How to use this reference
Editorial synthesis: document caller authorization, the selected change set and server-enforced field mutability as separate contracts. Valid field selection does not establish permission to change it. Preserve each nested field's behavior independently of its parent, and keep business-state transitions outside generic updates when the API contract requires dedicated operations.
Before reading
- Basic familiarity with resource-oriented APIs, partial updates and access-control modeling
Context and limits
- AIP-161's Created and Updated headers both show 2021-03-01. Its displayed output-only changelog date is 2023-10-18, while the corresponding first-party commit is timestamped 2023-10-19T15:57:39Z. A later 2025-03-28 commit added an AIP-157 link; neither header nor newest displayed changelog establishes the last source revision.
- AIP-203's headers show 2018-07-17 and its newest displayed changelog entry is 2023-09-14, although a reviewed 2026-06-25 commit adds an optional-field clarification. AIP-134's headers show 2019-01-24 while its newest displayed changelog entry is 2025-10-03. These dates are not interchangeable publication or edition dates.
- AIP-203 forbids an error merely because output-only input is present and requires it to be cleared or ignored. This differs from immutable input, for which unchanged values should be ignored and changes should cause a validation error. Nested field behavior is independent of its parent's annotation.
- AIP-134 says generic updates should avoid side effects and state fields must not be directly writable through them. The separation of field selection from caller authorization is editorial synthesis; these AIPs' explicit rules concern field behavior and update semantics.
- These are Google API design requirements, not universal protocol guarantees or proof that a particular service enforces them. This resource establishes no incident, affected deployment, bounty, exploitability or testing authorization.
Sources and provenance
- AIP-161: Field masks Google · reviewed 2026-10-04
- AIP-203: Field behavior documentation Google · reviewed 2026-10-04
- AIP-134: Standard methods: Update Google · reviewed 2026-10-04
- AIP-161/AIP-203: converge output-only update-mask guidance Google AIP maintainers · reviewed 2026-10-04
- AIP-161: link to AIP-157 Google AIP maintainers · reviewed 2026-10-04
- AIP-203: clarify optional field presence and field behavior Google AIP maintainers · reviewed 2026-10-04
Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.