> ## Documentation Index
> Fetch the complete documentation index at: https://docs.goodgrants.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update an attachment field

> Updates an attachment field for the attachment identified by the specified token.



## OpenAPI

````yaml /api-reference/openapi-v2_3.yaml put /attachment/{token}/update-field/{field_slug}
openapi: 3.1.0
info:
  title: Good Grants API
  version: '2.3'
  description: >
    The Good Grants API enables you to programmatically manage grant-making
    programs, funding cycles, and application workflows.


    Use this API to:

    - Create and manage grant applications and submissions

    - Automate review workflows and scoring assignments

    - Track grant payments and fund allocations

    - Generate compliance reports and analytics

    - Integrate with external systems via webhooks


    All API requests require authentication using an API key provided in the
    `X-Api-Key` header.
  license:
    name: Creative Force Client Subscription Terms
    url: https://creativeforce.team/agreement/
servers:
  - url: https://api.us.cr4ce.com
    description: US regional endpoint
  - url: https://api.eu.cr4ce.com
    description: EU regional endpoint
  - url: https://api.au.cr4ce.com
    description: Australasia regional endpoint
  - url: https://api.ca.cr4ce.com
    description: Canada regional endpoint
  - url: https://api.hk.cr4ce.com
    description: Hong Kong regional endpoint
security:
  - ApiKeyAuth: []
tags:
  - name: Account
    description: >-
      Use this operation to retrieve information about your organization
      account.

      The account resource provides metadata about the tenant associated with
      your API key.


      Note: Account information is read-only and contains organization-level
      settings and identifiers.
  - name: Action tasks
    description: >-
      Use these operations to manage individual review and evaluation
      activities.

      Action tasks represent specific actions that reviewers or administrators
      need to complete during the evaluation process.


      Tasks track timestamps, decisions, and reviewer associations.

      Action tasks integrate with the broader review workflow and status
      tracking.
  - name: Allocation payments
    description: >-
      Use these operations to manage individual payments made against grant
      allocations.

      Allocation payments represent installments or disbursements of awarded
      funds.


      Payments track scheduling, status (pending, paid, cancelled), and amounts.

      Comments can be added to payments for grantee communication and
      record-keeping purposes.
  - name: Allocations
    description: >-
      Use these operations to manage grant allocations awarded to applications.

      An allocation represents the award of funds from a budget (fund) to an
      application or applicant.


      Allocations track the total grant amount, currency, and outstanding
      balance.

      Multiple payments can be made against a single allocation to facilitate
      installment-based grants or milestone payments.
  - name: Applications (realtime)
    description: >-
      Use these operations to perform granular updates on applications without
      replacing the entire resource.

      These endpoints enable real-time updates to specific application
      properties such as:

      title, category assignment, chapter assignment, individual field values,
      document uploads, tags, and recusal status.


      These operations are optimized for interactive applications that need to
      update grants incrementally.
  - name: Applications
    description: >-
      Use these operations to manage grant applications submitted to your
      funding programs.

      Applications are the core entity that flows through the entire lifecycle
      from submission to review to grant award.


      Applications can contain custom form fields, supporting documents,
      contributors, and be organized by categories and chapters.

      Each application progresses through various statuses including draft,
      submitted, under review, and approved stages.
  - name: Assignments
    description: >-
      Use these operations to manage review assignments for evaluating grant
      applications.

      Assignments connect reviewers (or roles) with applications and scoring
      rubrics to facilitate the evaluation process.


      Assignments can be created individually or in bulk (asynchronous
      operations).

      Each assignment tracks completion status, scores, and panel membership.

      Assignments enable structured review workflows with configurable scoring
      criteria.
  - name: Attachments
    description: >-
      Use these operations to manage files uploaded to applications through
      attachment tabs.

      Attachments are distinct from field-based file uploads and allow for
      supplementary materials such as letters of support or compliance
      documents.


      Each attachment can have its own metadata and custom fields for
      categorization.

      Attachments remain associated with their application throughout the
      application lifecycle.
  - name: Categories
    description: >-
      Use these operations to manage funding categories or program areas.

      Categories organize applications into logical groups and can be
      hierarchical with parent-child relationships.


      Each category can have its own application form, chapter availability,
      submission limits, and custom labels.

      Categories support translated names and descriptions for multi-language
      grant programs.
  - name: Chapters
    description: >-
      Use these operations to manage geographic or organizational divisions
      within your grant programs.

      Chapters enable you to run regional funding programs, manage local grants,
      or organize by funding priorities.


      Applications can be assigned to chapters, and chapters can have their own
      administrators and configurations.

      Chapters support translated names and custom images for branding.
  - name: Contributors
    description: >-
      Use these operations to manage additional people associated with
      applications beyond the primary applicant.

      Contributors represent project team members, fiscal sponsors, or partners
      on a grant proposal.


      Each contributor can have their own custom fields and data collection
      requirements.

      Contributors are organized by tabs and can be managed independently from
      the main application.
  - name: Documents
    description: >-
      Use these operations to generate and retrieve PDF documents and data
      exports.

      Documents can be created based on application data, grantee data,
      compliance reports, or other program information.


      Document generation is asynchronous - after creating a document, poll the
      endpoint to check when generation is complete.

      Generated documents are available for download and can be associated with
      specific applicants or applications.
  - name: Fields
    description: >-
      Use these operations to manage custom form fields used to collect data
      throughout your grant programs.

      Fields can be attached to applications, users, contributors, attachments,
      and other resources.


      Supported field types include text, textarea, select, multi-select, date,
      file upload, table, and more.

      Fields support conditional logic, validation rules, and different
      protection levels.

      Note: Field deletion and updates are managed through the Good Grants
      interface.
  - name: Files
    description: >-
      Use these operations to retrieve information about uploaded files.

      Files provide metadata and download links for documents uploaded
      throughout the system.


      Access files using their secure token identifiers.

      Note: Files are read-only via this endpoint - file uploads are handled
      through resource-specific upload endpoints.
  - name: Forms
    description: >-
      Use these operations to retrieve application form structures and
      configurations.

      Forms define the data collection structure for grant applications within
      categories.


      Each form contains custom fields organized into tabs, along with content
      blocks and call-to-action elements.

      Forms support various types including application forms, review forms, and
      nomination forms.

      Note: Forms are read-only via the API and must be configured through the
      Good Grants interface.
  - name: Funds
    description: >-
      Use these operations to manage budget sources for allocations and grants.

      Funds represent pools of money available for distribution, such as
      "Innovation Fund 2026" or "Community Development Budget".


      Each fund tracks its budget, currency, and can have multiple allocations
      drawn against it.

      Funds enable financial tracking and reporting across your grant-making
      programs.
  - name: Grant reports
    description: >-
      Use these operations to manage grant reports and post-award compliance
      documentation.

      Grant reports track progress reporting requirements and outcomes for
      awarded grants.


      Reports capture applicant information, application details, custom form
      fields, and status tracking.
  - name: Grant statuses
    description: >-
      Use these operations to retrieve custom grant lifecycle statuses.

      Grant statuses provide additional status tracking beyond standard
      application review statuses.


      These are used to track stages like "Eligibility Review", "Compliance
      Check", "Funding Approved", "Grant Agreement Signed".

      Note: Grant statuses are read-only via the API and must be configured
      through the Good Grants interface.
  - name: Leaderboard
    description: >-
      Use these operations to retrieve ranking results and scores for
      applications.

      The leaderboard shows how applications rank based on score sets, with
      support for filtering by category, chapter, and tags.


      Results can be filtered to show specific subsets of the funding program.

      Note: The leaderboard is read-only and reflects calculated results from
      the review process.
  - name: Rounds
    description: >-
      Use these operations to retrieve round information for your grant
      programs.

      Rounds represent phases within a funding cycle, such as application
      rounds, review rounds, or decision rounds.


      Each round has specific start and end dates, associated forms, and can be
      scoped to specific chapters.

      Note: Rounds are read-only via the API and must be managed through the
      Good Grants interface.
  - name: Score sets
    description: >-
      Use these operations to retrieve scoring rubrics and evaluation criteria.

      Score sets define the questions, scoring scales, and calculation methods
      used to evaluate grant applications.


      Score sets can operate in different modes including scoring, ranking, and
      decision-making.

      Note: Score sets are read-only via the API and must be configured through
      the Good Grants interface.
  - name: Seasons
    description: >-
      Use these operations to retrieve information about funding cycles
      (seasons).

      A season represents a time-bound grant program instance, such as "2026
      Community Grants" or "Q1 2026 Innovation Fund".


      Seasons contain forms, rounds, categories, and chapters.

      Seasons progress through statuses: draft, active, archived, and destroyed.

      Note: Seasons are read-only via the API and must be managed through the
      Good Grants interface.
  - name: Taxes
    description: >-
      Use these operations to retrieve tax configurations for financial
      transactions.

      Tax settings define how taxes are calculated and applied to orders and
      payments.


      Note: Tax configurations are read-only via the API and must be managed
      through the Good Grants interface.
  - name: Users
    description: >-
      Use these operations to manage user accounts in your grant-making
      organization.

      Users represent people who interact with your programs, including
      applicants, reviewers, administrators, and other roles.


      Users can be assigned roles, have custom profile fields, receive
      notifications, and authenticate via API tokens.

      Each user has a unique slug identifier and can participate across multiple
      funding cycles.
  - name: Webhooks
    description: >-
      Use these operations to manage webhook subscriptions for real-time event
      notifications.

      Webhooks notify your external systems when events occur in Good Grants,
      such as application submissions, status changes, or payment completions.


      Available events include: application created, application submitted,
      application status changed, payment success, user confirmed, and 20+ more.

      Configure webhooks to send HTTP POST requests to your specified URLs with
      event payloads.
paths:
  /attachment/{token}/update-field/{field_slug}:
    parameters:
      - $ref: '#/components/parameters/token'
      - $ref: '#/components/parameters/fieldSlug'
    put:
      tags:
        - Applications (realtime)
      summary: Update an attachment field
      description: >-
        Updates an attachment field for the attachment identified by the
        specified token.
      operationId: PutAttachmentUpdateFieldV23
      parameters:
        - $ref: '#/components/parameters/Accept'
      requestBody:
        $ref: '#/components/requestBodies/AttachmentFieldUpdate'
      responses:
        '200':
          description: Attachment field updated.
          headers:
            ETag:
              $ref: '#/components/headers/ETag'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Attachment'
            application/xml:
              schema:
                $ref: '#/components/schemas/Attachment'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/UnprocessableEntity'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  parameters:
    token:
      name: token
      in: path
      description: Token string.
      required: true
      schema:
        type: string
        pattern: ^[A-Za-z0-9]{16}$|^[A-Za-z0-9]{32}$
    fieldSlug:
      name: field_slug
      in: path
      required: true
      description: Slug of the field.
      schema:
        type: string
        pattern: ^[A-Za-z]{8}$
    Accept:
      name: Accept
      in: header
      required: true
      description: Defines the response type.
      schema:
        type: string
        enum:
          - application/vnd.Creative Force.v2.3+json
          - application/vnd.Creative Force.v2.3+xml
  requestBodies:
    AttachmentFieldUpdate:
      content:
        application/json:
          schema:
            type: object
            additionalProperties: false
            required:
              - value
            properties:
              value:
                description: >-
                  New value for the attachment field identified by `field_slug`.
                  The accepted value depends on the type and configuration of
                  the field.


                  Use a string for text fields, a number for numeric fields, an
                  ISO 8601 date for date fields, and an option slug for choice
                  fields. A value outside the option set of a choice field
                  returns a `422` response. For file-type fields, use an object
                  containing the base64-encoded file data and a filename.
      description: Attachment field update payload.
      required: true
  headers:
    ETag:
      description: Entity tag for the selected representation.
      schema:
        type: string
    X-RateLimit-Limit:
      description: Maximum number of requests allowed per minute.
      schema:
        type: integer
        example: 60
    X-RateLimit-Remaining:
      description: Number of requests remaining in the current rate limit window.
      schema:
        type: integer
        example: 58
    X-RateLimit-Reset:
      description: Unix timestamp when the rate limit window resets.
      schema:
        type: integer
        example: 1783470988
    Retry-After:
      description: Number of seconds the client should wait before retrying.
      schema:
        type: integer
      example: 60
  schemas:
    Attachment:
      type: object
      title: Attachment
      description: >-
        File attached to an application through an attachments-typed form tab.


        Carries the file itself together with the form-field metadata captured
        against it, the application it belongs to, and the tab through which it
        was added.
      properties:
        application:
          type: object
          description: Application the attachment belongs to.
          properties:
            slug:
              type: string
              description: Short URL-safe identifier for the application.
            link:
              type: string
              format: uri
              description: Canonical URL for the application resource.
            title:
              type: string
              description: Title of the application as submitted by the applicant.
        attachment_fields:
          type: array
          description: >-
            Form fields captured against this attachment.


            One item per field defined on the parent attachments tab, in form
            order. The exact set of keys varies by field type.
          items:
            type: object
            properties:
              slug:
                type: string
                description: Short URL-safe identifier for the field.
              link:
                type: string
                format: uri
                description: Canonical URL for the field resource.
              label:
                type: object
                description: >-
                  Display label shown to the applicant alongside the field. May
                  contain HTML and may be empty.


                  Map keyed by locale code (for example `en_GB`, `fr_FR`). Keys
                  are drawn from the languages enabled on the account. Values
                  are the translated string.
                additionalProperties:
                  type: string
              title:
                type: object
                description: >-
                  Short title used to refer to the field in administrative
                  contexts.


                  Map keyed by locale code (for example `en_GB`, `fr_FR`). Keys
                  are drawn from the languages enabled on the account. Values
                  are the translated string.
                additionalProperties:
                  type: string
              value:
                type: string
                description: Raw stored value for the field, as submitted by the applicant.
              translated:
                type: object
                description: >-
                  Human-readable rendering of `value` resolved against the field
                  definition (for example, choice slugs expanded to labels).


                  Map keyed by locale code (for example `en_GB`, `fr_FR`). Keys
                  are drawn from the languages enabled on the account. Values
                  are the translated string.
                additionalProperties:
                  type: string
              download:
                type: string
                format: uri
                description: >-
                  Time-limited download URL. Present only for file-typed
                  attachment fields with an underlying file.
        created:
          type: string
          format: date-time
          description: Time the attachment was created.
        file:
          type: object
          description: File backing the attachment.
          properties:
            token:
              type: string
              description: Token identifying the file.
            link:
              type: string
              format: uri
              description: Canonical URL for the file resource.
            download:
              type:
                - string
                - 'null'
              format: uri
              description: >-
                Time-limited download URL for the underlying file.


                `null` when no signed URL can be resolved for the file (for
                example, in environments without a configured CDN).
            filename:
              type: string
              description: Original filename as uploaded.
        order:
          type: integer
          description: Position of the attachment within its tab.
        tab:
          type: object
          description: Attachments tab the attachment belongs to.
          properties:
            slug:
              type: string
              description: Short URL-safe identifier for the tab.
            link:
              type: string
              format: uri
              description: Canonical URL for the tab resource.
            name:
              type: object
              description: >-
                Map keyed by locale code (for example `en_GB`, `fr_FR`). Keys
                are drawn from the languages enabled on the account. Values are
                the translated string.
              additionalProperties:
                type: string
        token:
          type: string
          description: Token identifying the attachment file. Same value as `file.token`.
        updated:
          type: string
          format: date-time
          description: Time the attachment was last updated.
      example:
        application:
          slug: AbCdEfGh
          link: https://api.au.cr4ce.com/application/AbCdEfGh
          title: Project title
        attachment_fields:
          - slug: IjKlMnOp
            link: https://api.au.cr4ce.com/field/IjKlMnOp
            label:
              en_GB: Type of attachment
            title:
              en_GB: Type of attachment
            value: Photo
            translated:
              en_GB: Photo
          - slug: QrStUvWx
            link: https://api.au.cr4ce.com/field/QrStUvWx
            label:
              en_GB: <p>URL</p>
            title:
              en_GB: URL
            value: https://example.com/image.svg
            translated:
              en_GB: https://example.com/image.svg
        created: '2025-04-27T01:00:00Z'
        file:
          token: AbCdEfGhIjKlMnOp
          link: https://api.au.cr4ce.com/file/AbCdEfGhIjKlMnOp
          download: >-
            https://files.au.cr4ce.com/file/AbCdEfGhIjKlMnOp/example.pdf?Expires=1781485359&Signature=REDACTED&Key-Pair-Id=REDACTED
          filename: example.pdf
        order: 1
        tab:
          slug: YzAbCdEf
          link: https://api.au.cr4ce.com/tab/YzAbCdEf
          name:
            en_GB: Attachments
        token: AbCdEfGhIjKlMnOp
        updated: '2025-04-27T01:05:00Z'
    BadRequest:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 400
              maximum: 400
    Unauthorized:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 401
              maximum: 401
    Forbidden:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 403
              maximum: 403
    NotFound:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 404
              maximum: 404
    UnprocessableEntity:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 422
              maximum: 422
            errors:
              type: object
              description: >-
                Map of request field to the list of validation messages for that
                field. Present only on field-level validation failures; omitted
                when the 422 was raised by a resource-state precondition.
              additionalProperties:
                type: array
                items:
                  type: string
    TooManyRequests:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 429
              maximum: 429
    BaseProblem:
      description: Standard error envelope shared by every error response on this API.
      type: object
      properties:
        message:
          type: string
        status_code:
          type: integer
          minimum: 400
          maximum: 599
  responses:
    BadRequest:
      description: >-
        Request was rejected before the endpoint could process it. Common
        causes: invalid `Accept` header, unsupported `x-api-language` code,
        empty request body on `POST` / `PUT`, invalid JSON in the request body,
        or an invalid slug format in a path parameter.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/BadRequest'
        application/xml:
          schema:
            $ref: '#/components/schemas/BadRequest'
    Unauthorized:
      description: Missing `x-api-key` header.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Unauthorized'
        application/xml:
          schema:
            $ref: '#/components/schemas/Unauthorized'
    Forbidden:
      description: |-
        Authenticated request denied. Common causes: invalid or unknown
        API key, suspended account, or `api` feature not enabled for
        the account.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Forbidden'
        application/xml:
          schema:
            $ref: '#/components/schemas/Forbidden'
    NotFound:
      description: >-
        Resource identified by the path slug does not exist. Returned when the
        slug is well-formed but no record matches it.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/NotFound'
        application/xml:
          schema:
            $ref: '#/components/schemas/NotFound'
    UnprocessableEntity:
      description: >-
        Request was syntactically valid but could not be processed.


        Returned in two scenarios:


        - **Field-level validation failure** — one or more request fields
        violated the endpoint's validation rules. The body includes an `errors`
        map keyed by field name with one or more validation messages each.

        - **Resource-state precondition failure** — the request fields were all
        valid, but the target resource was in a state that does not permit the
        requested operation. The body carries only `message` and `status_code`;
        no `errors` map.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/UnprocessableEntity'
        application/xml:
          schema:
            $ref: '#/components/schemas/UnprocessableEntity'
    TooManyRequests:
      description: Rate limit of 60 requests per minute exceeded.
      headers:
        Retry-After:
          $ref: '#/components/headers/Retry-After'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/TooManyRequests'
        application/xml:
          schema:
            $ref: '#/components/schemas/TooManyRequests'
    ServiceUnavailable:
      description: Service is temporarily unavailable due to regional maintenance.
      content:
        application/json:
          schema:
            type: object
            properties:
              status:
                type: string
                description: Human-readable maintenance status.
            example:
              status: Maintenance in progress
        application/xml:
          schema:
            type: object
            properties:
              status:
                type: string
                description: Human-readable maintenance status.
            example:
              status: Maintenance in progress
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: |-
        API key used to authenticate and authorise every request.
        Include it in the `x-api-key` header.

````