> For the complete index of the 402pay docs, see [llms.txt](https://developer.402pay.co/llms.txt).

# Update a business

Change your business's name, website and emails, and turn alert emails on or off.

`PATCH https://dash.402pay.co/api/v1/businesses/{id}`

Send only what changes. It takes a person signed in to the dashboard, never an API key. You receive `business.updated` when the profile, as it comes back, changes.

A new `alert_email` doesn't take the alerts right away: it becomes `pending_alert_email` and gets a 6-digit code, and alerts keep going to `alert_email` until the code is [confirmed](https://developer.402pay.co/api/businesses/alert-email/confirm.md). Sending another address replaces the one waiting, with a new code. `null`, your own sign-in email and the address alerts already go to apply at once, and drop any address waiting.

### Path

- `id` (string, required): The business's ID, such as `biz_Nq4sT8vWx2Lm6Rb1`.

### Body

- `name` (string): 2 to 60 characters.
- `website` (string): An `https://` URL, or `null` to clear it.
- `support_email` (string): Shown on receipts so customers can reach you, or `null` to clear it.
- `alert_email` (string): Where payment alerts should go once its code is confirmed. `null` sends them to your sign-in email.
- `email_alerts` (boolean): Whether alert emails go out at all.
- `product_updates` (boolean): Whether 402pay emails you about new features.

### Errors

- 400 `invalid_request` A field is unknown or has a value it can't take, such as an `alert_email` that isn't an email address. `field` names it.
- 403 `session_required` An API key sent the request. Only a person signed in to the dashboard can send.
- 404 `not_found` You don't own a business with that ID.
- 429 `too_many_emails` You started 3 new alert addresses in the last hour, across all your businesses and counting ones since replaced or canceled, or the new `alert_email` has had as many emails as it can get for now, 5 an hour and 20 a day. Nothing in the request changed. `Retry-After` says when to try again.

Any request can also fail on its key or its body. See [errors](https://developer.402pay.co/api/errors.md).

Request, Browser:

```js
// On a dashboard page, whose session cookie the browser sends.
const response = await fetch("/api/v1/businesses/biz_Nq4sT8vWx2Lm6Rb1", {
  method: "PATCH",
  headers: {
    "402pay-Business": businessId,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    alert_email: "alerts@example.com"
  }),
});
const { data } = await response.json();
```

Response, 200 OK:

```json
{
  "data": {
    "id": "biz_Nq4sT8vWx2Lm6Rb1",
    "kind": "business",
    "name": "Acme Studio",
    "website": "https://example.com",
    "support_email": "billing@example.com",
    "alert_email": "payments@example.com",
    "pending_alert_email": "alerts@example.com",
    "status": "active",
    "suspended_at": null,
    "email_alerts": true,
    "product_updates": false,
    "created_at": "2026-05-09T21:18:42.216Z",
    "updated_at": "2026-09-24T10:02:51.338Z"
  }
}
```
