---
title: "Set user role assignments."
method: PUT
path: "/access-control/users/{userId}/roles"
tags: ["access_control", "enterprise"]
---

# Set user role assignments.

`PUT /access-control/users/{userId}/roles`

Update the user’s role assignments to match the provided set of UIDs. This will remove any assigned roles that aren’t in the request and add roles that are in the set but are not already assigned to the user.
Roles mapped through group attribute sync are not impacted.
If you want to add or remove a single role, consider using Add a user role assignment or Remove a user role assignment instead.

You need to have a permission with action `users.roles:add` and `users.roles:remove` and scope `permissions:type:delegate` for each. `permissions:type:delegate`  scope ensures that users can only assign or unassign roles which have same, or a subset of permissions which the user has. For example, if a user does not have required permissions for creating users, they won’t be able to assign or unassign a role which will allow to do that. This is done to prevent escalation of privileges.

## Path parameters

- `userId` integer, required

## Query parameters

- `targetOrgId` integer

## Request body

- SetUserRolesCommand
  - `global` boolean
  - `includeHidden` boolean
  - `roleUids` string[]

## Response `200`

An OKResponse is returned if the request was successful.

- SuccessResponseBody
  - `message` string

## Other responses

- `400` — BadRequestError is returned when the request is invalid and it cannot be processed.
- `403` — ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
- `404` — NotFoundError is returned when the requested resource was not found.
- `500` — InternalServerError is a general error indicating something went wrong internally.

---

[API](https://skmtc.net/grafana/apis/http-api.md) · [All operations](https://skmtc.net/grafana/apis/http-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/grafana/http-api/versions/df55ba1718ba/schema)
