## Update a VAT rate

`PATCH /v1/catalog-vat-rates/:id`

Partially updates a VAT rate in the product catalog. Send only the fields to change in a flat body, without a `fields` wrapper.

## Parameters

| Parameter | Type | Required | Description |
|------|------|------|------|
| `id` (path) | number | yes | VAT rate identifier, a non-negative integer. List: [`GET /v1/catalog-vat-rates`](/docs/entities/catalog-vat-rates/list). |

## Request body fields

| Field | Type | Required | Description |
|------|------|------|------|
| `name` | string | no | VAT rate name. |
| `rate` | number | no | VAT percentage. Fractional numbers and `0` are accepted. `null` is not accepted. |
| `active` | string | no | Status: `Y` or `N`. Other values and `null` are rejected. |
| `sort` | number | no | Sort order, an integer of at least `1`. `null` is not accepted. |
| `id` | number | no | `RO`. Set only in the path. Passing it in the body returns `400 READONLY_FIELD`. |
| `timestampX` | string | no | `RO`. The modification time is set by Bitrix24. Passing it in the body returns `400 READONLY_FIELD`. |

## Examples

### curl — personal key

```bash
curl -X PATCH "https://vibecode.bitrix24.com/v1/catalog-vat-rates/25" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Docs VAT updated 2026-10-08"
}'
```

### curl — OAuth application

```bash
curl -X PATCH "https://vibecode.bitrix24.com/v1/catalog-vat-rates/25" \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Docs VAT updated 2026-10-08"
}'
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/catalog-vat-rates/25', {
  method: 'PATCH',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "name": "Docs VAT updated 2026-10-08"
  }),
})

const { success, data } = await res.json()
console.log(data)
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/catalog-vat-rates/25', {
  method: 'PATCH',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "name": "Docs VAT updated 2026-10-08"
  }),
})

const { success, data } = await res.json()
console.log(data)
```

## Response fields

On success, returns `200` and the complete updated record.

| Field | Type | Description |
|------|------|------|
| `success` | boolean | Always `true` on success. |
| `data` | object | VAT rate object. |
| `data.id` | number | VAT rate identifier. List: [`GET /v1/catalog-vat-rates`](/docs/entities/catalog-vat-rates/list). Pass it as the product's `vatId`. |
| `data.name` | string | VAT rate name. |
| `data.rate` | number \| null | VAT percentage. For an existing "No VAT" rate, this field may be `null`. |
| `data.active` | string | Rate status: `Y` — active, `N` — inactive. |
| `data.sort` | number | Sort order. |
| `data.timestampX` | string | Modification date and time in ISO 8601 format. Set by Bitrix24. |
| `meta.warnings` | array | For an unknown field name, contains an `UNRECOGNIZED_WRITE_FIELD` warning with `code`, `field`, and `message` keys. |

## Response example

```json
{
  "success": true,
  "data": {
    "active": "N",
    "id": 25,
    "name": "Docs VAT updated 2026-10-08",
    "rate": 7.5,
    "sort": 900,
    "timestampX": "2026-10-08T18:50:04.000Z"
  }
}
```

## Error response example

422 — `rate` is `null`. The rate is not changed:

```json
{
  "success": false,
  "error": {
    "code": "BITRIX_ERROR",
    "message": "Required fields: rate",
    "b24Code": "0"
  }
}
```

## Errors

| HTTP | Code | Description |
|------|------|------|
| 404 | `ENTITY_NOT_FOUND` | No VAT rate exists with this `id`, including after deletion. |
| 400 | `INVALID_PARAMS` | `id` is not a non-negative integer, for example `abc`. |
| 400 | `EMPTY_UPDATE_BODY` | The body is empty or is not a JSON object. Provide at least one field. |
| 400 | `INVALID_PARAMS` | An invalid field type, `active` outside `Y`/`N`, or a fractional or non-positive `sort`. `active` and `sort` cannot be `null`. |
| 400 | `READONLY_FIELD` | The body contains `id` or `timestampX`. Remove the field from the request. |
| 422 | `BITRIX_ERROR` | `rate: null` is rejected with `Required fields: rate`. For other errors returned by Bitrix24, see `error.message` and `error.b24Code`. |
| 403 | `WRITE_BLOCKED_READONLY_KEY` | Writes are blocked: the key is read-only. |
| 403 | `SCOPE_DENIED` | The key does not have the `catalog` scope. |
| 401 | `MISSING_API_KEY` | The `X-Api-Key` header is missing. |
| 401 | `TOKEN_MISSING` | The key has no configured Bitrix24 tokens. For an OAuth application key, check the user session. |

For all common API errors, see [Errors](/docs/errors).

## Known specifics

**A single PATCH does not require repeating `name` and `rate`.** If a field is omitted, Vibecode supplies the rate's current value before updating it. An explicit `null` is not replaced. If an existing rate has `rate: null`, provide a numeric `rate`; otherwise Bitrix24 may reject a change to another field.

**A misspelled field may not be saved.** An unknown name does not bypass required-field validation. The response may contain `meta.warnings` with `UNRECOGNIZED_WRITE_FIELD`. Check names against [VAT rate fields](/docs/entities/catalog-vat-rates/fields) and verify the values in `data`.

## See also

- [Get a VAT rate](/docs/entities/catalog-vat-rates/get)
- [Create a VAT rate](/docs/entities/catalog-vat-rates/create)
- [List VAT rates](/docs/entities/catalog-vat-rates/list)
- [Delete a VAT rate](/docs/entities/catalog-vat-rates/delete)
- [VAT rate fields](/docs/entities/catalog-vat-rates/fields)
- [Batch](/docs/batch)
- [Limits and optimization](/docs/optimization)
