> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hydradb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update Connector Resource

> Change one resource's ingestion instructions or access rule, leaving everything else as it is.

Updates one configured resource in place. Send `custom_instructions`, `acl`, or both. At least one is required, and any field you omit is left unchanged. This is the safe way to edit a resource that is already syncing.

`resource_id` in the path is the id from [List Connector Resources](/api-reference/v2/endpoint/connector-resources), for example a Slack channel id or a Supabase `schema.table` name. URL-encode it if it contains spaces or other reserved characters.

* **`custom_instructions`** sets instructions for documents from this resource only. They **replace** the connector-level instructions for this resource rather than adding to them. Send `""` to clear them so the resource uses the connector's instructions again. Up to 4,000 characters. They apply from the next sync; documents already synced are not processed again. See [Custom Ingestion Instructions](/essentials/v2/connector-instructions).
* **`acl`** sets who can read this resource's objects, and applies to already-synced objects on the next query, with no re-sync. Use `["__public__"]` to open the resource to everyone and `[]` to allow nobody. For providers whose own permissions HydraDB reads, those permissions take over again at the next sync; your rule applies whenever the provider reports the resource as public or its permissions cannot be read. See [Access Control](/essentials/v2/access-control).

<RequestExample>
  ```bash cURL theme={"dark"}
  curl -X PATCH 'https://api.hydradb.com/connectors/{id}/resources/{resource_id}' \
    -H "Authorization: Bearer $HYDRA_DB_API_KEY" \
    -H "API-Version: 2" \
    -H "Content-Type: application/json" \
    -d '{
      "custom_instructions": "These threads are incident retros. Extract root cause, impact and owner."
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={"dark"}
  {
    "connector_id": "{connector_id}",
    "resource_id": "{resource_id}",
    "custom_instructions": "These threads are incident retros. Extract root cause, impact and owner.",
    "custom_instructions_updated": true
  }
  ```
</ResponseExample>

The response includes `custom_instructions` and `acl` only when the request set them, showing the stored values.

## Errors

* `400`: neither field was sent, `custom_instructions` is over 4,000 characters, or the access rule is malformed. Nothing is changed.
* `404`: no connector with this id in your workspace, or no configured resource with this `resource_id` on it.

<div className="api-before-related-resources" />

## Related Resources

* [Update Connector](/api-reference/v2/endpoint/update-connector): set the connector-level instructions these override
* [Custom Ingestion Instructions](/essentials/v2/connector-instructions): how connector and resource instructions combine
* [List Connector Resources](/api-reference/v2/endpoint/connector-resources): read the stored values back


## OpenAPI

````yaml api-reference/v2/openapi.json PATCH /connectors/{id}/resources/{resource_id}
openapi: 3.1.0
info:
  contact:
    email: support@hydradb.com
    name: HydraDB Support
  description: >-
    HydraDB Application API — knowledge ingestion, search, and memory
    management.
  license:
    name: Proprietary
  title: HydraDB Application API
  version: 0.1.0
servers:
  - description: Production server
    url: https://api.hydradb.com
security: []
externalDocs:
  description: ''
  url: ''
paths:
  /connectors/{id}/resources/{resource_id}:
    patch:
      tags:
        - connectors
      summary: Update a resource's ACL rule or custom instructions
      description: >-
        Update one configured resource's settings without re-sending the rest of
        it. `custom_instructions` sets this resource's ingestion instructions
        (`""` clears them back to the connector's), applied from the next sync.
        `acl` sets who can read the resource's objects and applies to
        already-synced objects immediately. For providers whose permissions
        HydraDB reads, the provider's own restrictions take over again at the
        next sync; your rule applies whenever the provider reports the resource
        as public or its permissions cannot be read. Send at least one of the
        two; omitted fields are left unchanged.
      parameters:
        - description: Connector ID
          in: path
          name: id
          required: true
          schema:
            example: HydraDoc1234
            type: string
        - description: Resource ID
          in: path
          name: resource_id
          required: true
          schema:
            example: C0123456789
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/handler.resourceUpdateReq'
        description: Resource settings to change
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/handler.resourceUpdateResponse'
          description: OK
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/handler.ErrorResponse'
          description: Bad Request
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/handler.ErrorResponse'
          description: Not Found
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/handler.ErrorResponse'
          description: Internal Server Error
      security:
        - BearerAuth: []
components:
  schemas:
    handler.resourceUpdateReq:
      properties:
        acl:
          description: >-
            Who can read this resource's objects: emails,
            `group:<provider>:<id>`, `domain:<domain>`, or `["__public__"]`.
            `[]` allows nobody. Provider permissions, where read, take over at
            the next sync.
          items:
            type: string
          type: array
          uniqueItems: false
        custom_instructions:
          description: >-
            Ingestion and indexing instructions for this resource, replacing the
            connector's. Omit to leave unchanged; `""` clears back to the
            connector's. Up to 4000 characters, applied from the next sync.
          type: string
      type: object
    handler.resourceUpdateResponse:
      properties:
        acl:
          description: The access rule as stored. Present only when the request set `acl`.
          items:
            type: string
          type: array
          uniqueItems: false
        connector_id:
          description: Connector this resource belongs to.
          example: conn_abc123
          type: string
        custom_instructions:
          description: >-
            The resource's instructions as stored; `""` means they were cleared.
            Present only when the request set them.
          type: string
        custom_instructions_updated:
          description: >-
            `true` when this request set or cleared the resource's
            `custom_instructions`.
          example: true
          type: boolean
        resource_id:
          description: Resource identifier from the Discover endpoint.
          example: C0123456789
          type: string
      type: object
    handler.ErrorResponse:
      properties:
        data:
          description: Always `null` on this error response.
        detail:
          $ref: '#/components/schemas/handler.ErrorDetail'
          description: Structured error detail with code, message, and deprecation hints.
          example:
            deprecated: true
            deprecated_field: tenant_id
            error_code: VALIDATION_ERROR
            message: Request validation failed
            preferred_field: database
        error:
          $ref: '#/components/schemas/handler.apiError'
          description: Error message, empty string on success.
          example:
            code: DATABASE_NOT_FOUND
            message: Database not found
        meta:
          $ref: '#/components/schemas/handler.ErrorMeta'
          example:
            latency_ms: 12.3
            request_id: 9d13aef4-02f4-4e73-8c62-4c2601d04f9d
        success:
          description: Whether the request succeeded.
          example: false
          type: boolean
      type: object
    handler.ErrorDetail:
      properties:
        deprecated:
          description: Whether this response concerns a deprecated field or route.
          example: true
          type: boolean
        deprecated_field:
          description: The deprecated field name.
          example: tenant_id
          type: string
        error_code:
          description: Machine-readable error classification code.
          example: VALIDATION_ERROR
          type: string
        message:
          description: Human-readable description of the error.
          example: Request validation failed
          type: string
        preferred_field:
          description: The canonical replacement for the deprecated field.
          example: database
          type: string
        success:
          deprecated: true
          description: >-
            Deprecated: always `false`. Read the HTTP status, then `error.code`
            and `error.message`.
          example: false
          type: boolean
          x-deprecated: 'true'
      type: object
    handler.apiError:
      properties:
        code:
          description: Machine-readable error code (e.g. `DATABASE_NOT_FOUND`).
          example: DATABASE_NOT_FOUND
          type: string
        message:
          description: Human-readable description of the error.
          example: Database not found
          type: string
      type: object
    handler.ErrorMeta:
      properties:
        api_version:
          description: Version of the API that served the request, for example `2.0.1`.
          type: string
        latency_ms:
          description: Server-side processing time in milliseconds.
          example: 12.3
          type: number
        request_id:
          description: Unique identifier for this request, useful for support and tracing.
          example: 9d13aef4-02f4-4e73-8c62-4c2601d04f9d
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: API key
      description: 'API key sent as a Bearer token: "Bearer prefix.secret"'
      scheme: bearer
      type: http

````