> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vibechain.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace a draft allowlist

> Replaces all entries, updates the enabled state, and calculates a Merkle root.



## OpenAPI

````yaml /api-reference/vibemarket_openapi.yml post /metadata/draft/whitelist
openapi: 3.0.3
info:
  title: vibe.market API
  version: 1.0.0
  description: |
    Production API for vibe.market packs, games, collections, creator drafts,
    allowlists, market activity, social features, recovery tools, and analytics.

    Most operations require a caller-specific VibeChain API key in the
    `API-KEY` header. Account-bound writes additionally require a vibe.market
    session token in `Authorization: Bearer <token>`. Public or Bearer-only
    exceptions are marked on the individual operation.
  contact:
    name: VibeChain developer support
    email: gm@vibechain.com
    url: https://docs.vibechain.com/api-reference/vibemarket-intro
servers:
  - url: https://build.vibechain.com/vibe/boosterbox
    description: Production
security:
  - ApiKeyAuth: []
tags:
  - name: Packs
    description: Read pack ownership, state, rarity, and metadata.
  - name: Collections
    description: Read collection holdings, statistics, and activity.
  - name: Games
    description: Discover games and read launch configuration.
  - name: Metadata
    description: Read published metadata and update launched collections.
  - name: Creator drafts
    description: Create, autosave, inspect, confirm, and delete launch drafts.
  - name: Allowlists
    description: Configure draft allowlists and generate Merkle proofs.
  - name: Activity
    description: Read recent packs and recover indexed transaction events.
  - name: Social
    description: Read chat, react to messages, and report collections.
  - name: Analytics
    description: Read price history, leaderboards, and platform totals.
  - name: Utility
    description: Resolve slugs, regions, prices, and processing readiness.
paths:
  /metadata/draft/whitelist:
    post:
      tags:
        - Allowlists
      summary: Replace a draft allowlist
      description: >-
        Replaces all entries, updates the enabled state, and calculates a Merkle
        root.
      operationId: replaceVibeMarketDraftAllowlist
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ReplaceAllowlistRequest'
      responses:
        '200':
          description: Allowlist replaced
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AllowlistMutationResponse'
        '400':
          $ref: '#/components/responses/InvalidInput'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/ApiKeyOrRateLimit'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - ApiKeyAuth: []
          BearerAuth: []
components:
  schemas:
    ReplaceAllowlistRequest:
      type: object
      required:
        - draftId
        - whitelistEnabled
        - entries
      properties:
        draftId:
          $ref: '#/components/schemas/ObjectId'
        whitelistEnabled:
          type: boolean
        entries:
          type: array
          items:
            $ref: '#/components/schemas/AllowlistEntry'
    AllowlistMutationResponse:
      type: object
      required:
        - success
      properties:
        success:
          type: boolean
          enum:
            - true
        message:
          type: string
        whitelistEnabled:
          type: boolean
        merkleRoot:
          type: string
          nullable: true
          pattern: ^0x[a-fA-F0-9]{64}$
        entriesCount:
          type: integer
          minimum: 0
        total:
          type: integer
          minimum: 0
        alreadyExists:
          type: boolean
    ObjectId:
      type: string
      pattern: ^[a-fA-F0-9]{24}$
      example: 66b1234567890abcdef12345
    AllowlistEntry:
      type: object
      required:
        - address
      properties:
        address:
          $ref: '#/components/schemas/EvmAddress'
        userId:
          type: string
        username:
          type: string
        profileImage:
          type: string
          format: uri
    Error:
      type: object
      required:
        - success
        - message
      properties:
        success:
          type: boolean
          enum:
            - false
        message:
          type: string
        error:
          description: >-
            Optional diagnostic detail. Do not depend on this field being
            present in production.
          oneOf:
            - type: string
            - type: object
              additionalProperties: true
    EvmAddress:
      type: string
      pattern: ^0x[a-fA-F0-9]{40}$
      example: '0x1111111111111111111111111111111111111111'
  responses:
    InvalidInput:
      description: Invalid or incomplete request input
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            message: Invalid contract address
    Unauthorized:
      description: Bearer token missing, expired, or invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            message: Unauthorized - No token provided
    Forbidden:
      description: The signed-in account does not control the requested creator resource
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            message: Forbidden
    NotFound:
      description: Requested resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            message: Resource not found
    ApiKeyOrRateLimit:
      description: API key missing/invalid or the caller's rate allowance is exhausted
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            message: >-
              Too many requests or invalid API key! See docs.vibechain.com for
              more info.
    InternalError:
      description: The server could not complete the operation
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            success: false
            message: Failed to complete request
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: API-KEY
      description: Caller-specific VibeChain API key used for quota and abuse control.
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Signed-in vibe.market session token. The account's linked wallets
        determine creator ownership.

````