curl --request POST \
--url https://app.goosybear.ai/api/v1/tools/page.patch_file \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"files": [
{
"path": "<string>",
"hunks": [
{
"find": "<string>",
"replace": "<string>"
}
]
}
],
"site_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expected_source_ref": "<string>",
"summary": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
'import requests
url = "https://app.goosybear.ai/api/v1/tools/page.patch_file"
payload = {
"files": [
{
"path": "<string>",
"hunks": [
{
"find": "<string>",
"replace": "<string>"
}
]
}
],
"site_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expected_source_ref": "<string>",
"summary": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
files: [{path: '<string>', hunks: [{find: '<string>', replace: '<string>'}]}],
site_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
expected_source_ref: '<string>',
summary: '<string>',
confirmation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
workspace: '<string>'
})
};
fetch('https://app.goosybear.ai/api/v1/tools/page.patch_file', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.goosybear.ai/api/v1/tools/page.patch_file",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'files' => [
[
'path' => '<string>',
'hunks' => [
[
'find' => '<string>',
'replace' => '<string>'
]
]
]
],
'site_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'expected_source_ref' => '<string>',
'summary' => '<string>',
'confirmation_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'workspace' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.goosybear.ai/api/v1/tools/page.patch_file"
payload := strings.NewReader("{\n \"files\": [\n {\n \"path\": \"<string>\",\n \"hunks\": [\n {\n \"find\": \"<string>\",\n \"replace\": \"<string>\"\n }\n ]\n }\n ],\n \"site_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"expected_source_ref\": \"<string>\",\n \"summary\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.goosybear.ai/api/v1/tools/page.patch_file")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"files\": [\n {\n \"path\": \"<string>\",\n \"hunks\": [\n {\n \"find\": \"<string>\",\n \"replace\": \"<string>\"\n }\n ]\n }\n ],\n \"site_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"expected_source_ref\": \"<string>\",\n \"summary\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.goosybear.ai/api/v1/tools/page.patch_file")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"files\": [\n {\n \"path\": \"<string>\",\n \"hunks\": [\n {\n \"find\": \"<string>\",\n \"replace\": \"<string>\"\n }\n ]\n }\n ],\n \"site_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"expected_source_ref\": \"<string>\",\n \"summary\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"ok": true,
"workspace": "<string>",
"working_in": {
"label": "<string>",
"note": "<string>",
"workspace": "<string>",
"source": "call-override"
},
"state": "confirmation_required",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expires_in_seconds": 123,
"request_summary": "<string>",
"site_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"source_ref": "<string>",
"base_source_ref": "<string>",
"build_run_id": "<string>",
"build_enqueue_error": "<string>",
"build_deferred": true,
"workbench_pushed": true,
"build_hint": "<string>",
"changed_paths": [
"<string>"
],
"diff": "<string>",
"diff_truncated": true,
"selected_element": "<string>"
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}Call page.patch_file
Change something on a site by writing its FILES — ‘add more space between these cards’, ‘change the button text to Book a call’, ‘fix the typo in the footer’, ‘make the hero heading bigger’. This is the one way every site whose files we hold is changed, however it was made or brought in: copy, styling, layout, a component, a page. Read each file with page.read_file first — start from the selected element’s file and line when the turn gives them, or from page.edit’s located, or find the words with page.list_files and contains — and copy find text exactly; a hunk that matches nowhere or more than once refuses the whole call and nothing is written. No site id is needed — it works on the site the member has open on screen. One call is ONE saved version, so send a whole change in one call. While a live workbench is showing the site the change appears there in place and no build runs (the result says build_deferred; relay its build_hint); otherwise a build follows and takes a minute or two. The result is the diff (say what it shows, never more), the new source_ref and base_source_ref (page.rollback to it undoes this). Which directories are editable depends on the project: refusals name the reason, so relay them rather than retrying. Dependency manifests and lockfiles, build configuration, generated files, and anything under a build or tooling directory are always refused. A site whose files are READ-ONLY here is refused — page.list_files reports can_write: false for one, so check that before composing a patch. A change the member asked for in this conversation is written at once; only a change nobody asked for — or any change, when the member has asked to see each one first — raises its approval card, which is the member’s confirmation, and is not made, saved or built unless they approve it there. Not for rewriting whole named files from an instruction — that is page.edit_file. Over the API it answers in two calls: without confirmation_id it proposes — says what would happen, returns a confirmation_id and changes, spends and sends nothing; the same arguments again with that confirmation_id, on a member’s own API key, do it.
Every result names the workspace it ran in. Say which workspace the answer is about. When the account has more than one workspace and none is selected, this tool refuses with workspace_ambiguous and lists the choices — offer them, never pick one.
curl --request POST \
--url https://app.goosybear.ai/api/v1/tools/page.patch_file \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"files": [
{
"path": "<string>",
"hunks": [
{
"find": "<string>",
"replace": "<string>"
}
]
}
],
"site_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expected_source_ref": "<string>",
"summary": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
'import requests
url = "https://app.goosybear.ai/api/v1/tools/page.patch_file"
payload = {
"files": [
{
"path": "<string>",
"hunks": [
{
"find": "<string>",
"replace": "<string>"
}
]
}
],
"site_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expected_source_ref": "<string>",
"summary": "<string>",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"workspace": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
files: [{path: '<string>', hunks: [{find: '<string>', replace: '<string>'}]}],
site_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
expected_source_ref: '<string>',
summary: '<string>',
confirmation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
workspace: '<string>'
})
};
fetch('https://app.goosybear.ai/api/v1/tools/page.patch_file', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.goosybear.ai/api/v1/tools/page.patch_file",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'files' => [
[
'path' => '<string>',
'hunks' => [
[
'find' => '<string>',
'replace' => '<string>'
]
]
]
],
'site_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'expected_source_ref' => '<string>',
'summary' => '<string>',
'confirmation_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'workspace' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.goosybear.ai/api/v1/tools/page.patch_file"
payload := strings.NewReader("{\n \"files\": [\n {\n \"path\": \"<string>\",\n \"hunks\": [\n {\n \"find\": \"<string>\",\n \"replace\": \"<string>\"\n }\n ]\n }\n ],\n \"site_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"expected_source_ref\": \"<string>\",\n \"summary\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.goosybear.ai/api/v1/tools/page.patch_file")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"files\": [\n {\n \"path\": \"<string>\",\n \"hunks\": [\n {\n \"find\": \"<string>\",\n \"replace\": \"<string>\"\n }\n ]\n }\n ],\n \"site_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"expected_source_ref\": \"<string>\",\n \"summary\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.goosybear.ai/api/v1/tools/page.patch_file")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"files\": [\n {\n \"path\": \"<string>\",\n \"hunks\": [\n {\n \"find\": \"<string>\",\n \"replace\": \"<string>\"\n }\n ]\n }\n ],\n \"site_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"expected_source_ref\": \"<string>\",\n \"summary\": \"<string>\",\n \"confirmation_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"workspace\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"ok": true,
"workspace": "<string>",
"working_in": {
"label": "<string>",
"note": "<string>",
"workspace": "<string>",
"source": "call-override"
},
"state": "confirmation_required",
"confirmation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"expires_in_seconds": 123,
"request_summary": "<string>",
"site_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"source_ref": "<string>",
"base_source_ref": "<string>",
"build_run_id": "<string>",
"build_enqueue_error": "<string>",
"build_deferred": true,
"workbench_pushed": true,
"build_hint": "<string>",
"changed_paths": [
"<string>"
],
"diff": "<string>",
"diff_truncated": true,
"selected_element": "<string>"
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}{
"ok": false,
"code": "<string>",
"message": "<string>",
"error": {
"code": "<string>",
"message": "<string>",
"retry_after_seconds": 123
},
"retry_after_seconds": 123
}Authorizations
An API key minted at Settings › API & MCP. Send it as Authorization: Bearer <key>. A key carries its holder's own permissions, resolved on every call — revoking a membership closes the key's reach immediately. Keep it in an environment variable (GOOSY_API_KEY), never in a committed file.
Headers
Your own id for this request, echoed back and recorded on the audit trail. 1–128 characters from A–Z a–z 0–9 . _ : -, starting with a letter or digit; anything else is replaced by a generated id.
128Body
1 - 8 elementsShow child attributes
Show child attributes
2000Omit to propose: the first call says what would happen, returns a confirmation_id and changes nothing. To go ahead, send the same arguments again with that confirmation_id, on a member's own API key; a service account's key can propose but never confirm.
Which workspace to run in — its slug. Omit to use your default. With more than one reachable workspace and no default, the call is refused and the choices are listed.
1Response
The call was admitted and dispatched. ok says whether the tool succeeded — a refusal the tool itself produced is still a 200, exactly as it is a successful JSON-RPC result over MCP.
- Option 1
- Option 2
The tool ran and answered.
The slug of the workspace this call ran in.
Which workspace this call ran in, and how that was decided. Present on every workspace-scoped result.
Show child attributes
Show child attributes
"confirmation_required"What will happen, in one sentence, for a person to approve before confirming.