SpendRock Docs
Items

Reorder the Favorites section (FAV-1). Independent of each item's order within its group.

`item_ids` may list all favorites or only some (e.g. the favorites in the month being viewed). The listed favorites are placed, in the given order, into the positions they held between them in the household's current Favorites order; favorites that are not listed keep their positions. For example, with Favorites `[A, B, C, D]`, sending `[D, B]` gives `[A, D, C, B]`. Every id must be a current favorite, listed once; otherwise the request fails with `invalid`. Required scope: `budget:write` (personal access tokens; sessions have every scope).

PUT
/favorites/order

item_ids may list all favorites or only some (e.g. the favorites in the month being viewed). The listed favorites are placed, in the given order, into the positions they held between them in the household's current Favorites order; favorites that are not listed keep their positions. For example, with Favorites [A, B, C, D], sending [D, B] gives [A, D, C, B]. Every id must be a current favorite, listed once; otherwise the request fails with invalid.

Required scope: budget:write (personal access tokens; sessions have every scope).

Authorization

bearerAuth
AuthorizationBearer <token>

Authorization: Bearer <token>: a mobile session token, or a personal access token (srp_…) created in Account → API tokens (DEV-1).

Personal access tokens:

  • Act as their user. The household comes from X-SpendRock-Household, else the user's default.
  • Carry scopes (DEV-2), and each operation's description names the one it needs: budget:read / budget:write (months, groups, items, funds, favorites, harvest), transactions:read / transactions:write (transactions, merchant suggestions), households:read / households:manage (households, members, invites), account:read / account:write (me, settings). A write scope includes its read scope. A call outside the token's scopes gets 403 insufficient_scope, with the needed scope in details.required_scope.
  • Can't manage tokens or passwords (403 session_required).
  • May expire (401 unauthenticated afterwards).
  • Are rate-limited (DEV-3): 120 requests/minute per token with bursts up to 120. Every response carries X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (seconds until the bucket is full again); over the limit the answer is 429 rate_limited with Retry-After (seconds). Limits are kept per server instance, so they're approximate.

Sessions (web cookie or mobile bearer) have every scope and aren't limited this way. Cross-origin browser calls (CORS, for the API docs playground) must use a bearer token; cookies are never accepted cross-origin.

In: header

Header Parameters

X-SpendRock-Household?string

The household to act on (HH-12). Defaults to the user's default household. 403 not_a_member if the caller isn't a current member (HH-16).

Match^[0-9A-HJKMNP-TV-Z]{26}$

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X PUT "https://example.com/favorites/order" \  -H "Content-Type: application/json" \  -d '{    "item_ids": [      "01J8Z3N4Q5R6S7T8V9W0X1Y2Z3"    ]  }'
Empty