Update User
PUT/api/users/:user
Updates an existing user. The is_admin field can only be set by admin users.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Tenant scoping: Returns 404 if the user is not a member of the current tenant. Closes a privilege-escalation hole where any tenant admin could otherwise mutate any user system-wide by guessing IDs.
is_admin / is_power_user propagation: when provided, these flags are mirrored to the tenant_users pivot row for the current tenant (the per-tenant source of truth) and also written to the central users columns (for legacy readers). Without this mirror, an admin elevated in one tenant would silently become admin in every tenant they're attached to.
Authentication: Requires Bearer token.
Fields (all optional):
- name (optional, max:255) — User's full name
- email (optional, email, max:255) — User's email address
- is_admin (optional, boolean) — Admin privileges (only settable by admins)
- is_power_user (optional, boolean) — Power user privileges
Requires permission: users.update
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not Found
Response Headers
Validation failed — the body is a field → messages map (Laravel shape) or the platform envelope with a stable machine-readable code. Fix the payload and resubmit.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.