---
deprecated: true
search:
  tags:
    - Multitenancy Recipe
    - PUT
seo:
  description: >-
    This API is deprecated. Please use the v2 version of this API. In… Reference
    for the PUT /recipe/multitenancy/app endpoint in the Core Driver Interface
    API.
sidebar:
  badge: PUT
  label: Upsert app (deprecated)
title: Upsert app (deprecated)
type: openapi-operation
---
This API is deprecated. Please use the v2 version of this API. In the v2 version of the API, the login methods are no longer enabled using the `emailPasswordEnabled`, `thirdPartyEnabled` and `passwordlessEnabled` inputs. Instead, they are enabled using factorIds (such as emailpassword, otp-email, etc) specified in the `firstFactors` and `requiredSecondaryFactors` inputs. Please refer [Multitenancy Docs](https://supertokens.com/docs/multitenancy/new-tenant) to know the list of factorIds available.

Note: This deprecated API still accepts those `emailPasswordEnabled`, `thirdPartyEnabled` and `passwordlessEnabled` inputs for backward compatibility.

Create or update an app.
SuperTokens subscription license key is required.

If creating a new app, only the login methods set to true will be enabled and rest will be disabled by default.

`firstFactors` and `requiredSecondaryFactors` can be set to null to remove all entries in the core, or a non empty string array to be updated in the core. Setting of empty array is disallowed.

Note: the create/update will fail if a login method is not enabled and a relavant factor is added to either `firstFactors` or `requiredSecondaryFactors`. For example, `emailPasswordEnabled` cannot be set to `false` if `emailpassword` is present in the `firstFactors` array.

If updating an existing app,
1. core will keep the existing state of login methods and only update the ones that are specified in the request body.
2. Core config will be merged into existing config. To delete a key in the config, use a null value

Note: the newly created app will use the same connection uri domain from which
this request originates and the request must originate from public app and public tenant.

Note: Updation of core config is not allowed for the default connectionUriDomain, public app. In order to update config for the default connectionUriDomain and public app, you must edit the config.yaml or the docker env directly.

<Operation source="references-cdi" id="createorupdateappput" />
