---
title: "Update a Natural User (SCA)"
method: PUT
path: "/v2.01/{ClientId}/sca/users/natural/{UserId}"
tags: ["Users"]
---

# Update a Natural User (SCA)

`PUT /v2.01/{ClientId}/sca/users/natural/{UserId}`

Modify details for a Natural Payer or Owner without changing category.

<Warning icon="fa-regular fa-triangle-exclamation">
**Caution – Modification may trigger SCA re-enrollment**

If `UserCategory` is `OWNER`, modifying the following values changes `UserStatus` to `PENDING_USER_ACTION` and requires [re-enrollment in SCA](/guides/sca/users#re-enroll-an-enrolled-owner) using the returned `PendingUserAction.RedirectUrl`:

- `Email`
- `PhoneNumber`
- `PhoneNumberCountry`

In Sandbox, you can bypass SCA by including the word `accept` in the Natural User's `Email` – for example `accept@example.com` or `john.doe+accept@example.com`.
</Warning>

<Warning icon="fa-regular fa-triangle-exclamation">
**Caution – Modification may cause KYC/B verification downgrade** 

If `KYCLevel` is `REGULAR`, modifying the following values triggers a [verification downgrade](/guides/users/verification/downgrade) to `LIGHT`: 
- `FirstName`
- `LastName`
- `Birthday`
- `Nationality`
</Warning>

<Note icon="fa-regular fa-circle-info">
**Note – Country-based restrictions apply to users**

Due to Mangopay's [country restrictions](/guides/users/country-restrictions), it is not possible to use blocked countries as the following:
- `Nationality`
- `CountryOfResidence`
- `Address.Country`
</Note>

## Path parameters

- `ClientId` string, required
- `UserId` string, required

## Headers

- `Authorization` string, required

## Request body

- union
  - UpdateNaturalPayerSCARequest — Request body for updating a Natural User with `UserCategory` `PAYER`.
    - `FirstName` string — Min. length: 1; max. length: 100 The first name of the individual.
    - `LastName` string — Min. length: 1; max. length: 100 The last name of the individual.
    - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
    - `Email` string — Format: A valid email address The individual's email address. **Caution:** If `UserCategory` is `OWNER`, modifying this value means the user will be required to re-enroll the new value in SCA via the `PendingUserAction.RedirectUrl`. For more details see the [SCA guides](/guides/sca/users).
    - `PhoneNumber` string — Format: International E.164 standard (preceded by plus sign and country code) or local format The individual's phone number. The local format (recommended) requires `PhoneNumberCountry` to ensure correct formatting. If present, the phone number forms part of card transaction data that is passed to issuers to improve authentication rates. For users with `UserCategory` `OWNER` , the phone number is used to pre-populate the SCA session for them to confirm and receive an SMS OTP. If the individual modifies the phone number during the session, this data is not updated in the API.
    - `PhoneNumberCountry` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) Required if the `PhoneNumber` is provided in local format (recommended), to render the value in the E.164 standard.
    - `Address` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
    - `TermsAndConditionsAccepted` boolean, required — Whether the user has accepted Mangopay's terms and conditions (as defined by your contract, see the [T&Cs guide](/guides/users/terms) for details). Must be `true` if `UserCategory` is `OWNER`.
    - `UserCategory` string, required — **Allowed values:** `PAYER` The [category](/guides/users/categories) of the user: - `PAYER` – User who can only make pay-ins to their wallets and transfers to other wallets (as well as refunds for pay-ins and transfers). - `OWNER` – User who can also receive transfers to their wallets. Owners are able to request [KYC verification](/guides/users/verification), which if successful gives them the `KYCLevel` of `REGULAR` and the ability to request payouts.
  - UpdateNaturalOwnerSCARequest — Request body for updating a Natural User with `UserCategory` `OWNER`. Modifying `Email`, `PhoneNumber` or `PhoneNumberCountry` requires re-enrollment in SCA via the `PendingUserAction.RedirectUrl` returned.
    - `FirstName` string — Min. length: 1; max. length: 100 The first name of the individual.
    - `LastName` string — Min. length: 1; max. length: 100 The last name of the individual.
    - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
    - `Email` string — Format: A valid email address The individual's email address. **Caution:** If `UserCategory` is `OWNER`, modifying this value means the user will be required to re-enroll the new value in SCA via the `PendingUserAction.RedirectUrl`. For more details see the [SCA guides](/guides/sca/users).
    - `PhoneNumber` string — Format: International E.164 standard (preceded by plus sign and country code) or local format The individual's phone number. The local format (recommended) requires `PhoneNumberCountry` to ensure correct formatting. If present, the phone number forms part of card transaction data that is passed to issuers to improve authentication rates. For users with `UserCategory` `OWNER` , the phone number is used to pre-populate the SCA session for them to confirm and receive an SMS OTP. If the individual modifies the phone number during the session, this data is not updated in the API.
    - `PhoneNumberCountry` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) Required if the `PhoneNumber` is provided in local format (recommended), to render the value in the E.164 standard.
    - `Address` AddressSubPropsRequired — The postal address.
      - `AddressLine1` string, required — The first line of the address.
      - `AddressLine2` string — The second line of the address.
      - `City` string, required — The city of the address.
      - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
      - `PostalCode` string, required — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
      - `Country` string, required — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
    - `TermsAndConditionsAccepted` boolean, required — Whether the user has accepted Mangopay's terms and conditions (as defined by your contract, see the [T&Cs guide](/guides/users/terms) for details). Must be `true` if `UserCategory` is `OWNER`.
    - `UserCategory` string, required — **Allowed values:** `OWNER` The [category](/guides/users/categories) of the user: - `PAYER` – User who can only make pay-ins to their wallets and transfers to other wallets (as well as refunds for pay-ins and transfers). - `OWNER` – User who can also receive transfers to their wallets. Owners are able to request [KYC verification](/guides/users/verification), which if successful gives them the `KYCLevel` of `REGULAR` and the ability to request payouts.
    - `Birthday` integer — The date of birth of the individual. **Note:** This is a Unix timestamp in UTC. Ensure you convert your timezone to UTC to avoid midnight being interpreted as the day before.
    - `Nationality` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The nationality of the individual.
    - `CountryOfResidence` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of residence of the individual.
    - `Occupation` string — Max. length: 255 characters The occupation of the individual.
    - `IncomeRange` integer — **Allowed values:** `1`, `2`, `3`, `4`, `5`, `6`, `null`. The bracket indicating the income of the individual. The brackets are: - 1: < 18K - 2: 18K - 30K - 3: 30K - 50K - 4: 50K - 80K - 5: 80K - 120K - 6: > 120K
    - `ScaContext` string — **Possible values:** `USER_PRESENT`, `USER_NOT_PRESENT` **Default value:** `USER_PRESENT` The SCA context of the request, which is **required** if the user's `UserCategory` is `OWNER`: - `USER_PRESENT` – The user is taking the SCA-triggering action of updating account information and must re-enroll in SCA. The platform must [redirect the user](/guides/sca/session) using the `PendingUserAction.RedirectUrl` returned so that the user can complete the SCA session. - `USER_NOT_PRESENT` – The platform is taking the action under proxy from the user and the user has previously given consent to Mangopay (via the SCA hosted experience) to allow the action. If the user has not given (or has revoked) their consent, then `USER_NOT_PRESENT` returns a 403 error. Read more about [managing proxy and user consent](/guides/sca/proxy-management) **&rarr;** **Note:** On User endpoints, `ScaContext` is not returned in the API response as it does not form part of the User data – it's only related to the action being performed on the user.

## Response `200`

Success

- NaturalUserSCAResponse — Response body for a Natural User. The same schema is returned for `PAYER` and `OWNER` users. If `UserCategory` is `PAYER`, the following are returned `null`: - `Birthday` - `Nationality` - `CountryOfResidence` - `Occupation` - `IncomeRange` - `TermsAndConditionsAcceptedDate`
  - `FirstName` string — Min. length: 1; max. length: 100 The first name of the individual.
  - `LastName` string — Min. length: 1; max. length: 100 The last name of the individual.
  - `Birthday` integer, nullable — Returned `null` if `UserCategory` is `PAYER`. The date of birth of the individual. **Note:** This is a Unix timestamp in UTC. Ensure you convert your timezone to UTC to avoid midnight being interpreted as the day before.
  - `Nationality` string, nullable — Returned `null` if `UserCategory` is `PAYER`. The nationality of the individual.
  - `CountryOfResidence` string, nullable — Returned `null` if `UserCategory` is `PAYER`. The country of residence of the individual.
  - `Occupation` string, nullable — Max. length: 255 characters The occupation of the individual. Returned `null` if `UserCategory` is `PAYER`.
  - `IncomeRange` integer, nullable — Returned `null` if `UserCategory` is `PAYER`. The bracket indicating the income of the individual. The brackets are: - 1: < 18K - 2: 18K - 30K - 3: 30K - 50K - 4: 50K - 80K - 5: 80K - 120K - 6: > 120K
  - `ProofOfIdentity` string, nullable — The `Id` of the KYC Document whose `Type` is `IDENTITY_PROOF` if validated for the user. If no identity proof is validated, then this value is `null`.
  - `ProofOfAddress` string, nullable — The `Id` of the KYC Document whose `Type` is `ADDRESS_PROOF` if validated for the user. If no address proof is validated, then this value is `null`.
  - `Capacity` string — This is a deprecated parameter.
  - `PhoneNumber` string, nullable — Format: International E.164 standard (preceded by plus sign and country code) or local format The individual's phone number. The local format (recommended) requires `PhoneNumberCountry` to ensure correct formatting. If present, the phone number forms part of card transaction data that is passed to issuers to improve authentication rates. For users with `UserCategory` `OWNER` , the phone number is used to pre-populate the SCA session for them to confirm and receive an SMS OTP. If the individual modifies the phone number during the session, this data is not updated in the API.
  - `PhoneNumberCountry` string, nullable — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) Required if the `PhoneNumber` is provided in local format (recommended), to render the value in the E.164 standard.
  - `Address` Address — The postal address.
    - `AddressLine1` string — The first line of the address.
    - `AddressLine2` string — The second line of the address.
    - `City` string — The city of the address.
    - `Region` string — Required if `Country` is US, CA, or MX. The region of the address.
    - `PostalCode` string — The postal code of the address. The postal code can contain the following characters: alphanumeric, dashes, and spaces.
    - `Country` string — Format: Two-letter country code ([ISO 3166-1 alpha-2 format](/api-reference/overview/data-formats)) The country of the address.
  - `PendingUserAction` NaturalUserScaResponsePendingUserAction — Object containing the `RedirectUrl` needed for SCA redirection if triggered by the API call (otherwise returned `null`).
    - `RedirectUrl` string — The URL to which to redirect the user to perform strong customer authentication (SCA) via a Mangopay-hosted webpage. This value is a variable and should not be hardcoded. The SCA session link expires 10 minutes after it's generated. **Caution:** Before redirecting the user on this URL, you must add the query parameter `ReturnUrl` with the percent-encoded URL to which you want the SCA session to return the user after authentication (whether successful or not). For more details, see [How to redirect a user for an SCA session](/guides/sca/session#how-to-redirect-a-user-for-sca).
  - `Id` string — Max length: 128 characters (see [data formats](/api-reference/overview/data-formats) for details) The unique identifier of the object.
  - `Tag` string — Max. length: 255 characters Custom data that you can add to this object.
  - `CreationDate` integer — Unix timestamp (UTC) of the date and time the object was created.
  - `PersonType` string — **Returned values:** `NATURAL`, `LEGAL` The type of the user: - `NATURAL` – Natural users are individuals (natural persons). - `LEGAL` – Legal users are legal entities (legal persons) like companies, non-profits, and sole proprietors. The `PersonType` is defined by the endpoint used to create the user and can’t be modified.
  - `Email` string — Format: A valid email address The individual's email address.
  - `KYCLevel` string — **Default value:** `LIGHT` **Returned values:** `LIGHT`, `REGULAR` The verification status of the user set by Mangopay: - `LIGHT` – Unverified, assigned by default to all users. - `REGULAR` – Verified, meaning the user has successfully completed the verification process and had the necessary documents validated by Mangopay. Only users whose `UserCategory` is `OWNER` can submit verification documents for validation. Only users whose `KYCLevel` is `REGULAR` can request payouts.
  - `TermsAndConditionsAccepted` boolean — Whether the user has accepted Mangopay's terms and conditions (as defined by your contract, see the [T&Cs guide](/guides/users/terms) for details). Must be `true` if `UserCategory` is `OWNER`.
  - `TermsAndConditionsAcceptedDate` integer, nullable — The date and time at which the `TermsAndConditionsAccepted` value was set to `true`. Returned `null` if `UserCategory` is `PAYER`.
  - `UserCategory` string — **Possible values:** `PAYER`, `OWNER`, `PLATFORM` The [category](/guides/users/categories) of the user: - `PAYER` – User who can only make pay-ins to their wallets and transfers to other wallets (as well as refunds for pay-ins and transfers). - `OWNER` – User who can also receive transfers to their wallets. Owners are able to request [KYC verification](/guides/users/verification), which if successful gives them the `KYCLevel` of `REGULAR` and the ability to request payouts. - `PLATFORM` – Single specific user that represents the platform. The `PLATFORM` value is only assigned by Mangopay and may be used as part of the validated workflow implemented by the platform.
  - `UserStatus` string — **Returned values:** `PENDING_USER_ACTION`, `ACTIVE`, `CLOSED` The status of the user: - `PENDING_USER_ACTION` – The user must enroll in SCA before they can become `ACTIVE`. - `ACTIVE` – The user account is active and the user can access Mangopay features. - `CLOSED` – The user account is permanently closed. This value is used by Mangopay to close an account following the procedure outlined in the terms and conditions.

## Other responses

- `400` — Bad Request
- `403` — Forbidden

---

[API](https://skmtc.net/mangopay/apis/api-reference.md) · [All operations](https://skmtc.net/mangopay/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/mangopay/api-reference/versions/795281070285/schema)
