---
title: "Update user roles"
method: PUT
path: "/users/{id}/roles"
tags: ["Users"]
---

# Update user roles

`PUT /users/{id}/roles`

Update the roles of a user account (not service accounts — their roles are fixed at creation). Restricted to super_admin; a caller cannot update their own roles. Blocked with a 400 if the user has any active (published, unexpired) API key in any environment, since a key's permissions are snapshotted at creation time and would otherwise silently keep running on the old roles; the error lists the active keys grouped by environment ID so the caller can prompt to expire them first, then retry.

## Path parameters

- `id` string, required

## Request body

- UpdateUserRolesRequest
  - `roles` string[]

## Response `200`

OK

- UpdateUserRolesResponse
  - `email` string — Empty for service accounts
  - `id` string
  - `metadata` object
  - `name` string
  - `roles` string[]
  - `tenant` TenantResponse
    - `billing_details` TenantBillingDetails
      - `address` Address
        - `address_city` string
        - `address_country` string
        - `address_line1` string
        - `address_line2` string
        - `address_postal_code` string
        - `address_state` string
      - `email` string
      - `help_email` string
      - `phone` string
    - `created_at` string, date-time
    - `id` string
    - `metadata` TypesMetadata
    - `name` string
    - `status` string
    - `updated_at` string, date-time
  - `type` 'user' | 'service_account'

## Other responses

- `400` — Invalid request, or user has active API keys that must be expired first
- `403` — Forbidden
- `404` — Not found
- `500` — Server error

---

[API](https://skmtc.net/flexprice/apis/flexprice-api.md) · [All operations](https://skmtc.net/flexprice/apis/flexprice-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/flexprice/flexprice-api/revisions/29f14678f58f/schema)
