# Update a traveler

> Changes a passenger's fields — an absent field is unchanged, `null` clears it — and/or moves it (`position`).

`PATCH /v1/travelers/{travelerId}`

Changes a passenger's fields — an absent field is unchanged, `null` clears it — and/or moves it (`position`). The resulting passenger is validated as the drawer does. Send `expectedUpdatedAt` (the `updatedAt` you read) to refuse with 409 if someone changed it since. Staff may correct any field in any state. On a `reservada` trip a new email gets the app-access email. Undo with POST /changes/{changeId}/revert within 30 days, while nobody has edited the passenger since. An access email the write queued is not recalled.

**Permissions:** `travelers:write` · **Kind:** write · **Cost:** 1 unit · MCP tool [`update_traveler`](https://api.bymundi.com/docs/mcp/tools/update_traveler.md)

Undoable: the response carries `Bymundi-Change-Id`; [revert it](https://api.bymundi.com/docs/guides/undo-and-dry-run.md) with `POST /v1/changes/{changeId}/revert`.

## Path parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `travelerId` | uuid | yes |  |

## Body

| Field | Type | Required | Description |
|---|---|---|---|
| `position` | integer |  | 0 = first on the booking. Past the end = last. 0–39 |
| `expectedUpdatedAt` | datetime |  | Refuse (409) unless the passenger still carries this `updatedAt`. |
| `title` | "mr" \| "mrs" \| "ms" \| "mstr" \| "miss" \| null |  | Form of address; the app derives one from sex and age when empty. |
| `firstName` | string \| null |  |  |
| `lastName1` | string \| null |  | Surname(s) as on the passport — the app asks for both surnames here. |
| `lastName2` | string \| null |  | A second surname stored separately (older passengers); usually null. |
| `birthDate` | string \| null |  |  |
| `sex` | "m" \| "f" \| null |  |  |
| `nationality` | string \| null |  |  |
| `docType` | "dni" \| "nie" \| "passport" \| "other" \| null |  |  |
| `docNumber` | string \| null |  |  |
| `docExpiry` | string \| null |  |  |
| `docCountry` | string \| null |  | The country that issued the document. |
| `email` | email \| null |  |  |
| `phone` | string \| null |  |  |
| `address` | object \| null |  |  |
| `address.line1` | string \| null | yes |  |
| `address.line2` | string \| null | yes |  |
| `address.postalCode` | string \| null | yes |  |
| `address.city` | string \| null | yes |  |
| `address.region` | string \| null | yes |  |
| `address.country` | string \| null | yes |  |
| `taxId` | string \| null |  |  |

## Response `200`

| Field | Type | Required | Description |
|---|---|---|---|
| `object` | "traveler" | yes |  |
| `id` | uuid | yes |  |
| `tripId` | uuid | yes |  |
| `position` | integer | yes |  |
| `title` | "mr" \| "mrs" \| "ms" \| "mstr" \| "miss" \| null | yes |  |
| `firstName` | string \| null | yes |  |
| `lastName1` | string \| null | yes |  |
| `lastName2` | string \| null | yes |  |
| `birthDate` | string \| null | yes |  |
| `sex` | "m" \| "f" \| null | yes |  |
| `nationality` | string \| null | yes |  |
| `docType` | "dni" \| "nie" \| "passport" \| "other" \| null | yes |  |
| `docNumber` | string \| null | yes |  |
| `docExpiry` | string \| null | yes |  |
| `docCountry` | string \| null | yes |  |
| `email` | string \| null | yes |  |
| `phone` | string \| null | yes |  |
| `address` | object \| null | yes |  |
| `address.line1` | string \| null | yes |  |
| `address.line2` | string \| null | yes |  |
| `address.postalCode` | string \| null | yes |  |
| `address.city` | string \| null | yes |  |
| `address.region` | string \| null | yes |  |
| `address.country` | string \| null | yes |  |
| `taxId` | string \| null | yes |  |
| `paxType` | "adult" \| "child" \| "infant" \| "unknown" | yes |  |
| `missing` | string[] | yes |  |
| `access` | "invited" \| "queued" \| "failed" \| "no_email" \| "not_yet" \| null | yes |  |
| `source` | string | yes |  |
| `consentAt` | string \| null | yes |  |
| `docsPurgedAt` | string \| null | yes |  |
| `createdAt` | string | yes |  |
| `updatedAt` | string | yes |  |

## Errors

Errors are [problem details](https://api.bymundi.com/docs/guides/errors.md). Besides the refusals described above, any call like this one can return:

- [`invalid_request`](https://api.bymundi.com/problems/invalid_request.md) — Invalid request
- [`unauthorized`](https://api.bymundi.com/problems/unauthorized.md) — Missing or invalid API key
- [`insufficient_scope`](https://api.bymundi.com/problems/insufficient_scope.md) — Missing permission
- [`rate_limited`](https://api.bymundi.com/problems/rate_limited.md) — Rate limit reached
- [`not_found`](https://api.bymundi.com/problems/not_found.md) — Not found
- [`idempotency_key_reused`](https://api.bymundi.com/problems/idempotency_key_reused.md) — Idempotency-Key reused
- [`request_in_progress`](https://api.bymundi.com/problems/request_in_progress.md) — Request in progress

## Examples

#### curl

```bash
curl -X PATCH https://api.bymundi.com/v1/travelers/$TRAVELER_ID \
  -H "Authorization: Bearer $BYMUNDI_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{}'
```

#### JavaScript

```javascript
const res = await fetch(`https://api.bymundi.com/v1/travelers/${travelerId}`, {
  method: "PATCH",
  headers: {
    Authorization: `Bearer ${process.env.BYMUNDI_KEY}`,
    "Content-Type": "application/json",
    "Idempotency-Key": crypto.randomUUID(),
  },
  body: JSON.stringify({}),
});
if (!res.ok) throw new Error((await res.json()).detail);
const data = await res.json();
```

#### Python

```python
import os, uuid, requests

res = requests.patch(
    f"https://api.bymundi.com/v1/travelers/{travelerId}",
    headers={"Authorization": f"Bearer {os.environ['BYMUNDI_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
    json={},
)
res.raise_for_status()
data = res.json()
```
