Users
Update User
Updates the details and permissions of a user.
PATCH /api/users/:id
Request Body
{
"firstName": "Jane",
"lastName": "Smith",
"role": "admin",
"isActive": true,
"customerIds": ["11111111-1111-4111-8111-111111111111", "22222222-2222-4222-8222-222222222222"] // Update the list of assigned customers via public IDs
}Notes:
customerIdsaccepts customer public IDs and legacy numeric IDs.- Public IDs are the preferred format for new integrations.
firstNameandlastNameare limited to 100 characters,rolemust be one ofadmin,editor,readonly,responder,customerIdsholds at most 500 entries.- The global platform flags (
isGlobalAdmin,isGlobalSupporter) cannot be set through this endpoint; they are ignored if sent.
Guards
- You cannot deactivate yourself or change your own role.
- The last active admin of an organization cannot be demoted or deactivated. Promote another user to
adminfirst. - A user who is a global admin or global supporter can only be modified by a global admin.
Common errors
400 Bad Requestwhen the body fails validation (unknown field type, string too long,customerIdsnot an array)400 Bad Requestwithdata.code: "invalidRole"whenroleis not one of the allowed values400 Bad Requestwithdata.code: "userSelfChangeForbidden"when you try to deactivate yourself or change your own role400 Bad Requestwithdata.code: "lastAdminProtected"when the change would leave the organization without an active admin403 Forbiddenwithdata.code: "globalUserProtected"when a tenant admin tries to modify a global admin or global supporter404 Not Foundwhen the user does not exist in your organization
Response
Returns the updated user object. See Error Codes for error responses.