# Change the itinerary

> Applies a batch of block operations (`add`, `update`, `move`, `delete`) atomically, with the builder's own validation, and re-plans the route of every day it touches.

`POST /v1/trips/{tripId}/itinerary/ops`

Applies a batch of block operations (`add`, `update`, `move`, `delete`) atomically, with the builder's own validation, and re-plans the route of every day it touches. Rules:
- `update` and `delete` send the block's current `version` as `expectedVersion`; a stale one is a 409.
- `update.data` is MERGED into the block's data, so send only the fields you change. An unknown field is a 422. A stop's times on a planned route belong to the route and are ignored.
- A later op in the same batch refers to a block added earlier by its `clientId` (in `parentId` or `anchorId`). The server assigns ids and returns them in `created`.
- `dia` structure ops are refused (422) on a trip whose days come from its design; change the design, then call /itinerary/sync.
- Deleting more than 5 blocks, or more than 30 % of the itinerary, needs `confirm` set to the trip's exact title.
- A batch in which nothing changes is refused (422), and so is deleting a retired block type, which could not be undone.

With `?dryRun=true`, returns the counts and the planner's notices without writing.

**Permissions:** `trips:write` · **Kind:** destructive · **Cost:** 1 unit · **Dry run:** `?dryRun=true`

Undoable: the response carries `Bymundi-Change-Id`; [revert it](https://api.bymundi.com/docs/guides/undo-and-dry-run.md) with `POST /v1/changes/{changeId}/revert`.

## Path parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `tripId` | uuid | yes |  |

## Body

| Field | Type | Required | Description |
|---|---|---|---|
| `ops` | object \| object \| object \| object[] | yes | max 200 items |
| `confirm` | string |  | max 300 chars |

## Response `200`

One of:

### `itinerary_change`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "itinerary_change" | yes |  |
| `changeId` | uuid | yes |  |
| `created` | object[] | yes |  |
| `created[].clientId` | string \| null | yes |  |
| `created[].id` | uuid | yes |  |
| `itinerary` | object | yes |  |
| `itinerary.object` | "itinerary" | yes |  |
| `itinerary.tripId` | uuid | yes |  |
| `itinerary.title` | string | yes |  |
| `itinerary.publication` | "draft" \| "published" | yes |  |
| `itinerary.hasDesignedRoute` | boolean | yes |  |
| `itinerary.blocks` | object[] | yes |  |
| `itinerary.blocks[].object` | "block" | yes |  |
| `itinerary.blocks[].id` | uuid | yes |  |
| `itinerary.blocks[].type` | "titulo" \| "texto" \| "imagen" \| "agenda" \| "dia" \| "caja" \| "desplegable" \| "seccion" \| "capitulo" \| "derivado" \| "actividad" \| "alojamiento" \| "vuelo" \| "comida" \| "transporte" \| "tren" \| "crucero" \| "informacion" \| "galeria" \| "video" \| "mapa" \| "html" \| "itinerario" | yes |  |
| `itinerary.blocks[].parentId` | uuid \| null | yes |  |
| `itinerary.blocks[].rank` | string | yes |  |
| `itinerary.blocks[].data` | object | yes |  |
| `itinerary.blocks[].layout` | object | yes |  |
| `itinerary.blocks[].version` | integer | yes |  |
| `itinerary.blocks[].source` | object \| null | yes |  |

### `itinerary_change_preview`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "itinerary_change_preview" | yes |  |
| `added` | integer | yes |  |
| `updated` | integer | yes |  |
| `moved` | integer | yes |  |
| `removed` | integer | yes |  |
| `notices` | string[] | yes |  |
| `requiresConfirmation` | boolean | yes |  |


## Errors

Errors are [problem details](https://api.bymundi.com/docs/guides/errors.md). Besides the refusals described above, any call like this one can return:

- [`invalid_request`](https://api.bymundi.com/problems/invalid_request.md) — Invalid request
- [`unauthorized`](https://api.bymundi.com/problems/unauthorized.md) — Missing or invalid API key
- [`insufficient_scope`](https://api.bymundi.com/problems/insufficient_scope.md) — Missing permission
- [`rate_limited`](https://api.bymundi.com/problems/rate_limited.md) — Rate limit reached
- [`not_found`](https://api.bymundi.com/problems/not_found.md) — Not found
- [`idempotency_key_reused`](https://api.bymundi.com/problems/idempotency_key_reused.md) — Idempotency-Key reused
- [`request_in_progress`](https://api.bymundi.com/problems/request_in_progress.md) — Request in progress

## Examples

#### curl

```bash
curl -X POST https://api.bymundi.com/v1/trips/$TRIP_ID/itinerary/ops \
  -H "Authorization: Bearer $BYMUNDI_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{"ops":[{"op":"add","type":"titulo"}]}'
```

#### JavaScript

```javascript
const res = await fetch(`https://api.bymundi.com/v1/trips/${tripId}/itinerary/ops`, {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.BYMUNDI_KEY}`,
    "Content-Type": "application/json",
    "Idempotency-Key": crypto.randomUUID(),
  },
  body: JSON.stringify({"ops":[{"op":"add","type":"titulo"}]}),
});
if (!res.ok) throw new Error((await res.json()).detail);
const data = await res.json();
```

#### Python

```python
import os, uuid, requests

res = requests.post(
    f"https://api.bymundi.com/v1/trips/{tripId}/itinerary/ops",
    headers={"Authorization": f"Bearer {os.environ['BYMUNDI_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
    json={"ops":[{"op":"add","type":"titulo"}]},
)
res.raise_for_status()
data = res.json()
```
