Skip to navigation

Update a user

Restates a user’s whole record (users:manage) — an admission grants capabilities to a discovered member; users have no maker-checker, so the write is live at once.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

idintegerRequired

The record's id — a positive 32-bit integer the platform minted.

Headers

Idempotency-KeystringRequired

Required on every write: a URL-safe string of 1 to 64 characters from [A-Za-z0-9._~-] (a UUID fits), scoped to you. It names one operation on one record, ever: a retry replays the stored outcome (Idempotent-Replay: true) or attaches to the live one, and reuse on another record refuses 409 IDEMPOTENCY_KEY_REUSED. Missing or malformed, 400.

If-MatchstringOptional

The ETag the read minted, quoted or bare; absent or * is unconditional; a weak validator refuses 400 INVALID_IF_MATCH. A stale value answers 412 VERSION_CONFLICT with currentVersion and a fresh ETag: re-read, reapply, retry. Send it — every write restates the whole record, so an unconditional write overwrites every field from your copy, and an amend against a pending proposal replaces that proposal.

Request

This endpoint expects an object.
kindenumRequired

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
namestringRequired
targetUserIdinteger or nullOptional

0 = create.

expectedVersionstring or nullOptionalformat: "^-?[0-9]+$"
int64 as a decimal JSON string
capabilitieslist of enumsOptional

a set (SBE bit-set) served as the array of its scope strings — each choice spelled <route family>:<verb> (the schema's camel-cased choice name de-camelled: accountAddressesApprove is account-addresses:approve) — in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict

idpUserRefstringOptional

Empty = unstated, which keeps the current binding (a rename or an admission never strands a login); a value binds or re-binds. Refused IDP_REF_TAKEN when another row of the organisation carries it.

presetenumOptional

A named capability bundle the edge expands to its scope strings and never forwards — the row records bits, never a preset name: INITIATOR (the six maker-checker families' propose bits), APPROVER (initiator plus their approve bits), ADMIN (approver plus users:manage and portfolios:manage), TRADER (orders:trade), TREASURY (the account, address and asset/chain policy families, both verbs), PLATFORM (orgs:propose and orgs:approve, inside the internal platform org only). Either preset or capabilities names the set; both stated must agree, else 400. x-immix-preset-capabilities is the expansion.

Response

The user as the platform now holds it after the write — the same row the read serves, with the answering change's position, the row's ETag and, on a replayed key, Idempotent-Replay.

capabilitieslist of enums

The user's capabilities — what they may do; empty on a discovered row. a set (SBE bit-set) served as the array of its scope strings — each choice spelled <route family>:<verb> (the schema's camel-cased choice name de-camelled: accountAddressesApprove is account-addresses:approve) — in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict

displayNamestring

What the IdP stated at discovery (the name, else email, else nickname claim); informational, never a key.

globalSequencestringformat: "^[0-9]+$"

The position as a decimal string — the last change this member had applied, orders and balance readings included.

kindenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
namestring

Platform name — per-org unique among live users with a non-empty name; empty until admission.

orgIdinteger

Membership — stamped by the owner from the actor's org, or from the discovery's parent ref.

statusenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
userIdinteger
Sticky entity key.
versionstringformat: "^-?[0-9]+$"
Monotonic per entity. int64 as a decimal JSON string
idpUserRefstringOptional

The identity provider's subject, opaque, never parsed: a token's sub resolves to this row inside the token's organisation. Empty = unbound (a locally authenticated user). Unique among all the organisation's users, disabled included — a subject binds for the life of its row, and a second binding is refused IDP_REF_TAKEN.

unscaledbooleanOptionalDeprecated

Never present since 0.3.3: every money value on this API states its own scale on the wire — a policy amount or cap since 0.3.3, an order's and an execution's since 0.3.2, a balance's since 0.3.1 — so a row is never served raw, whether or not this member holds the asset or instrument it references. Kept, deprecated, so a client generated from 0.3.2 still compiles; it goes at the next major.

Errors

400
Update Users Request Bad Request Error
401
Update Users Request Unauthorized Error
403
Update Users Request Forbidden Error
404
Update Users Request Not Found Error
409
Update Users Request Conflict Error
412
Update Users Request Precondition Failed Error
413
Update Users Request Content Too Large Error
422
Update Users Request Unprocessable Entity Error
429
Update Users Request Too Many Requests Error
500
Update Users Request Internal Server Error
503
Update Users Request Service Unavailable Error