Updates the content of one non-deleted message and returns the full message. Edits are allowed only during the 5-minute grace period after message creation. Visitor callers can access only their own conversations and can edit only visitor messages they authored. The endpoint sanitizes the content, preserves up to 20 prior versions in edit history, refreshes search indexing, publishes a `message_edited` realtime event, and fires a `message.updated` webhook. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `conversations:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Editing records a revision and publishes the route's documented realtime update; callers should not assume that repeating an edit creates no additional revision metadata. Retry behavior: Repeating the same request converges on the same resource state, but a retry may return a conflict or not-found response after the first request succeeds.
/api/conversations/{id}/messages/{messageId}Organization API key supplied as Authorization: Bearer convor_sk_....
In: header
application/json
TypeScript Definitions
Use the request body type in TypeScript.
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
{
"id": "7f1f4d83-0a0e-4f34-9c4b-9a98d6e1c2ab",
"orgId": "8a8f4d83-0a0e-4f34-9c4b-9a98d6e1c2ab",
"conversationId": "9f1f4d83-0a0e-4f34-9c4b-9a98d6e1c2ab",
"senderType": "visitor",
"senderId": "550e8400-e29b-41d4-a716-446655440000",
"content": "Updated message text",
"type": "text",
"metadata": {},
"isRead": false,
"isEdited": true,
"editedAt": "2026-06-23T08:05:00.000Z",
"createdAt": "2026-06-23T08:00:00.000Z",
"deletedAt": null,
"replyToId": null,
"mentions": null,
"searchVector": "'updated':1 'message':2 'text':3"
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}curl --request PATCH \
'https://api.convor.io/api/conversations/11111111-1111-4111-8111-111111111111/messages/33333333-3333-4333-8333-333333333333' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer convor_sk_...' \
--header 'Content-Type: application/json' \
--data '{
"content": "Updated message text"
}'const response = await fetch("https://api.convor.io/api/conversations/11111111-1111-4111-8111-111111111111/messages/33333333-3333-4333-8333-333333333333", {
method: "PATCH",
headers: {
"Accept": "application/json",
"Authorization": "Bearer convor_sk_...",
"Content-Type": "application/json"
},
body: JSON.stringify({
"content": "Updated message text"
}),
});
const contentType = response.headers.get("content-type") ?? "";
const data = response.status === 204
? null
: contentType.includes("json")
? await response.json()
: contentType.startsWith("text/")
? await response.text()
: await response.blob();
if (!response.ok) {
const message = typeof data === "object" && data !== null
&& "error" in data && typeof data.error === "object"
&& data.error !== null && "message" in data.error
? String(data.error.message)
: "Convor API request failed (" + response.status + ")";
throw new Error(message);
}
console.log(data);Was this page helpful?
Delete an internal note
Deletes one internal note from the current organization. For administrator sessions, the endpoint preserves author ownership checks. A scoped organization API key may delete any note owned by the authenticated organization and path conversation. A successful changed-row delete returns a simple success flag, then publishes an operator-only invalidation and audit event after commit. Access requires an active organization administrator session or an organization API key with the `conversations:write` scope. API-key calls also require the automation API module. Data is isolated to the authenticated organization; identifiers from another organization or site are not disclosed.
Get a single message
Returns one message from a conversation in the current organization. Visitor callers can fetch messages only from their own conversations. The response includes full message metadata such as edit flags, reply links, mentions, and timestamps. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `conversations:read` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Retry behavior: This read-only operation is safe to retry.