# Update a member

`PATCH https://evohub.io/api/v1/users/{id}`

Part of the [Organization API](https://docs-dev.evohub.io/organization.md) reference · operationId `updateMember`.

Changes a member's name, title or standing. A field left out keeps its value;
`title: ""` clears the title, and an empty `name` is refused
(`VALIDATION_FAILED`). The name and title are the person's own across every
organization they belong to.

A key cannot change a standing, nor edit an owner or administrator
(`ADMIN_ONLY`): that is an administrator's act. Nobody becomes `owner` this
way (`OWNER_ROLE`).

**Permission (API-key scope):** `identity:user:write`.

## Authorization

Any one of:

- `bearerAuth` (identity:user:write)
- `apiKeyHeader` (identity:user:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required): The id of the member (`usr_…`), team (`team_…`), role (`role_…`), invitation (`inv_…`) or organization (`org_…`) the path names.

## Request body (required)

Content type: `application/json`

Type: `object`

- `name` (string)
- `title` (string)
- `role` (string, one of `admin`, `member`, `viewer`)

## Responses

### 200 — The member.

Content type: `application/json`

Type: `object`

- `data` (Member, required)
  - `id` (string, required)
  - `email` (string (email), required)
  - `name` (string, required)
  - `title` (string)
  - `role` (Standing, required, one of `owner`, `admin`, `member`, `viewer`)
  - `org_id` (string, required)
  - `status` (string, required, one of `active`, `invited`, `suspended`)
  - `mfa_enabled` (boolean)
  - `mfa_setup_required` (boolean): Only on `/users/me`: the login policy requires MFA and the person has not set it up.
  - `has_password` (boolean): `false` for people who sign in only with GitHub or Google.
  - `phone_number` (string)
  - `phone_verified` (boolean)
  - `created_at` (string (date-time), required)
  - `updated_at` (string (date-time), required)
- `success` (boolean, required, value `true`)

### 400 — Not JSON (`INVALID_BODY`), `role` is not admin, member or viewer (`VALIDATION_ERROR`), or `name` is sent empty (`VALIDATION_FAILED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 403 — The key lacks the scope (`FORBIDDEN`), or this needs an administrator (`ADMIN_ONLY`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 404 — No such user in the organization (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 409 — The owner cannot be changed (`OWNER_ROLE`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

## Example request

```bash
curl -X PATCH 'https://evohub.io/api/v1/users/string' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "title": "Staff SRE"
}'
```
