# List, retrieve, then update a secure token via JSON Patch.

List, retrieve, then update a secure token via JSON Patch.

1. OPTIONAL — lists secure tokens on the terminal, filtered by customer name, and extracts the first result's `secureTokenId`. Skip if you already hold the `secureTokenId`.
 [listSecureTokens](/api/list-secure-tokens)
2. OPTIONAL — retrieve the secure token to confirm its current state before patching. Surfaces the token `status` and the replayable `token` value.
 [getSecureToken](/api/get-secure-token)
3. Partially update the secure token with an RFC 6902 JSON Patch document (the `patchDocument` input), NOT a plain resource object. Immutable fields (processingTerminalId, type, token, status, and sensitive source fields such as cardNumber/routingNumber) cannot be patched. Requires a unique `Idempotency-Key` header. Returns 200.
 [updateSecureToken](/api/update-secure-token)

## Workflow diagram

```mermaid
flowchart TD
  step0["1. token search · API"]
  step1["2. token lookup · API"]
  step0 --> step1
  step2["3. JSON Patch update · API"]
  step1 --> step2
```
