> ## Documentation Index
> Fetch the complete documentation index at: https://www.dropfans.io/developers/llms.txt
> Use this file to discover all available pages before exploring further.

# PATCH /api/external/vault/{id}/tags — Replace a vault item’s content tags

> Replaces (not merges) the content tags on a vault item. Send the full list every time.

- Source: https://www.dropfans.io/developers/reference/set-vault-item-tags
- Section: API reference
- OpenAPI: https://www.dropfans.io/developers/openapi.json

Replaces (not merges) the content tags on a vault item. Send the full list every time.

Tags are trimmed, de-duplicated, silently truncated to 64 characters each, and capped at 50 tags — the response echoes what was actually stored, so compare it to what you sent.

> [!NOTE] Field name
> The body field is `contentTags`, not `tags`.

## Authentication

`Authorization: Bearer dpfn_...` — an API key generated in the creator's dashboard (Vault → API Connect). One key = one creator. Missing or invalid keys return 401 `{"error":"Unauthorized","code":"unauthorized"}`.

## Path parameters

| Field | Type | Required | Description |
|---|---|---|---|
| `id` | string | yes | The vault item id. |

## Request body (application/json)

| Field | Type | Required | Description |
|---|---|---|---|
| `contentTags` | string[] | yes | The complete new tag list (≤50 kept). |

Example — Set two tags:

```json
{
  "contentTags": [
    "beach",
    "bikini"
  ]
}
```

## Responses

### 200

Stored — `contentTags` echoes the normalised list.

| Field | Type | Required | Description |
|---|---|---|---|
| `success` | boolean | yes | Always true. |
| `contentTags` | string[] | yes | The tags after trimming, de-duplication and capping. |

```json
{
  "success": true,
  "contentTags": [
    "beach",
    "bikini"
  ]
}
```

## Errors

| Status | Body | When |
|---|---|---|
| 400 | `{"error":"Invalid JSON body"}` | The body is not valid JSON. |
| 400 | `{"error":"contentTags must be an array of strings"}` | Missing, not an array, or contains non-strings. |
| 401 | `{"error":"Unauthorized","code":"unauthorized"}` | Missing or invalid API key. |
| 404 | `{"error":"Vault item not found"}` | No such item on this account. |

## Rate limiting

Per-key fixed windows by tier (Personal 60/min · 5,000/day; approved apps 300/min · 50,000/day; Dropfans-operated integrations exempt). Read the live values from X-RateLimit-Tier, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and their -Day variants; a 429 carries Retry-After and `{"error":"Rate limit exceeded","code":"rate_limited"}`. See [Rate limits](https://www.dropfans.io/developers/concepts/rate-limits.md).

## Code samples

### curl

```bash
curl -X PATCH "https://www.dropfans.io/api/external/vault/$VAULT_ITEM_ID/tags" \
  -H "Authorization: Bearer $DROPFANS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "contentTags": [
    "beach",
    "bikini"
  ]
}'
```

### Node

```javascript
const vaultItemId = '…'; // from an earlier response

const res = await fetch(`https://www.dropfans.io/api/external/vault/${vaultItemId}/tags`, {
  method: 'PATCH',
  headers: {
    Authorization: `Bearer ${process.env.DROPFANS_API_KEY}`,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "contentTags": [
      "beach",
      "bikini"
    ]
  }),
});
console.log(await res.json());
```

### Python

```python
import os
import requests

vault_item_id = "…"  # from an earlier response

res = requests.patch(
    f"https://www.dropfans.io/api/external/vault/{vault_item_id}/tags",
    headers={"Authorization": f"Bearer {os.environ['DROPFANS_API_KEY']}"},
    json={
        "contentTags": [
            "beach",
            "bikini",
        ],
    },
)
print(res.json())
```

## OpenAPI

```json
{
  "method": "PATCH",
  "path": "/api/external/vault/{id}/tags",
  "operationId": "setVaultItemTags",
  "tags": [
    "vault"
  ],
  "summary": "Replace a vault item’s content tags",
  "description": "Replaces (not merges) the content tags on a vault item. Send the full list every time.\n\nTags are trimmed, de-duplicated, silently truncated to 64 characters each, and capped at 50 tags — the response echoes what was actually stored, so compare it to what you sent.\n\n> [!NOTE] Field name\n> The body field is `contentTags`, not `tags`.",
  "parameters": [
    {
      "name": "id",
      "in": "path",
      "required": true,
      "description": "The vault item id.",
      "schema": {
        "type": "string"
      },
      "example": "clxv1a2b30001item"
    }
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "contentTags": {
              "type": "array",
              "items": {
                "type": "string",
                "description": "A tag (longer ones are cut to 64 chars).",
                "maxLength": 64
              },
              "description": "The complete new tag list (≤50 kept).",
              "maxItems": 50
            }
          },
          "required": [
            "contentTags"
          ]
        },
        "examples": {
          "tags": {
            "summary": "Set two tags",
            "value": {
              "contentTags": [
                "beach",
                "bikini"
              ]
            }
          }
        }
      }
    }
  },
  "responses": {
    "200": {
      "description": "Stored — `contentTags` echoes the normalised list.",
      "headers": {
        "X-RateLimit-Tier": {
          "description": "Rate-limit tier of the key: personal, app or first_party (first_party is unlimited).",
          "schema": {
            "type": "string",
            "enum": [
              "personal",
              "app",
              "first_party"
            ]
          }
        },
        "X-RateLimit-Limit": {
          "description": "Requests allowed per minute for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining": {
          "description": "Requests left in the current minute window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset": {
          "description": "Epoch seconds when the minute window resets.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Limit-Day": {
          "description": "Requests allowed per UTC day for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining-Day": {
          "description": "Requests left in the current UTC day window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset-Day": {
          "description": "Epoch seconds when the day window resets.",
          "schema": {
            "type": "integer"
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "success": {
                "type": "boolean",
                "description": "Always true.",
                "example": true
              },
              "contentTags": {
                "type": "array",
                "items": {
                  "type": "string",
                  "description": "A stored tag."
                },
                "description": "The tags after trimming, de-duplication and capping."
              }
            },
            "required": [
              "success",
              "contentTags"
            ]
          },
          "example": {
            "success": true,
            "contentTags": [
              "beach",
              "bikini"
            ]
          }
        }
      }
    },
    "400": {
      "description": "The body is not valid JSON. Also: Missing, not an array, or contains non-strings.",
      "headers": {
        "X-RateLimit-Tier": {
          "description": "Rate-limit tier of the key: personal, app or first_party (first_party is unlimited).",
          "schema": {
            "type": "string",
            "enum": [
              "personal",
              "app",
              "first_party"
            ]
          }
        },
        "X-RateLimit-Limit": {
          "description": "Requests allowed per minute for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining": {
          "description": "Requests left in the current minute window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset": {
          "description": "Epoch seconds when the minute window resets.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Limit-Day": {
          "description": "Requests allowed per UTC day for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining-Day": {
          "description": "Requests left in the current UTC day window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset-Day": {
          "description": "Epoch seconds when the day window resets.",
          "schema": {
            "type": "integer"
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "string",
                "description": "Human-readable message describing what went wrong.",
                "example": "Vault item not found"
              }
            },
            "required": [
              "error"
            ]
          },
          "example": {
            "error": "Invalid JSON body"
          }
        }
      }
    },
    "401": {
      "description": "Missing or invalid API key.",
      "headers": {
        "X-RateLimit-Tier": {
          "description": "Rate-limit tier of the key: personal, app or first_party (first_party is unlimited).",
          "schema": {
            "type": "string",
            "enum": [
              "personal",
              "app",
              "first_party"
            ]
          }
        },
        "X-RateLimit-Limit": {
          "description": "Requests allowed per minute for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining": {
          "description": "Requests left in the current minute window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset": {
          "description": "Epoch seconds when the minute window resets.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Limit-Day": {
          "description": "Requests allowed per UTC day for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining-Day": {
          "description": "Requests left in the current UTC day window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset-Day": {
          "description": "Epoch seconds when the day window resets.",
          "schema": {
            "type": "integer"
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "string",
                "description": "Human-readable message.",
                "example": "Rate limit exceeded"
              },
              "code": {
                "type": "string",
                "description": "Machine-readable code: unauthorized, app_suspended, first_party_only, rate_limited, username_required.",
                "example": "rate_limited"
              }
            },
            "required": [
              "error",
              "code"
            ]
          },
          "example": {
            "error": "Unauthorized",
            "code": "unauthorized"
          }
        }
      }
    },
    "403": {
      "description": "The app this key belongs to has been suspended by Dropfans. Every request fails with this until the app is reinstated — surface it to the creator and contact Dropfans.",
      "headers": {
        "X-RateLimit-Tier": {
          "description": "Rate-limit tier of the key: personal, app or first_party (first_party is unlimited).",
          "schema": {
            "type": "string",
            "enum": [
              "personal",
              "app",
              "first_party"
            ]
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "string",
                "description": "Human-readable message.",
                "example": "Rate limit exceeded"
              },
              "code": {
                "type": "string",
                "description": "Machine-readable code: unauthorized, app_suspended, first_party_only, rate_limited, username_required.",
                "example": "rate_limited"
              }
            },
            "required": [
              "error",
              "code"
            ]
          },
          "example": {
            "error": "This integration has been suspended by Dropfans. Contact the app developer.",
            "code": "app_suspended"
          }
        }
      }
    },
    "404": {
      "description": "No such item on this account.",
      "headers": {
        "X-RateLimit-Tier": {
          "description": "Rate-limit tier of the key: personal, app or first_party (first_party is unlimited).",
          "schema": {
            "type": "string",
            "enum": [
              "personal",
              "app",
              "first_party"
            ]
          }
        },
        "X-RateLimit-Limit": {
          "description": "Requests allowed per minute for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining": {
          "description": "Requests left in the current minute window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset": {
          "description": "Epoch seconds when the minute window resets.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Limit-Day": {
          "description": "Requests allowed per UTC day for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining-Day": {
          "description": "Requests left in the current UTC day window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset-Day": {
          "description": "Epoch seconds when the day window resets.",
          "schema": {
            "type": "integer"
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "string",
                "description": "Human-readable message describing what went wrong.",
                "example": "Vault item not found"
              }
            },
            "required": [
              "error"
            ]
          },
          "example": {
            "error": "Vault item not found"
          }
        }
      }
    },
    "429": {
      "description": "Rate limit exceeded for the current minute or day window. Wait Retry-After seconds and retry.",
      "headers": {
        "X-RateLimit-Tier": {
          "description": "Rate-limit tier of the key: personal, app or first_party (first_party is unlimited).",
          "schema": {
            "type": "string",
            "enum": [
              "personal",
              "app",
              "first_party"
            ]
          }
        },
        "X-RateLimit-Limit": {
          "description": "Requests allowed per minute for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining": {
          "description": "Requests left in the current minute window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset": {
          "description": "Epoch seconds when the minute window resets.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Limit-Day": {
          "description": "Requests allowed per UTC day for this key (absent on first_party).",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Remaining-Day": {
          "description": "Requests left in the current UTC day window.",
          "schema": {
            "type": "integer"
          }
        },
        "X-RateLimit-Reset-Day": {
          "description": "Epoch seconds when the day window resets.",
          "schema": {
            "type": "integer"
          }
        },
        "Retry-After": {
          "description": "Seconds to wait before retrying (sent with 429s).",
          "schema": {
            "type": "integer"
          }
        }
      },
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "string",
                "description": "Human-readable message.",
                "example": "Rate limit exceeded"
              },
              "code": {
                "type": "string",
                "description": "Machine-readable code: unauthorized, app_suspended, first_party_only, rate_limited, username_required.",
                "example": "rate_limited"
              }
            },
            "required": [
              "error",
              "code"
            ]
          },
          "example": {
            "error": "Rate limit exceeded",
            "code": "rate_limited"
          }
        }
      }
    }
  },
  "x-codeSamples": [
    {
      "lang": "cURL",
      "label": "curl",
      "source": "curl -X PATCH \"https://www.dropfans.io/api/external/vault/$VAULT_ITEM_ID/tags\" \\\n  -H \"Authorization: Bearer $DROPFANS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n  \"contentTags\": [\n    \"beach\",\n    \"bikini\"\n  ]\n}'"
    },
    {
      "lang": "JavaScript",
      "label": "Node",
      "source": "const vaultItemId = '…'; // from an earlier response\n\nconst res = await fetch(`https://www.dropfans.io/api/external/vault/${vaultItemId}/tags`, {\n  method: 'PATCH',\n  headers: {\n    Authorization: `Bearer ${process.env.DROPFANS_API_KEY}`,\n    'Content-Type': 'application/json',\n  },\n  body: JSON.stringify({\n    \"contentTags\": [\n      \"beach\",\n      \"bikini\"\n    ]\n  }),\n});\nconsole.log(await res.json());"
    },
    {
      "lang": "Python",
      "source": "import os\nimport requests\n\nvault_item_id = \"…\"  # from an earlier response\n\nres = requests.patch(\n    f\"https://www.dropfans.io/api/external/vault/{vault_item_id}/tags\",\n    headers={\"Authorization\": f\"Bearer {os.environ['DROPFANS_API_KEY']}\"},\n    json={\n        \"contentTags\": [\n            \"beach\",\n            \"bikini\",\n        ],\n    },\n)\nprint(res.json())"
    }
  ],
  "x-dropfans-docs": "https://www.dropfans.io/developers/reference/set-vault-item-tags"
}
```

---

Previous: [Move a vault item to a folder](https://www.dropfans.io/developers/reference/move-vault-item.md) · Next: [List vault folders](https://www.dropfans.io/developers/reference/list-folders.md) · All pages: [llms.txt](https://www.dropfans.io/developers/llms.txt)
