Updates a user of your access token’s organization. All fields are optional; only the fields you send change. Integrations can update only users whose roles are branch-level (branch_user / branch_manager).
Auth: Authorization: Bearer <accessToken> — an organization-scoped token from Authentication.
Payload schema:
Path parameters
Body
The user’s email cannot be changed through this endpoint, and the user cannot be moved to another organization.
Example
Response
Returns 201 with the updated user — the same shape as a List users item.
Notes:
- Updating a user that does not exist returns
entity_not_found (400); a user outside your organization returns auth_error (400).
- Updating a user whose roles are not branch-level returns
user_not_updatable (400); API users return api_user_not_updatable (400).
system_admin and api_user roles can never be assigned through the API (role_not_allowed, 400).
- Optional fields that have no value are omitted from the response — you will not receive
null.
Last modified on October 8, 2026