Edit a company user's name, role and status
Replaces company-local display name, optional contact email, one default role and ACTIVE/SUSPENDED status using lockVersion. Login email/password and global profile are never changed. Self edits and owner edits are forbidden. Existing temporary/special grants are revoked; suspension also revokes refresh sessions. Other company memberships are untouched. Company permission: `updateCompanyUser`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
id*stringuuidapplication/json- body
contactEmail?stringemail0 <= length <= 320displayName*string0 <= length <= 200lockVersion*integerint320 <= valuerole*stringADMIN|ACCOUNTANT|MANAGER|EMPLOYEE1 <= lengthstatus*stringACTIVE|SUSPENDED1 <= lengthMembership updated and atomically audited
curl -X PUT 'https://api.monetaryai.uz/api/v1/settings/users/497f6eca-6276-4993-bfeb-53cbbbba6f08' \ -H 'Content-Type: application/json' \ -d '{ "displayName": "string", "lockVersion": 0, "role": "string", "status": "string"}'Replace a role's complete access list PUT
Send permission IDs from the catalogue and the last read lockVersion. An empty list denies all configurable APIs. Unknown/duplicate IDs are rejected. Changes apply to already-issued bearer tokens on their next request. The last permanent access administrator cannot be locked out; OWNER remains protected. Company permission: `replaceCompanyRolePermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
Revoke the current user's web browser DELETE
Idempotently disables only an owned device and clears its encrypted token. Unknown or foreign ids do not change another user's subscription.