ROOKDocs
PATCH

Update a monitoring case

ENDPOINT/v1/monitoring/cases/{case_id}

Applies a partial update to status, resolution, assignee, priority, or queue while the case is not CLOSED. Omitted fields are left unchanged. Closing requires status CLOSED and resolution. Closed cases reject this operation. This operation is program-scoped.

Authentication & Headers

HeaderTypeRequirementDescription
AuthorizationstringREQUIREDAPI key passed as an HTTP Bearer token: Bearer rk_live_...
X-Program-IDUUIDPROGRAM-SCOPEDProgram boundary UUID that scopes the issuing card, wallet, or transfer.
Content-TypestringREQUIREDMust be application/json.
Idempotency-KeystringOPTIONALUnique UUID to prevent duplicate execution of financial creations or mutations.

Path Parameters

ParameterTypeRequirementDescription
case_idstringREQUIREDUnique identifier of the monitoring case.

Request Body Schema

application/json
statusstring
optional

Lifecycle of a monitoring case. Allowed transitions: `OPEN` → `IN_REVIEW`, `ESCALATED`, `CLOSED`. `IN_REVIEW` → `OPEN`, `ESCALATED`, `CLOSED`. `ESCALATED` → `IN_REVIEW`, `CLOSED`. `CLOSED` is terminal. PATCH `status` to move the case. Closing requires `resolution`. Comments and files are accepted in every status except `CLOSED`.

Enum values:OPENIN_REVIEWESCALATEDCLOSED
resolutionany
optional

Outcome. Required when `status` is `CLOSED`. Ignored unless closing. Null is rejected on close.

assignee_idstringnulluuid
optional

Replacement operator. Null unassigns the case.

prioritystring
optional

Operator urgency of a monitoring case. Distinct from `risk_score`, which is the numeric signal that opened the case. `CRITICAL` is the highest.

Enum values:LOWMEDIUMHIGHCRITICAL
queue_idstringnulluuid
optional

Queue to move the case into. Null removes it from its queue.

Response Codes & Schemas

200The monitoring case after the update.
application/json
{
  "id": "4c7e2a19-8d3f-4b61-a5c0-1f6b9e0d4572",
  "object": "monitoring_case",
  "wallet_id": "4d8f2a10-6c3e-4b91-9e5a-2f7c8d1e0b44",
  "wallet_entity_id": "2e9c4b71-8a5d-4f03-b6e2-1c7d9a0f3e58",
  "queue_id": "6a8d1e30-5b2c-4f47-9d0e-3c4f5a6b7182",
  "assignee_id": "7b9e2f41-6c3d-4058-ae1f-4d5a6b7c8293",
  "status": "IN_REVIEW",
  "priority": "HIGH",
  "category": "FRAUD",
  "resolution": null,
  "trigger": {
    "type": "RULE",
    "rule_id": "8e4c1a92-2f70-4c45-9b3d-0a1e6f7c8290",
    "score": null
  },
  "transaction_ids": [
    "2b5f7a28-9c4d-4e01-a6f3-1d8e0b7c2354"
  ],
  "card_ids": [
    "0c4e8f16-2a7b-4d93-b5e1-8f3a6c9d0142"
  ],
  "risk_score": 82,
  "sla_due_at": "2026-08-28T16:20:00Z",
  "created_at": "2026-08-27T16:20:00Z",
  "updated_at": "2026-08-27T16:45:00Z"
}
400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "invalid_request",
    "message": "invalid order by: foo. Valid options are: [created_at updated_at]",
    "param": "order_by",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/invalid_request"
  }
}
401Unauthorized: missing, malformed, or unknown API key.
application/json
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_error",
    "message": "A valid API key is required.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/authentication_error"
  }
}
403Forbidden: the API key is denied by RBAC, or it cannot access this program. A resource that exists on another program or organization returns `404 not_found`, not `403`.
application/json
{
  "error": {
    "type": "permission_error",
    "code": "permission_denied",
    "message": "The API key cannot access this program.",
    "param": "X-Program-ID",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/permission_denied"
  }
}
404Not Found: unknown id, or the resource is not visible to this API key.
application/json
{
  "error": {
    "type": "not_found_error",
    "code": "not_found",
    "message": "No card found for the given id.",
    "param": "card_id",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/not_found"
  }
}
409Conflict: incompatible state, or Idempotency-Key reused with a different body.
application/json
{
  "error": {
    "type": "conflict_error",
    "code": "conflict",
    "message": "The card cannot be reissued from its current state.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/conflict"
  }
}
422Unprocessable Entity: the document is valid JSON but violates a business rule.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "insufficient_funds",
    "message": "The source financial account does not have enough available balance.",
    "param": "amount",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/insufficient_funds"
  }
}
429Too Many Requests: the API key exceeded its rate limit.
application/json
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/rate_limited"
  }
}
500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json
{
  "error": {
    "type": "api_error",
    "code": "internal_error",
    "message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/internal_error"
  }
}