---
title: "Update an existing customer profile."
method: PUT
path: "/programs/{programCode}/externalAccounts/customers/{customerToken}"
tags: ["ExternalAccount"]
---

# Update an existing customer profile.

`PUT /programs/{programCode}/externalAccounts/customers/{customerToken}`

Update an existing customer profile with encrypted data. The customer profile must exist and the request must be authorized.

## Path parameters

- `programCode` string, required
- `customerToken` string, required

## Headers

- `X-GD-RequestId` string, required
- `X-GD-CustomerType` string

## Request body

- UpdateCustomerProfileGlobalFundTransferRequestEncrypted — Update Customer Profile Global Fund Transfer Request (Encrypted) – Used for secure scenarios where customer data is provided encrypted. Contains the encrypted customer profile data.
  - `encryptedData` EncryptedData — Represents a container for encrypted data used in secure data transfer operations. Contains the encrypted payload and associated cryptographic metadata, including encryption version, ephemeral public key, and public key hash. Used to securely transmit sensitive information such as user data, ensuring confidentiality and integrity during transport.
    - `version` string, nullable — The version of the encryption algorithm used to encrypt the data (e.g., "v1", "v2").
    - `ephemeralPublicKey` string, nullable — The ephemeral public key used in the encryption process, typically for key exchange or session establishment.
    - `publicKeyHash` string, nullable — The hash of the public key used to verify the integrity and authenticity of the encryption key.
    - `data` string, nullable — The encrypted data payload, typically base64-encoded, containing the sensitive information.
  - `salt` string, nullable — Unique id in GUID format, must match the RequestID in the headers. Used for idempotency and encryption.

## Response `200`

Customer profile updated successfully.

- UpdateCustomerProfileGlobalFundTransferResponse — Represents the response returned after updating a customer profile for global fund transfer operations. Contains the unique customer token for future actions and the status of the profile update. Inherits standard response metadata from Gd.Bos.DataTransfer.Response.ResponseBase.
  - `customerToken` string, nullable — Unique token identifying the customer profile. Used for subsequent operations such as linking cards or banks.
  - `status` string, nullable — The status of the customer profile after the update (e.g., Pending, Active, Suspended).
  - `responseDetails` ResponseDetail[], nullable — Required: A list of response details providing status codes, descriptions, and additional information about the result of the operation.
    - `code` integer — The primary status or error code for the response (e.g., 200 for success, 400 for validation error).
    - `subCode` integer, nullable — An optional subcode providing more granular detail about the response or error.
    - `description` string, nullable — A human-readable description of the response, error, or status.
    - `url` string, nullable — A URL linking to documentation or a web page with more information about the response code.

## Other responses

- `400` — Invalid or missing parameters.
- `401` — Unauthorized access.
- `403` — Forbidden
- `500` — Internal Server Error
- `503` — Service unavailable.

---

[API](https://skmtc.net/greendot/apis/baas-apis.md) · [All operations](https://skmtc.net/greendot/apis/baas-apis/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/greendot/baas-apis/versions/666553766b78/schema)
