# Modify a routing payload Updates a routing payload within a Draft profile. The request fully replaces the payload. ## Endpoint `PUT /bsp/api/v1/bmp/browser_router/{profile_id}/router_payloads/{payload_id}` ## Request URL `https://{server-hostname}:8383/bsp/api/v1/bmp/browser_router/{profile_id}/router_payloads/{payload_id}` ## Scope `BrowserManager.UPDATE` ## Header `Authorization: d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Request Headers - **Content-Type** (`string`, Mandatory): `application/json` - **Accept** (`string`, Mandatory): `application/json` ### Path Parameters - **payload_id** (`string`, Mandatory): Router Payload ID from [Get Browser Router Profile](https://www.manageengine.com/products/desktop-central/help/api/onpremise/browser-router-get-browser-router-profile.html) response (`config_data_item_id` field) - **profile_id** (`string`, Mandatory): Browser Router Profile ID from [List Browser Router Profiles](https://www.manageengine.com/products/desktop-central/help/api/onpremise/browser-router-list-browser-router-profiles.html) response (`profile_id` field) ### Request Body JSON body with a `router_payloads` object containing the updated routing rule. Provide the full payload configuration URLs, groups, browser mode, and target browser. This replaces the existing payload configuration entirely. `application/json` - `JSON Object`: Routing payload. Pick a target browser from the dropdown. - **router_payloads** (Optional): Browser-specific routing rule ## Examples ### Chrome #### Sample Request ```curl curl --request PUT \ --url https://appdomain/bsp/api/v1/bmp/browser_router/{profile_id}/router_payloads/{payload_id} \ --header 'Accept: application/json' \ --header 'Authorization: d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{"router_payloads":{"urls":[{"webdomain_ids":["21"],"doc_type":""}],"groups":[{"ids":["313"],"doc_type":""}],"intranet_zone":false,"open_in":"chrome"}}' ``` #### Sample Request Body - Chrome Redirect payload to Google Chrome. `open_in`: target browser, set to `chrome`. `urls.webdomain_ids`: array of pre-created webdomain IDs to route. `urls.doc_type`: IE document compatibility mode, set to empty string as IE mode is not applicable for Chrome. `groups.ids`: array of pre-created webdomain group IDs to route. `groups.doc_type`: IE document compatibility mode for the group, set to empty string. `intranet_zone`: whether to include local intranet zone sites in this rule. This replaces the entire payload configuration. ```json { "router_payloads": { "urls": [ { "webdomain_ids": [ "21" ], "doc_type": "" } ], "groups": [ { "ids": [ "313" ], "doc_type": "" } ], "intranet_zone": false, "open_in": "chrome" } } ``` ## Response Parameters ### HTTP Code 200 #### Response Body — application/json - `JSON Object` - **payloads** (`JSON Array`): Modified payload configurations with routing details ### HTTP Code 400 #### Response Body — application/json - `JSON Object` - **error_description** (`string`): Name of the duplicate webdomain or group already assigned to another payload - **error_code** (`string`): Error code for duplicate webdomain/group assignment ### HTTP Code 401 #### Response Body — application/json - `JSON Object` - **errorCode** (`long`): Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required) - **errorMsg** (`string`): Authentication failure reason ### HTTP Code 403 #### Response Body — application/json - `JSON Object` - **errorCode** (`long`): Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin) - **errorMsg** (`string`): Message indicating insufficient privileges to access this resource ### HTTP Code 404 #### Response Body — application/json - `JSON Object` - **error_description** (`string`): Message indicating the specified profile or payload was not found ### HTTP Code 409 #### Response Body — application/json - `JSON Object` - **error_description** (`string`): Message indicating published profiles cannot be modified ### HTTP Code 429 #### Response Body — application/json - `JSON Object` - **errorCode** (`long`): Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes - **errorMsg** (`string`): Rate limit exceeded message with retry guidance ### HTTP Code 500 #### Response Body — application/json - `JSON Object` - **error_description** (`string`): Message describing the server-side failure - **error_code** (`string`): Internal server error code ## Possible Response Codes - `200` — HTTP code - `400` — HTTP code - `401` — HTTP code - `403` — HTTP code - `404` — HTTP code - `409` — HTTP code - `429` — HTTP code - `500` — HTTP code ## Response Examples ### Sample Response: HTTP 400 Duplicate webdomain ```json { "error_description": "example.com", "error_code": "BSP_BR0001" } ``` ### Sample Response: HTTP 401 Unauthorized ```json { "errorCode": "UNAUTHORIZED", "errorMsg": "You are not authorized to perform this action" } ``` ### Sample Response: HTTP 403 Forbidden ```json { "errorCode": "FORBIDDEN", "errorMsg": "You do not have permission to access this resource" } ``` ### Sample Response: HTTP 404 Not found ```json { "error_description": "Profile not found" } ``` ### Sample Response: HTTP 409 Profile is published ```json { "error_description": "Cannot modify a published profile" } ``` ### Sample Response: HTTP 429 Rate limit exceeded ```json { "errorCode": "RATE_LIMIT_EXCEEDED", "errorMsg": "You have exceeded the maximum number of API calls. Please try again later." } ``` ### Sample Response: HTTP 500 Server error ```json { "error_description": "Internal Server error, Please try again in a moment.", "error_code": "COM0004" } ``` ## Rate Limits ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 60 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.