> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-findings-decoys-followup.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Update Function

> Update an existing function's metadata, code, or both. Also the publish
 path: set function.published_commit_id and include "published_commit_id"
 in update_mask to make a commit the default runnable version. To push a
 new code commit, set content (and optionally commit_message); this is
 independent of update_mask, since commits are versioned separately from
 function metadata. A single request cannot publish the commit it just
 created, since published_commit_id is validated against existing commits
 before content is committed: publishing new code takes two calls, push
 then publish with the returned commit.id.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/functions/update
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/functions/update:
    post:
      tags:
        - Function
      summary: Update Function
      description: |-
        Update an existing function's metadata, code, or both. Also the publish
         path: set function.published_commit_id and include "published_commit_id"
         in update_mask to make a commit the default runnable version. To push a
         new code commit, set content (and optionally commit_message); this is
         independent of update_mask, since commits are versioned separately from
         function metadata. A single request cannot publish the commit it just
         created, since published_commit_id is validated against existing commits
         before content is committed: publishing new code takes two calls, push
         then publish with the returned commit.id.
      operationId: c1.api.functions.v1.FunctionsService.UpdateFunction
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse
          description: Successful response
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: >-
            import { ConductoroneSDKTypescript } from
            "conductorone-sdk-typescript";


            const conductoroneSDKTypescript = new ConductoroneSDKTypescript({
              security: {
                bearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
                oauth: "<YOUR_OAUTH_HERE>",
              },
            });


            async function run() {
              const result = await conductoroneSDKTypescript.functions.updateFunction();

              console.log(result);
            }


            run();
        - lang: go
          label: UpdateFunction
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.Functions.UpdateFunction(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.FunctionsServiceUpdateFunctionResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.functions.v1.FunctionsServiceUpdateFunctionRequest:
      description: The FunctionsServiceUpdateFunctionRequest message.
      properties:
        commitMessage:
          description: >-
            The commit message describing this code update. Defaults to a
            generic
             message if content is set and this is empty. Ignored if content is empty.
          type: string
        content:
          additionalProperties:
            format: base64
            type: string
          description: |-
            File map for a new code commit, applied as the function's new head
             commit. Keys are file paths in the function root; values are file
             contents as bytes. See CreateFunctionRequest.initial_content for the
             required entry-file signature. Independent of update_mask.
          type: object
        function:
          oneOf:
            - $ref: '#/components/schemas/c1.api.functions.v1.Function'
            - type: 'null'
        updateMask:
          type:
            - string
            - 'null'
      title: Functions Service Update Function Request
      type: object
      x-speakeasy-name-override: FunctionsServiceUpdateFunctionRequest
    c1.api.functions.v1.FunctionsServiceUpdateFunctionResponse:
      description: The FunctionsServiceUpdateFunctionResponse message.
      properties:
        commit:
          oneOf:
            - $ref: '#/components/schemas/c1.api.functions.v1.FunctionCommit'
            - type: 'null'
        function:
          oneOf:
            - $ref: '#/components/schemas/c1.api.functions.v1.Function'
            - type: 'null'
      title: Functions Service Update Function Response
      type: object
      x-speakeasy-name-override: FunctionsServiceUpdateFunctionResponse
    c1.api.functions.v1.Function:
      description: Function represents a customer-provided code extension in the API
      properties:
        createdAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        description:
          description: The description field.
          type: string
        displayName:
          description: The displayName field.
          type: string
        functionType:
          description: The functionType field.
          enum:
            - FUNCTION_TYPE_UNSPECIFIED
            - FUNCTION_TYPE_ANY
            - FUNCTION_TYPE_CODE_MODE
          type: string
          x-speakeasy-unknown-values: allow
        head:
          description: The head field.
          type: string
        hookRefs:
          description: |-
            IDs of every non-deleted hook that still references this function.
             Read-only: maintained by the Hook API, not by CreateFunction/UpdateFunction.
             Non-empty means DeleteFunction will refuse to delete until these are
             removed or retargeted.
          items:
            type: string
          readOnly: true
          type:
            - array
            - 'null'
        id:
          description: The id field.
          type: string
        isDraft:
          description: The isDraft field.
          type: boolean
        outboundNetworkAllowlist:
          description: The outboundNetworkAllowlist field.
          items:
            type: string
          type:
            - array
            - 'null'
        provisionedConcurrency:
          description: >-
            Number of pre-warmed Lambda instances. 0 (default) leaves the
            function
             cold-started on first invoke. > 0 reserves and provisions that many
             execution environments via AWS Lambda provisioned concurrency.
             Ignored for FUNCTION_TYPE_CODE_MODE functions — that value is driven
             by AIGovernanceSettings.code_mode_concurrency.
          format: int32
          type: integer
        publishedCommitId:
          description: The publishedCommitId field.
          type: string
        scopedRoleIds:
          description: >-
            Scoped role IDs define the permissions granted to this function when
            calling
             ConductorOne APIs. These are role IDs (not service roles) that get resolved
             to their service roles at authentication time.

             Currently only the "Read-Only Administrator" role (system:viewer) is supported.
             The role ID can be obtained from the roles API.
          items:
            type: string
          type:
            - array
            - 'null'
        secret:
          additionalProperties:
            type: string
          description: The secret field.
          type: object
        updatedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        useSpn:
          description: >-
            FN-347 transition flag. When true, the function authenticates to
            c1-api
             as user:<sp_id> via the AssumeIdentity token exchange using its
             ServicePrincipalBinding; when false, it authenticates as
             function:<id>. Read-only from clients: set by CreateFunction (when the
             tenant has completed the FunctionsToSPN migration) and by the migration
             itself, never by UpdateFunction. Retired once all functions are on SPN.
          readOnly: true
          type: boolean
        workflowTemplateRefs:
          description: >-
            IDs of every non-deleted workflow template whose CallFunction step
            still
             references this function. Read-only, same semantics as hook_refs.
          items:
            type: string
          readOnly: true
          type:
            - array
            - 'null'
      title: Function
      type: object
      x-speakeasy-entity: Function
      x-speakeasy-name-override: Function
    c1.api.functions.v1.FunctionCommit:
      description: FunctionCommit represents a single commit in a function's history
      properties:
        author:
          description: The author field.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        functionId:
          description: The functionId field.
          type: string
        id:
          description: The id field.
          type: string
        message:
          description: The message field.
          type: string
      title: Function Commit
      type: object
      x-speakeasy-name-override: FunctionCommit
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````