/api/v6/urlshortener/links/{domain}/{code}Update a short link
Change the destination, the status or the expiry. Domain and code do not change.
Scope and limits
API key with the urlshortener service enabled and the urlshortener.write capability granted
35 requests per second
Changes the destination URL (longUrl, revalidated as on creation), the status (status) or the expiry (expiresAt). Send only what you want to change; at least one field is required. Domain and code cannot change: that would break every short URL already handed out. Editing is free.
Every change is recorded with the previous value, the new one and who made it (the API key or the portal user). A link blocked by Hablame (status: blocked) cannot be edited: it returns 409 LINK_BLOCKED.
Keys it does not recognize are ignored: a body like {"active": false} (from the previous contract) changes nothing and returns 400 NOTHING_TO_UPDATE. To disable, send {"status": "disabled"}.
Requires a key that can write
Besides the urlshortener service, the API key needs the urlshortener.write capability, which only an owner or an administrator of your organization can grant when creating the key. Without it, the key lists and reads links, statistics, the overview, the domains and the pricing, and gets 403 AUTH_CAPABILITY_NOT_ALLOWED here.
Path parameters
domaindomain. Compared in lowercase. It names the link that answers at that short URL today; for one on a domain that no longer belongs to your organization (domainStatus: released), add domainStatus=released.codeQuery parameters
domainStatusreleased, the link is the one on a domain that no longer belongs to your organization (the one the list returns with domainStatus: released), even if that name is today another domain with the same code. Without it, domain names the domain that has that name today. Any other value returns 400 VALIDATION_INVALID_PARAMETER.releasedRequest body
application/jsonlongUrlstatusdisabled stops redirecting right away (the visitor gets 404); active turns it back on.activedisabledexpiresAt-05:00). null or an empty string clears it.{
"status": "disabled"
}Responses
Link updated, as it ended up.
{
"success": true,
"data": {
"domain": "h0b.co",
"code": "a1b2c3d",
"shortUrl": "https://h0b.co/a1b2c3d",
"longUrl": "https://example.com/landing?utm_source=sms",
"isAlias": false,
"status": "active",
"domainStatus": "active",
"expiresAt": null,
"createdAt": "2026-09-23T15:04:05Z",
"clicks": 0,
"uniqueClicks": 0,
"firstClickAt": null,
"lastClickAt": null
},
"meta": {
"requestId": "8f0c0e2a4b1d4c8fae2b7a91e0c5d3f6",
"timestamp": "2026-09-23T18:30:00+00:00",
"responseTimeMs": 7.2
}
}Nothing to change was sent, a field has the wrong type, or a value is invalid.
Invalid or missing credentials.
The API key does not have the URL shortener enabled (or it is turned off for your organization), lacks the urlshortener.write capability to create and edit links, cannot be used from the request network, or the organization is not active.
No link of your organization with that domain and code (or it was deleted). A link from another organization also returns 404: its existence is not disclosed.
The link is blocked by Hablame and cannot be changed.
Request limit exceeded.
Possible errors
Codes this endpoint can return in error.code. The full detail lives in the catalog.
AUTH_REQUIREDNo Bearer token was sent, and every call requires one.401AUTH_INVALID_KEYThe API key is not recognized: wrong format, revoked or expired.403AUTH_SERVICE_NOT_ALLOWEDThe key is not allowed to use the service behind this endpoint.403AUTH_IP_NOT_ALLOWEDThe key only works from certain networks and your IP is not one of them.403ACCOUNT_NOT_ACTIVEYour organization is suspended or closed.403AUTH_CAPABILITY_NOT_ALLOWEDThe key has the service, but not the capability this endpoint requires.400NOTHING_TO_UPDATENo updatable fields were sent.400VALIDATION_INVALID_PARAMETERA parameter or a body field is not valid.400URL_INVALIDThe destination URL is malformed.400URL_SCHEME_NOT_ALLOWEDOnly http/https destinations are allowed.400URL_TOO_LONGThe destination URL exceeds the maximum length.400URL_BLOCKED_HOSTThe destination host is private or reserved.400EXPIRES_AT_INVALIDexpiresAt must be a future ISO date-time.404LINK_NOT_FOUNDNo link with that domain and code.409LINK_BLOCKEDThe link is blocked for security.429RATE_TPS_EXCEEDEDYou exceeded your organization quota for this endpoint.