation for embedded templates
  - name: Workspace Settings
    description: Workspace configuration and settings
  - name: Legacy
    description: Deprecated endpoints maintained for backward compatibility
paths:
  /templates/{id}:
    put:
      tags:
        - Templates
      summary: Comprehensive Template Update
      description: >-
        Comprehensive update of template including properties, users, fields,
        and reminders. Supports user deletion with field reassignment or
        deletion. All sections are optional but at least one must be provided.
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                template_properties:
                  type: object
                  description: Update template metadata and settings
                  properties:
                    name:
                      type: string
                      maxLength: 255
                    description:
                      type: string
                    document:
                      type: string
                      format: byte
                      description: >-
                        Base64-encoded PDF to replace document. Maximum size:
                        20MB
                    expiration_hours:
                      type: integer
                      minimum: 1
                    settings:
                      type: object
                      properties:
                        allow_editing_before_sending:
                          type: boolean
                        attach_pdf_on_finish:
                          type: boolean
                        allow_download:
                          type: boolean
                users:
                  type: array
                  description: Upsert users (include id to update, omit to create)
                  items:
                    type: object
                    required:
                      - first_name
                      - email
                      - designation
                      - order
                    properties:
                      id:
                        type: string
                        format: uuid
                        description: Omit for new users
                      first_name:
                        type: string
                      last_name:
                        type: string
                        description: >-
                          Optional, but required if using full_name or last_name
                          prefilled variables
                      email:
                        type: string
                        format: email
                      designation:
                        type: string
                        enum:
                          - Signer
                      order:
                        type: integer
                        minimum: 1
                      phone_number:
                        type: string
                      street_address:
                        type: string
                      city:
                        type: string
                      state_province:
                        type: string
                      postal_code:
                        type: string
                      country:
                        type: string
                      title:
                        type: string
                      company:
                        type: string
                deleted_users:
                  type: array
                  description: Users to delete with field handling strategy
                  items:
                    type: object
                    required:
                      - user_id
                      - field_action
                    properties:
                      user_id:
                        type: string
                        format: uuid
                      field_action:
                        type: string
                        enum:
                          - delete
                          - reassign
                        description: What to do with fields assigned to this user
                      reassign_to_user_id:
                        type: string
                        format: uuid
                        description: >-
                          Required when field_action is 'reassign'. Target user
                          must have same designation.
                fields:
                  type: array
                  description: Upsert fields (include id to update, omit to create)
                  items:
                    type: object
                    required:
                      - type
                      - x
                      - 'y'
                      - width
                      - height
                      - page
                    properties:
                      id:
                        type: string
                        format: uuid
                        description: Omit for new fields
                      type:
                        type: string
                        enum:
                          - signature
                          - text
                          - date
                          - checkbox
                          - dropdown
                      x:
                        type: number
                        minimum: 0
                        maximum: 100
                        description: X position as percentage
                      'y':
                        type: number
                        minimum: 0
                        maximum: 100
                        description: Y position as percentage
                      width:
                        type: number
                        minimum: 0
                        maximum: 100
                      height:
                        type: number
                        minimum: 0
                        maximum: 100
                      page:
                        type: integer
                        minimum: 1
                      required:
                        type: boolean
                        default: false
                      assigned_to_user_id:
                        type: string
                        format: uuid
                      options:
                        type: array
                        items:
                          type: string
                        description: For dropdown fields
                      default_to_signing_date:
                        type: boolean
                        description: For date fields
                      multi_group_id:
                        type: string
                        format: uuid
                      variable_name:
                        type: string
                reminders:
                  type: array
                  description: Upsert reminders (include id to update, omit to create)
                  items:
                    type: object
                    required:
                      - hours
                      - subject
                      - message
                    properties:
                      id:
                        type: string
                        format: uuid
                        description: Omit for new reminders
                      hours:
                        type: integer
                        minimum: 1
                        description: Hours after sending before reminder
                      all_users:
                        type: boolean
                        default: false
                      user_id:
                        type: string
                        format: uuid
                        description: Required if all_users is false
                      subject:
                        type: string
                        maxLength: 255
                      message:
                        type: string
                        maxLength: 5000
      responses:
        '200':
          description: >-
            Template updated successfully. Returns full template with all
            relationships.
          headers:
            X-RateLimit-Limit:
              schema:
                type: integer
              description: 'Rate limit: 120 requests per minute'
            X-RateLimit-Remaining:
              schema:
                type: integer
            X-RateLimit-Reset:
              schema:
                type: integer
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Template'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '404':
          $ref: '#/components/responses/NotFoundError'
        '429':
          $ref: '#/components/responses/RateLimitError'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    Template:
      type: object
      properties:
        id:
          type: string
          format: uuid
          description: Unique identifier for the template
        name:
          type: string
          description: Template name
          maxLength: 255
        description:
          type: string
          description: Template description
          nullable: true
        document_url:
          type: string
          format: uri
          description: >-
            Pre-signed URL to the PDF document. This is a time-limited signed
            URL for secure access - see document_url_expires_at for expiration
            time. Initial URLs are valid for 7 days; refreshed URLs are valid
            for 1 hour. Request a new template retrieval to get a fresh URL if
            expired.
        document_url_expires_at:
          type: string
          format: date-time
          nullable: true
          description: >-
            ISO 8601 timestamp when the document_url will expire. After this
            time, the URL will return an access denied error. Fetch the template
            again to receive a fresh signed URL.
        date_created:
          type: string
          format: date-time
          description: Template creation timestamp
        date_changed:
          type: string
          format: date-time
          description: Template last update timestamp
    Error:
      type: object
      properties:
        error:
          type: string
          description: Human-readable error message
        message:
          type: string
          description: Detailed error description
        details:
          type: object
          description: Additional error details
          additionalProperties: true
  responses:
    ValidationError:
      description: Bad Request - Validation failed
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: Validation Error
            message: Invalid input data
            details:
              name: Name is required
              email: Invalid email format
    UnauthorizedError:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: Unauthorized
            message: Invalid API key
    NotFoundError:
      description: Not Found - Resource does not exist
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: Not Found
            message: The requested resource was not found
    RateLimitError:
      description: Too Many Requests - Rate limit exceeded
      headers:
        X-RateLimit-Limit:
          schema:
            type: integer
          description: Maximum requests per minute
        X-RateLimit-Remaining:
          schema:
            type: integer
          description: Requests remaining
        X-RateLimit-Reset:
          schema:
            type: integer
          description: Unix timestamp of reset
        Retry-After:
          schema:
            type: integer
          description: Seconds until retry allowed
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: Rate Limit Exceeded
            message: Too many requests. Please wait before retrying.
            details:
              retry_after: 45
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        API key for authentication. Use your API key directly without any prefix
        (e.g., 'your-api-key'). Bearer prefix is optional but not required.

````