> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pilotstatus.com.br/llms.txt
> Use this file to discover all available pages before exploring further.

# Publish Flow

> Publishes the Flow on Meta. **IRREVERSIBLE**: a published Flow is never edited or unpublished again — it can only be cloned into a new one (`POST /v1/flows` with `cloneFromFlowId`).

**`confirm: true` is required, strictly.** The check is `=== true`, so `"true"`, `1` and `{}` are all refused: the cost of accepting too little is a 400, the cost of accepting too much is a Flow nobody can unpublish. Without the field the answer is 400 `FLOW_PUBLISH_REQUIRES_CONFIRMATION`.

A truncated body is not read as an empty one — the payload is parsed from raw text so `{"confirm": true` (one missing brace) is 400 `FLOW_BODY_INVALID` rather than a confusing "confirmation required". Never reachable through `PATCH`. Permission `flows:manage`.

**Requires a number-scoped key.** A tenant-scoped key must name the number with the `x-whatsapp-number-id` header, or it gets 403 `TENANT_SCOPE_NOT_ALLOWED`.



## OpenAPI

````yaml openapi.json POST /v1/flows/{id}/publish
openapi: 3.1.0
info:
  title: Pilot Status API
  version: 1.0.0
  license:
    name: Pilot Status Terms of Service
    url: https://pilotstatus.com.br/terms
  description: >-
    Public REST API for Pilot Status. Authenticate with the `x-api-key: ps_...`
    header (or `x-api-key-id`). Base URL: https://pilotstatus.com.br
servers:
  - url: https://pilotstatus.com.br
security:
  - apiKey: []
  - apiKeyId: []
paths:
  /v1/flows/{id}/publish:
    post:
      tags:
        - Flows
      summary: Publish Flow
      description: >-
        Publishes the Flow on Meta. **IRREVERSIBLE**: a published Flow is never
        edited or unpublished again — it can only be cloned into a new one
        (`POST /v1/flows` with `cloneFromFlowId`).


        **`confirm: true` is required, strictly.** The check is `=== true`, so
        `"true"`, `1` and `{}` are all refused: the cost of accepting too little
        is a 400, the cost of accepting too much is a Flow nobody can unpublish.
        Without the field the answer is 400
        `FLOW_PUBLISH_REQUIRES_CONFIRMATION`.


        A truncated body is not read as an empty one — the payload is parsed
        from raw text so `{"confirm": true` (one missing brace) is 400
        `FLOW_BODY_INVALID` rather than a confusing "confirmation required".
        Never reachable through `PATCH`. Permission `flows:manage`.


        **Requires a number-scoped key.** A tenant-scoped key must name the
        number with the `x-whatsapp-number-id` header, or it gets 403
        `TENANT_SCOPE_NOT_ALLOWED`.
      operationId: post_flows_id_publish
      parameters:
        - name: id
          in: path
          required: true
          description: >-
            The **local** id of the Flow — the `id` field `GET /v1/flows`
            returns, never `metaFlowId`.
          schema:
            type: string
          example: cmf1a2b3c4d5e6f7g8h9i0j1
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - confirm
              properties:
                confirm:
                  type: boolean
                  enum:
                    - true
                  description: >-
                    Must be the boolean `true`, exactly. Acknowledges that
                    publishing cannot be undone.
                  example: true
            example:
              confirm: true
      responses:
        '200':
          description: Flow published on Meta. Irreversible
          content:
            application/json:
              example:
                flowId: cmf1a2b3c4d5e6f7g8h9i0j1
                published: true
        '400':
          description: >-
            `FLOW_PUBLISH_REQUIRES_CONFIRMATION`, `FLOW_BODY_INVALID`,
            `FLOW_UNKNOWN_FIELDS`, `FLOW_NUMBER_FROM_KEY`, or a Meta refusal
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Portuguese half
                  errorEN:
                    type: string
                    description: English half
                  code:
                    type: string
              example:
                error: >-
                  Publicar é irreversível: um Flow publicado não pode mais ser
                  editado, apenas clonado. Envie `"confirm": true` (booleano,
                  exatamente) para prosseguir.
                errorEN: >-
                  Publishing is irreversible: a published Flow can no longer be
                  edited, only cloned. Send `"confirm": true` (a boolean,
                  exactly) to proceed.
                code: FLOW_PUBLISH_REQUIRES_CONFIRMATION
        '401':
          description: Missing or invalid `x-api-key` / `x-api-key-id` header
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  code:
                    type: string
              example:
                error: Unauthorized
        '403':
          description: >-
            Tenant-scoped key used on a number-scoped endpoint, or the key's
            role lacks the permission
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  code:
                    type: string
              example:
                error: Tenant-scoped keys cannot call number endpoints
                code: TENANT_SCOPE_NOT_ALLOWED
        '404':
          description: >-
            No Flow with that id inside the key's own WABA. Never 403: a Flow of
            another tenant is indistinguishable from one that does not exist, on
            purpose — a 403 would confirm someone else's id to whoever guessed
            it
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Portuguese half
                  errorEN:
                    type: string
                    description: English half
                  code:
                    type: string
              example:
                error: Flow não encontrado para o número desta chave.
                errorEN: Flow not found for this key's number.
                code: FLOW_NOT_FOUND
        '409':
          description: >-
            The Flow has left `DRAFT`. Publishing is irreversible on Meta —
            clone it to start a new version
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Portuguese half
                  errorEN:
                    type: string
                    description: English half
                  code:
                    type: string
              example:
                error: >-
                  Este Flow já foi publicado na Meta e não pode mais ser
                  alterado. Clone-o para criar uma nova versão.
                errorEN: >-
                  This Flow is already published on Meta and can no longer be
                  changed. Clone it to create a new version.
                code: FLOW_NOT_DRAFT
        '422':
          description: >-
            The key's number is not a Meta (Cloud API) number, or has no WABA
            behind it
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Portuguese half
                  errorEN:
                    type: string
                    description: English half
                  code:
                    type: string
              example:
                error: >-
                  Flows existem apenas em números Meta (API Oficial). O número
                  desta chave não é Meta ou não tem uma WABA associada — use uma
                  chave de um número Meta.
                errorEN: >-
                  Flows only exist on Meta (Cloud API) numbers. This key's
                  number is not a Meta number, or has no WABA behind it — use a
                  key bound to a Meta number.
                code: FLOW_REQUIRES_META_NUMBER
        '429':
          description: Rate limit exceeded
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  code:
                    type: string
              example:
                error: Too many requests
        '500':
          description: >-
            Internal error. Never carries the internal message — that belongs in
            the log
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: Portuguese half
                  errorEN:
                    type: string
                    description: English half
                  code:
                    type: string
              example:
                error: Erro interno do servidor.
                errorEN: Internal server error.
                code: INTERNAL_ERROR
components:
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: Your ps_ API key
    apiKeyId:
      type: apiKey
      in: header
      name: x-api-key-id
      description: API key id (alternative to x-api-key)

````