Shipeasy
APIOperations

Replace a gate's whitelist

Replaces the gate's whole whitelist with entries, creating the block if the gate didn't have one. Idempotent — the same call twice leaves the same list.

Replaces the gate's whole whitelist with entries, creating the block if the gate didn't have one. Idempotent — the same call twice leaves the same list.

This is the only whitelist call that can switch attr (emailuser_id) or clear the block: entries: [] removes the whitelist from the gate entirely.

Use cases
  • Pin an exact list{ "entries": ["alice@acme.dev", "bob@acme.dev"] }.
  • Switch to user ids{ "attr": "user_id", "entries": ["usr_123"] }.
  • Drop the whitelist{ "entries": [] }.
PUT
/api/admin/gates/{id}/whitelist

Authorization

bearerSdkKey
AuthorizationBearer <token>

Pass an admin SDK key as Authorization: Bearer sdk_admin_…. Mint via POST /api/admin/keys with type: "admin".

In: header

Path Parameters

id*string

Stable opaque gate id (gate_…) or the gate's name.

Length1 <= length <= 128

Header Parameters

X-Project-Id?string

Project the request operates on. Optional — defaults to the project the SDK key belongs to; pass it only to scope a multi-project key (the generated client sets it once from its configuration, so per-call callers never thread it).

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PUT "https://shipeasy.ai/api/admin/gates/string/whitelist" \  -H "Content-Type: application/json" \  -d '{    "entries": [      "alice@acme.dev",      "bob@acme.dev"    ]  }'
{
  "id": "gate_01j7w8a1b2c3d4e5f6g7h8i9j0",
  "name": "new_checkout",
  "attr": "email",
  "entries": [
    "alice@acme.dev",
    "bob@acme.dev"
  ]
}
{
  "error": "Malformed request (bad JSON, missing project scope).",
  "code": "BAD_REQUEST"
}
{
  "error": "Missing or invalid admin SDK key.",
  "code": "UNAUTHORIZED"
}

{
  "error": "Key is valid but not allowed to act on this project.",
  "code": "FORBIDDEN"
}

{
  "error": "The resource does not exist or is not visible to the caller.",
  "code": "NOT_FOUND"
}

{
  "error": "A resource with this name already exists in the project.",
  "code": "ALREADY_EXISTS"
}

{
  "error": "The request body failed structural (schema) validation.",
  "code": "VALIDATION"
}

Was this page helpful?
Updated August 8, 2026