Update website
PUT https://datafa.st/api/v1/admin/websites/{websiteId}Update website settings such as name, timezone, currency, KPI, tracking rules, and notification preferences. Send only the fields you want to change.
Viewers cannot write. Members can update most settings; team management remains owner-only.
Request
Path parameters
websiteIdstring
Body parameters
domainstring
Tracked domain without
https://. Example: "example.com". Must pass DataFast domain validation.namestring|null
Name shown in the dashboard. Example:
"My SaaS". Optional on create.timezonestring
Timezone used to interpret dates and group analytics buckets. Defaults to the website timezone. IANA timezone for dashboard periods and API date grouping. Examples:
"America/New_York", "Europe/Paris", "UTC".currencystring
ISO 4217 currency for revenue. Example:
"USD", "EUR".kpistring
Goal name used as the dashboard KPI card. Must match a tracked goal. Example:
"signup". List names via List tracked goals.kpiColorSchemestring
Dashboard KPI card color. Example:
"orange", "blue".revenueMetricstring
How revenue is summarized. Example:
"revenue" or "mrr" when supported.sendWeeklyReportsboolean
true to email weekly analytics summaries.sendViralTrafficAlertsboolean
true to notify on traffic spikes.isPublicDashboardEnabledboolean
true to enable a shareable public dashboard link.isPublicDataEnabledboolean
true to expose metrics on public dashboards/widgets.isCookielessboolean
true for cookieless tracking mode. See script configuration.isAttackModeEnabledboolean
true to enable attack-mode bot filtering.includeRenewalRevenueboolean
true to count renewal revenue in KPI totals.allowedHostnamesstring[]
Hostnames allowed to send events. Example:
["example.com", "www.example.com"].isAllHostnamesAllowedboolean
true to accept events from any hostname.excludedIpsstring[]
IPs excluded from tracking. Example:
["203.0.113.10"].excludedPathsstring[]
URL paths excluded from tracking. Example:
["/admin", "/preview"].excludedCountriesstring[]
Country names or codes excluded from tracking.
excludedHostnamesstring[]
Hostnames excluded from tracking.
Example request body
Send only fields you want to change:
{
"name": "Renamed product",
"timezone": "Europe/Paris",
"currency": "EUR",
"kpi": "signup",
"includeRenewalRevenue": true,
"excludedPaths": ["/admin", "/preview"]
}
Response
Returns a JSON object with
status: "success" and endpoint-specific fields in data.Response fields
data[]._idstring
Website ObjectId.
data[].domainstring
Website domain.
data[].namestring|null
Human-readable name for the resource or event. The exact meaning depends on the endpoint.
data[].logostring|null
Website logo URL.
data[].trackingIdstring
Script tracking ID.
data[].timezonestring
Timezone used to interpret dates and group analytics buckets. Defaults to the website timezone.
data[].currencystring
Currency code for money values, such as
USD or EUR.data[].kpistring|null
Configured KPI goal or metric.
data[].kpiColorSchemestring|null
KPI color scheme.
data[].revenueMetricstring|null
Revenue metric preference.
data[].isCookielessboolean
Whether cookieless tracking is enabled.
data[].isAttackModeEnabledboolean
Whether attack-mode bot filtering is enabled.
data[].includeRenewalRevenueboolean
Whether renewal revenue is included in KPI calculations.
data[].allowedHostnamesstring[]
Allowed hostnames.
data[].isAllHostnamesAllowedboolean
Whether events from every hostname are accepted.
data[].excludedIpsstring[]
Excluded IPs.
data[].excludedPathsstring[]
Excluded paths.
data[].excludedCountriesstring[]
Excluded countries.
data[].excludedHostnamesstring[]
Excluded hostnames.
data[].createdAtstring
Website creation timestamp.
Authentication
Use a
dft_ account token with settings:write.A
df_ website API key for the same website can also call this route when the path websiteId matches the key's website. Write access with a df_ key is capped at member level — owner-only actions such as team management require a dft_ token and owner role.Errors
400 — No valid fields in body or invalid domain.
403 — Viewer role or website access denied.
See API errors for the standard error envelope, auth failures, validation errors, permission errors, and rate limits.