`PATCH /v1/orgs/{org}/hosts/{host_id}` (DAWG-285).
const url = 'https://api.updawg.net/v1/orgs/example/hosts/example';const options = { method: 'PATCH', headers: {'Content-Type': 'application/json'}, body: '{"display_name":"example","labels":"example","notes":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://api.updawg.net/v1/orgs/example/hosts/example \ --header 'Content-Type: application/json' \ --data '{ "display_name": "example", "labels": "example", "notes": "example" }'Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Organization slug.
The hst_… id.
Request Bodyrequired
Section titled “Request Bodyrequired”Every field optional. An absent field is left alone; null clears
display_name or notes. labels replaces the whole set.
object
⚠️ The whole set, not a merge. A merge could never remove a label, and a label is a selector: one left behind keeps the host in a group.
Examplegenerated
{ "display_name": "example", "labels": "example", "notes": "example"}Responses
Section titled “Responses”Changed; the host as it now is. A label change queues the host for evaluation, so its proposals and label groups catch up.
object
How its agent was installed and the channel it follows. A package install updates only to builds its own repository’s channel holds. Absent: an agent too old to say.
object
The channel the package repository follows, e.g. stable. Absent for
a binary install, which can take a build from any channel.
apt or dnf (the package from pkg.updawg.net), binary
(install.sh’s binaries, updated from the signed manifest), or other.
⚠️ A ceiling, not a setting. The host’s own agent.toml decides
this; the server may narrow it and can never widen it. A portal that
renders it as editable is describing a control that does not exist.
Its package sources are pinned in time (DAWG-233): updates is
measured against a snapshot that does not move. ⚠️ Zero updates on a
frozen host is not “patched”, least of all when behind.
object
Known to be behind what it is offered. false also when nobody can
tell.
releasever (dnf’s release is fixed: Amazon Linux 2023, or
/etc/dnf/vars/releasever), snapshot (apt sources on a dated
archive snapshot), or other from an agent newer than this server.
The newest release it is offered, where its agent can tell.
What it is pinned to: 2023.5.20240805, 9.2, 20240101T000000Z.
⚠️ A selector, not decoration. A policy that targets several labels
intersects them, and the fleet filter takes them as repeatable
key=value, so a client that cannot see the type cannot build either.
String to string, enforced by hosts_labels_are_strings rather than
asserted here (DAWG-261).
object
Identity, and not the hostname. Hostnames change and repeat.
⚠️ Three-valued. null is “this host cannot say”, which is not
false. A distribution with no way to answer must not read as “nothing
to do here”.
Whether this host can take snapshots, and so be rolled back
(DAWG-115). ⚠️ null is an agent too old to say, not a host that
cannot: that one has a reason and no provider.
object
The provider in use, e.g. snapper. Absent: none, and reason says
why.
⚠️ null means never evaluated, not zero. A host that has never
uploaded an inventory has never been looked at, and rendering that as
“0 updates” tells somebody their unevaluated fleet is fully patched.
object
Updates that will leave the host needing a reboot — distinct from
reboot_required, which is whether it needs one now.
Whether anything rates this host’s updates (DAWG-215):
covered: advisories are published for its release.no_feed: its release is known and no advisory feed covers it — a derivative like Linux Mint, Pop!_OS or Raspbian. ⚠️ Every update here is unrated, which is not the same as safe.unknown_release: not resolved to a known release yet.
object
⚠️ An update for a held package will not install. This is the answer to “why did nothing happen” before anybody has to ask it.
Free text for whoever looks after the box.
Open proposals only, newest first. A host that has been in four hundred merged proposals is the normal case, and listing them would make this a changelog rather than an answer to “is anything waiting on this box”.
object
Examplegenerated
{ "agent_install": { "channel": "example", "method": "example" }, "agent_mode": "example", "agent_permissions": [ "example" ], "agent_version": "example", "arch": "example", "display_name": "example", "distro": "example", "distro_version": "example", "enrolled_at": "2026-04-15T12:00:00Z", "frozen": { "behind": true, "kind": "example", "latest": "example", "pinned": "example" }, "hostname": "example", "id": "example", "kernel_version": "example", "labels": { "additionalProperty": "example" }, "last_inventory_at": "2026-04-15T12:00:00Z", "last_seen_at": "2026-04-15T12:00:00Z", "machine_id": "example", "os_family": "example", "reboot_required": true, "services_need_restart": [ "example" ], "snapshots": { "provider": "example", "reason": "example" }, "status": "example", "updates": { "requiring_reboot": 1, "security": 1, "total": 1 }, "advisory_coverage": "example", "cert_expires_at": "2026-04-15T12:00:00Z", "cloud": { "instance_id": "example", "provider": "example", "region": "example" }, "decommissioned_at": "2026-04-15T12:00:00Z", "groups": [ { "id": "example", "name": "example" } ], "held_packages": [ "example" ], "notes": "example", "proposals": [ { "id": "example", "number": 1, "status": "example", "title": "example" } ], "virtualization": "example"}Too many labels, an empty key, or a display name or notes that are too long.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No session.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted for this role.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such host here.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}