> ## Documentation Index
> Fetch the complete documentation index at: https://www.vitalog.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update browser profile

> Update the root account display name using a browser session. Email and password remain environment-managed. Health records are unaffected.



## OpenAPI

````yaml /openapi.json patch /auth/profile
openapi: 3.1.1
info:
  title: Vitalog
  version: 1.0.1
  description: >-
    Single-user structured observations with equivalent REST and MCP domain
    services. Environment AUTH_KEY or revocable personal Bearer keys with
    required name, permissions and explicit expiry (including Never); Primary
    key management requires AUTH_KEY; the UI uses separate, root-verified
    30-minute management sessions. MCP clients use OAuth authorization code with
    S256 PKCE, issued after root sign-in. Clients are resolved through HTTPS
    metadata, pre-registration or dynamic registration. OAuth tokens grant MCP
    access only.
servers:
  - url: https://vitalog-api.example.com
    description: Production REST and MCP API
  - url: http://localhost:3000
    description: Loopback development; production requires TLS ingress
security: []
paths:
  /auth/profile:
    patch:
      tags:
        - Account settings
      summary: Update browser profile
      description: >-
        Update the root account display name using a browser session. Email and
        password remain environment-managed. Health records are unaffected.
      operationId: update_browser_profile
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 120
              required:
                - name
              additionalProperties: false
      responses:
        '200':
          description: >-
            Update the root account display name using a browser session. Email
            and password remain environment-managed. Health records are
            unaffected.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  name:
                    type: string
                    minLength: 1
                    maxLength: 120
                  email:
                    type: string
                    format: email
                    pattern: >-
                      ^(?:[A-Za-z0-9_'+\-]+\.)*[A-Za-z0-9_'+\-]*[A-Za-z0-9_+-]@(?:[A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
                  preferences:
                    type: object
                    properties:
                      dateFormat:
                        $ref: '#/components/schemas/Schema_2dc3849296b6___schema0'
                      timeFormat:
                        $ref: '#/components/schemas/Schema_2dc3849296b6___schema1'
                      timeZone:
                        $ref: '#/components/schemas/Schema_2dc3849296b6___schema2'
                    required:
                      - dateFormat
                      - timeFormat
                      - timeZone
                    additionalProperties: false
                    description: >-
                      Display preferences default to day-short-month-year,
                      24-hour and UTC. Saved choices and recorded dates remain
                      unchanged.
                required:
                  - name
                  - email
                  - preferences
                additionalProperties: false
        '401':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - browserSession: []
components:
  schemas:
    Schema_2dc3849296b6___schema0:
      type: string
      enum:
        - day-short-month-year
        - short-month-day-year
        - year-month-day
        - day-month-year
        - month-day-year
    Schema_2dc3849296b6___schema1:
      type: string
      enum:
        - 24-hour
        - 12-hour
        - 24-hour-seconds
        - 12-hour-seconds
    Schema_2dc3849296b6___schema2:
      type: string
      minLength: 1
      maxLength: 100
    Error:
      type: object
      additionalProperties: false
      required:
        - code
        - message
        - catalog_version
        - issues
      properties:
        code:
          type: string
          enum:
            - VALIDATION_ERROR
            - NOT_FOUND
            - VERSION_CONFLICT
            - IDEMPOTENCY_CONFLICT
            - DAILY_TOTAL_EXISTS
            - CATALOG_VERSION_MISMATCH
            - LIMIT_EXCEEDED
            - UNAUTHORIZED
            - FORBIDDEN
            - RATE_LIMITED
            - UNAVAILABLE
            - TIMEOUT
            - INTERNAL_ERROR
        message:
          type: string
        catalog_version:
          type: string
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              reason:
                type: string
              message:
                type: string
              suggested_keys:
                type: array
                items:
                  type: string
              discovery:
                type: object
        existing_id:
          type: string
        current_version:
          type: integer
        current_catalog_version:
          type: string
  securitySchemes:
    browserSession:
      type: http
      scheme: bearer
      description: >-
        Opaque vls_ browser token, valid for 30 days unless revoked. Read-only
        REST access. The UI stores it in a host-only HttpOnly SameSite=Lax
        cookie; it never reaches browser JavaScript. Key administration and MCP
        reject this token.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.