# Modify risk score blocklist rules

Modifies risk score blocklist rules.

Endpoint: PUT /risk-score-rules/blocklists
Version: latest
Security: SecretApiKey, JWT

## Security:

  - `SecretApiKey` (unknown)
    apiKey in header REB-APIKEY

  - `JWT` (unknown)
    http bearer JWT

## Request body:

  - `application/json` (unknown)
    Risk score blocklist rules.

## Request fields (application/json):

  - `permanentlyBlockList` (object | null)
    Items permanently blocklisted when TTL is equal to `0`.

  - `permanentlyBlockList.address` (object)
    Rule that permanently blocklists items when TTL is equal to `0`.

  - `permanentlyBlockList.address.riskScoreThreshold` (integer, required)
    Pass and fail threshold for the blocklist.

  - `temporaryBlockList` (object | null)
    Items temporarily blocklisted when TTL is greater than `0`.

  - `temporaryBlockList.address` (object)
    Items temporarily blocklisted when TTL is greater than `0`.

  - `temporaryBlockList.address.riskScoreThreshold` (integer, required)
    Pass and fail threshold for the blocklist.

  - `temporaryBlockList.address.ttl` (integer, required)
    Amount of seconds a blocklist exists before it expires.
This value must be greater than 0.

## Response 200:

  - `200` (unknown)
    Risk score blocklist rules set.

## Response 200 fields (application/json):

  - `permanentlyBlockList` (object | null)
    Items permanently blocklisted when TTL is equal to `0`.

  - `permanentlyBlockList.address` (object)
    Rule that permanently blocklists items when TTL is equal to `0`.

  - `permanentlyBlockList.address.riskScoreThreshold` (integer, required)
    Pass and fail threshold for the blocklist.

  - `temporaryBlockList` (object | null)
    Items temporarily blocklisted when TTL is greater than `0`.

  - `temporaryBlockList.address` (object)
    Items temporarily blocklisted when TTL is greater than `0`.

  - `temporaryBlockList.address.riskScoreThreshold` (integer, required)
    Pass and fail threshold for the blocklist.

  - `temporaryBlockList.address.ttl` (integer, required)
    Amount of seconds a blocklist exists before it expires.
This value must be greater than 0.

## Response 200 headers (application/json):

  - `X-RateLimit-Limit` (integer)
    Total number of rate limit tokens for this request within a rate limit period.
For more information, see [Rate limits](#section/Rate-limits).
    Example: 3600

  - `X-RateLimit-Remaining` (integer)
    Remaining number of rate limit tokens for this request within the rate limit period. 
For example, in the sandbox environment, rate limits for non-GET endpoints are set at 3000 requests per 10 minutes.
    Example: 3600

## Response 201:

  - `201` (unknown)
    Risk score blocklist rules set.

## Response 201 fields (application/json):

  - `permanentlyBlockList` (object | null)
    Items permanently blocklisted when TTL is equal to `0`.

  - `permanentlyBlockList.address` (object)
    Rule that permanently blocklists items when TTL is equal to `0`.

  - `permanentlyBlockList.address.riskScoreThreshold` (integer, required)
    Pass and fail threshold for the blocklist.

  - `temporaryBlockList` (object | null)
    Items temporarily blocklisted when TTL is greater than `0`.

  - `temporaryBlockList.address` (object)
    Items temporarily blocklisted when TTL is greater than `0`.

  - `temporaryBlockList.address.riskScoreThreshold` (integer, required)
    Pass and fail threshold for the blocklist.

  - `temporaryBlockList.address.ttl` (integer, required)
    Amount of seconds a blocklist exists before it expires.
This value must be greater than 0.

## Response 201 headers (application/json):

  - `Location` (string)
    Location of the related resource.
    Example: https://api.rebilly.com/example

  - `X-RateLimit-Limit` (integer)
    Total number of rate limit tokens for this request within a rate limit period.
For more information, see [Rate limits](#section/Rate-limits).
    Example: 3600

  - `X-RateLimit-Remaining` (integer)
    Remaining number of rate limit tokens for this request within the rate limit period. 
For example, in the sandbox environment, rate limits for non-GET endpoints are set at 3000 requests per 10 minutes.
    Example: 3600

## Response 401:

  - `401` (unknown)
    Unauthorized access.
Invalid credentials used.

## Response 401 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 403:

  - `403` (unknown)
    Access forbidden.

## Response 403 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 422:

  - `422` (unknown)
    Invalid data sent.

## Response 422 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

  - `invalidFields` (array)
    Invalid field details.
    Example: [{"field":"field1","message":"field1 is invalid"},{"field":"subObject.field2","message":"field2 is invalid"},{"field":"subObject.field2","message":"another error in the field2"}]

  - `invalidFields.field` (string)
    Name of the field.
Dot notation is used for nested object field names.

  - `invalidFields.message` (string)
    Message field.

## Response 429:

  - `429` (unknown)
    Request rate limit exceeded.

## Response 429 fields (application/json):

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".
    Example: about:blank

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.
    Example: Rate Limit Exceeded

  - `status` (integer)
    HTTP status code.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.
    Example: A request cannot be executed because the user has sent too many requests within a certain period of time

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 429 headers (application/json):

  - `X-RateLimit-Retry-After` (integer)
    UTC timestamp after which the rate limit resets and the request can be retried.
    Example: 1713187500

