POST/v1/user/self

Update the authenticated user's profile

Updates the profile information for the authenticated user. Supply username and lastPasswordChange, and include any other profile fields you want to change. The response contains the updated user object.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

11 body fields

User profile data to update. username and lastPasswordChange are required.

confirmPasswordstringoptional
Confirmation of the new password.
emailstringoptional
The user's email address, up to 255 characters.
forcePasswordChangebooleanoptional
Whether the user must change their password.
fullnamestringoptional
The user's full name, up to 255 characters.
lastPasswordChangeintegerrequired
UNIX epoch timestamp in milliseconds
newPasswordstringoptional
The new password for the user.
nonExpiryPasswordbooleanoptional
Whether the user's password is exempt from expiration.
permissionsarray<object>optional
Permission records associated with the user.
suspendedbooleanoptional
Whether the user account is suspended.
teamsarray<object>optional
Teams associated with the user; each team includes its name and UUID.
usernamestringrequired
The user's username. Must be 1 to 255 characters.

3 status codes
200Returns the updated user object, including profile information, permissions, teams, and account status.
confirmPasswordstringoptional
emailstringoptional
forcePasswordChangebooleanoptional
fullnamestringoptional
lastPasswordChangeintegerrequired
UNIX epoch timestamp in milliseconds
newPasswordstringoptional
nonExpiryPasswordbooleanoptional
permissionsarray<object>optional
suspendedbooleanoptional
teamsarray<object>optional
usernamestringrequired
400Returned when the payload is invalid or the authenticated user is not a managed user.
401Returned when the request is unauthorized.

Error handling

A 400 is returned for an invalid payload or when the authenticated user is not a managed user. username and lastPasswordChange are required; username must be 1 to 255 characters, and lastPasswordChange is a UNIX epoch timestamp in milliseconds. A 401 indicates an unauthorized request.