# Update a user

> Source: https://docs.clonepartner.com/api-reference/users/update-user/

`PUT /api/users/{id}`

Superadmin can update any user (except self-delete). Admins can only update viewers.
Superadmin role cannot be assigned via this endpoint.

**Operation ID:** `updateUser`

## Authentication

### Option 1

- **BearerAuth** (`http bearer`)
  API key token. Create via POST /api/api-keys. Format: `envoy_<hex>`

### Option 2

- **CookieAuth** (`apiKey`)
  Session cookie set after login + TOTP verification

## Path parameters

- `id` — `integer`, `required`
  Resource ID

## Request body

The request body is required.

### `application/json`

- Type: `object`
- Properties:
  - `username` (`string`)
  - `password` (`string`)
  - `role` (`string`)
    - Allowed values: `admin`, `viewer`

## Success responses

### 200

User updated

**Content type:** `application/json`

- Reference: `UserSafe`
  - Type: `object`
  - Properties:
    - `id` (`integer`)
    - `username` (`string`)
    - `role` (`string`)
      - Allowed values: `superadmin`, `admin`, `viewer`
    - `totp_verified` (`integer`)
      - Allowed values: `0`, `1`
    - `invite_pending` (`boolean`)
    - `created_at` (`string`)
      - Format: `date-time`
    - `updated_at` (`string`)
      - Format: `date-time`

## Error responses

### 400

Validation error

**Content type:** `application/json`

- Reference: `Error`
  - Type: `object`
  - Properties:
    - `error` (`string`)
      - Example: `NOT_FOUND`
    - `message` (`string`)
      - Example: `Resource not found`

Example:

```json
{
  "error": "VALIDATION_ERROR",
  "message": "Invalid input"
}
```

### 403

Insufficient permissions


### 404

Resource not found

**Content type:** `application/json`

- Reference: `Error`
  - Type: `object`
  - Properties:
    - `error` (`string`)
      - Example: `NOT_FOUND`
    - `message` (`string`)
      - Example: `Resource not found`

Example:

```json
{
  "error": "NOT_FOUND",
  "message": "Resource not found"
}
```

## Examples

### cURL

```bash
curl --request PUT \
  --url 'https://your-envoy.example.com/api/users/YOUR_ID' \
  --header 'Authorization: Bearer $API_KEY' \
  --header 'Content-Type: application/json' \
  --data '{
  "username": "string",
  "password": "string",
  "role": "admin"
}'
```

### JavaScript (fetch)

```javascript
const response = await fetch('https://your-envoy.example.com/api/users/YOUR_ID', {
  method: 'PUT',
  headers: {
    'Authorization': 'Bearer YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "username": "string",
    "password": "string",
    "role": "admin"
  }),
});

if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = response.status === 204 ? null : await response.json();
console.log(data);
```
