Updates the details of a custom attribute.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| attribute_id | string | required | Pass the unique ID of the custom attribute. |
Body Parameters
| Name | Type | Required | Description |
|---|---|---|---|
| name | string | optional | Pass a name for the attribute within 100 characters. |
| type | number | optional | Pass the number associated with the type. |
| description | string | optional | Pass a description for the attribute within 500 characters. |
| choices | array | optional | Pass the list of choices for a single-select attribute. |
| is_actionable | boolean | optional | Pass true to enable the custom attribute to be modified in threat data objects. |
| status | number | optional | Pass 1 to activate the attribute. Pass 0 to deactivate the attribute. |
| sdo_objects | array | optional | Pass the list of SDOs on which you want to list this attribute as actionable. To get the list of supported SDO types, see the Supported SDO Types table in Threat Data > Miscellaneous. |
Run it
Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).
Playground
Request parameters
Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.
Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.
Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.
Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.
curl --request PUT \
--url "https://cs-testv2.cyware.com/ctixapi/ingestion/configuration/custom-attribute/910de07c-2cec-4534-b69a-36b50b03e088/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
--data '{
"name": "pin",
"type": 3,
"description": "sample description",
"choices": [
"SDO1"
],
"is_actionable": true,
"status": 1,
"sdo_objects": [
"identity"
]
}'View-only example — running live API calls requires a role with snippet testing access.
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/configuration/custom-attribute/910de07c-2cec-4534-b69a-36b50b03e088/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";
const response = await fetch(url, {
method: "PUT",
headers: {},
body: JSON.stringify({
"name": "pin",
"type": 3,
"description": "sample description",
"choices": [
"SDO1"
],
"is_actionable": true,
"status": 1,
"sdo_objects": [
"identity"
]
}),
});
const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);View-only example — running live API calls requires a role with snippet testing access.
import requests
url = "https://cs-testv2.cyware.com/ctixapi/ingestion/configuration/custom-attribute/910de07c-2cec-4534-b69a-36b50b03e088/"
params = {
"AccessID": "<your access id>",
"Signature": "<your signature>",
"Expires": "<your expires>"
}
headers = {}
payload = {
"name": "pin",
"type": 3,
"description": "sample description",
"choices": [
"SDO1"
],
"is_actionable": true,
"status": 1,
"sdo_objects": [
"identity"
]
}
response = requests.request("PUT", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)View-only example — running live API calls requires a role with snippet testing access.
{
"name": "pin",
"type": 3,
"description": "sample description",
"choices": [
"SDO1"
],
"is_actionable": true,
"status": 1,
"sdo_objects": [
"identity"
]
}View-only example — running live API calls requires a role with snippet testing access.
{
"id": "94db014d-a713-4904-9a9a-d6fec593b52e",
"name": "pin",
"type": 3,
"ctix_created": 1633090980,
"ctix_modified": 1633093451,
"choices": [
"SDO1"
],
"is_actionable": false,
"status": 1,
"sdo_objects": [
"identity"
],
"manual": true
}View-only example — running live API calls requires a role with snippet testing access.