> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a form

> PATCH /forms/{form_id}/

Updates a form's name, field schema, or theme settings.

<Note>
  Requires a Management API key with `MANAGEMENT_API` (or `MANAGEMENT_API_SANDBOX`) quota, and the `LEAD_GENERATION_CAN_EDIT` permission, sent as the raw `Authorization` header value — see the [Management API overview](/api-reference/management-api/overview).
</Note>

```
PUT   https://api.scanova.io/forms/{form_id}/
PATCH https://api.scanova.io/forms/{form_id}/
```

<ParamField path="form_id" type="string" required>
  The form's `form_id`. Immutable — it cannot be changed via this endpoint.
</ParamField>

<ParamField body="name" type="string">
  Form name.
</ParamField>

<ParamField body="data" type="object">
  The form's field schema — re-validated against Scanova's form-builder JSON schema on every update. Malformed data returns `400` under `data`.
</ParamField>

<ParamField body="theme_id" type="integer">
  An active theme's ID to style the form's public page.
</ParamField>

<ParamField body="theme_overrides" type="object">
  Partial theme token overrides layered on top of `theme_id` (or the default theme).
</ParamField>

<RequestExample>
  ```bash cURL theme={null}
  curl --request PATCH \
    --url 'https://api.scanova.io/forms/F8a9b0c1d2e3f4g5h/' \
    --header 'Authorization: YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{ "name": "Trade Show Booth Signup" }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "id": 376,
    "form_id": "F8a9b0c1d2e3f4g5h",
    "name": "Trade Show Booth Signup",
    "created_by": "Docs",
    "created": "2026-08-16T20:46:12.554000+05:30",
    "form_url": "https://new.scnv.io/form/F8a9b0c1d2e3f4g5h",
    "is_active": true,
    "usage_count": 1,
    "linked_qrs": [],
    "entries_count": 3,
    "conversion": 12.5,
    "modified": "2026-09-08T10:12:00.000000+05:30",
    "data": {
      "fields": [
        { "type": "text", "label": "Full name", "required": true },
        { "type": "email", "label": "Email", "required": true }
      ]
    },
    "theme_id": null,
    "theme_config": {},
    "theme_overrides": null
  }
  ```
</ResponseExample>

Both `PUT` and `PATCH` are supported. This endpoint does not accept `qr_id`/`qr_ids` — use [Link QR Codes to a form](/api-reference/management-api/forms/link-qrs) to change which QR Codes are attached. `404` if `form_id` isn't owned by this account.

## Related

* [Retrieve a form](/api-reference/management-api/forms/retrieve) — view current values before updating.
* [Link QR Codes to a form](/api-reference/management-api/forms/link-qrs) — change the linked QR Codes.
* [Delete a form](/api-reference/management-api/forms/delete) — remove it permanently.
* [Management API overview](/api-reference/management-api/overview) — the auth scheme and quota architecture this endpoint is part of.


## OpenAPI

````yaml api-reference/openapi/management-api.json PATCH /forms/{form_id}/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    api.scanova.io (QR codes, folders, tags, leads, forms, analytics, plans,
    shared users & roles), plus the token-creation and usage-stats endpoints
    used to authenticate against it. Every path and request/response shape below
    was verified live against a real API key and the actual running backend
    (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://api.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /forms/{form_id}/:
    patch:
      summary: Update a form
      operationId: partialUpdateManagedForm
      responses:
        '200':
          description: Form updated.
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. api.scanova.io) — the same key sent to the
        regular API host will not authenticate.

````