> ## Documentation Index
> Fetch the complete documentation index at: https://docs.autocalls.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Update user settings

> Update the permissions, minute rate, limits and appearance of one of your users

This endpoint changes the settings of one of your platform users: their name and email, their permissions, their minute rate, their limits and what they see on your platform. Send only the keys you want to change: everything you leave out stays as it is. The response returns all the user's settings after the change, in the same format as [Get user settings](/api-reference/white-label/get-user-settings).

<Note>
  This endpoint is available to the **account owner** (with an active plan) and to team members who can open the administration panel, meaning they have **Platform Admin**, **Settings Access** or **Billing Access**. Only the owner can change `permissions`. Team members can change everything else, on their own account too, as in the administration panel. Only users of your platform can be changed: any other ID, including the owner account, returns 404.
</Note>

### Path Parameters

<ParamField path="id" type="integer" required>
  The ID of the user. Administrators can list user IDs with [Get platform users](/api-reference/white-label/get-users).
</ParamField>

### Request Body

<ParamField body="name" type="string">
  The user's name, up to 255 characters. It cannot contain `<`, `>`, links or domain names.
</ParamField>

<ParamField body="email" type="string">
  The user's email address. It must be a valid email address that is not already used by another user of your platform or by the owner account.
</ParamField>

<ParamField body="permissions" type="object">
  The user's permissions in your administration panel. Only the account owner can send this key; for anyone else the request returns 403 and nothing is saved. Permissions you leave out stay unchanged. See [Permissions](#permissions) for what each one allows.

  <Expandable title="permissions properties">
    <ParamField body="platform_admin" type="boolean">
      Platform Admin
    </ParamField>

    <ParamField body="settings_access" type="boolean">
      Settings Access
    </ParamField>

    <ParamField body="billing_access" type="boolean">
      Billing Access
    </ParamField>

    <ParamField body="revenue_reports_access" type="boolean">
      Revenue Reports Access
    </ParamField>

    <ParamField body="impersonate_owner" type="boolean">
      Allow impersonate owner
    </ParamField>
  </Expandable>
</ParamField>

<ParamField body="custom_minute_rate" type="number">
  The rate per minute this user is charged, in your currency, instead of the rate of their plan or your default rate. Up to 4 decimals, and at least your own cost per minute. `minimum_minute_cost` in [Get default limits](/api-reference/white-label/get-default-limits) is that cost rounded up to the cent, so it is always accepted. `null` removes the custom rate, and the user goes back to the rate of their plan or your default rate.
</ParamField>

<ParamField body="limits" type="object">
  The user's own limits, which take priority over their plan and your default limits. The keys are those of [default limits](/api-reference/white-label/update-default-limits#limits) except `calendar_integrations`: `assistants`, `campaigns`, `cloned_voices`, `knowledgebases`, `mid_call_tools`, `parallel_calls`, `automation_runs` and `own_numbers` are count limits, and `web_widget`, `secondary_languages`, `automation_platform`, `custom_dashboards`, `ai_prompt_editor`, `flow_builder` and `ai_connector` are boolean limits.

  Count limits take an integer from `-1` to `100000` (`-1` means unlimited, `0` means none). Boolean limits take `true` or `false`. `null` on a key removes that limit from the user, who then gets the limit of their plan or your default limit again. Limits you leave out stay unchanged. `limits: null` removes all of the user's own limits.
</ParamField>

<ParamField body="appearance" type="object">
  What the user sees on your platform. For each page and feature, the user sees your platform-wide setting unless you give them a different one, and the pages and features you leave matching your platform-wide appearance keep following it when you change it later. A list you send replaces the current list for this user, and a value sent twice is saved once. `appearance: null` returns the user to your platform-wide appearance and clears `visible_plans`.

  <Expandable title="appearance properties">
    <ParamField body="hide_pages" type="string[]">
      Every page to hide for this user. Values from [Pages you can hide](/api-reference/white-label/update-settings#pages-you-can-hide)
    </ParamField>

    <ParamField body="hide_features" type="string[]">
      Every feature to hide for this user. Values from [Features you can hide](/api-reference/white-label/update-settings#features-you-can-hide), except `hide_auto_generated_plan_features` and `hide_platform_tour`, which only exist platform-wide
    </ParamField>

    <ParamField body="visible_plans" type="integer[]">
      IDs of the plans this user sees on the plans page, from [List plans](/api-reference/white-label/list-plans). They must be your own plans, and inactive plans are allowed, so you can offer a plan to this user only. Up to 100 IDs. Send `[]` to show all your active plans
    </ParamField>
  </Expandable>
</ParamField>

### Response

<ResponseField name="message" type="string">
  Success message
</ResponseField>

<ResponseField name="data" type="object">
  All the user's settings after the change, in the same format as [Get user settings](/api-reference/white-label/get-user-settings). `permissions` is returned only to the account owner
</ResponseField>

<ResponseExample>
  ```json 200 User Updated theme={null}
  {
    "message": "User updated.",
    "data": {
      "id": 123,
      "name": "Jane Doe",
      "email": "jane@example.com",
      "permissions": {
        "platform_admin": false,
        "settings_access": false,
        "billing_access": false,
        "revenue_reports_access": false,
        "impersonate_owner": false
      },
      "custom_minute_rate": 0.12,
      "effective_minute_rate": 0.12,
      "limits": {
        "assistants": { "custom": 3, "effective": 3 },
        "campaigns": { "custom": null, "effective": 1 },
        "cloned_voices": { "custom": null, "effective": 0 },
        "knowledgebases": { "custom": null, "effective": 1 },
        "mid_call_tools": { "custom": null, "effective": 1 },
        "parallel_calls": { "custom": null, "effective": 3 },
        "automation_runs": { "custom": null, "effective": 500 },
        "own_numbers": { "custom": null, "effective": 1 },
        "web_widget": { "custom": false, "effective": false },
        "secondary_languages": { "custom": null, "effective": true },
        "automation_platform": { "custom": null, "effective": true },
        "custom_dashboards": { "custom": null, "effective": false },
        "ai_prompt_editor": { "custom": null, "effective": true },
        "flow_builder": { "custom": null, "effective": true },
        "ai_connector": { "custom": null, "effective": true }
      },
      "appearance": {
        "custom": true,
        "hide_pages": ["hide_blacklist_page"],
        "hide_features": ["hide_carrier_costs"],
        "visible_plans": [12]
      }
    }
  }
  ```

  ```json 401 Unauthenticated theme={null}
  {
    "message": "Unauthenticated."
  }
  ```

  ```json 403 Not Administrator theme={null}
  {
    "message": "You are not an administrator."
  }
  ```

  ```json 403 Permissions Owner Only theme={null}
  {
    "message": "Only the account owner can change permissions."
  }
  ```

  ```json 404 User Not Found theme={null}
  {
    "message": "User not found."
  }
  ```

  ```json 422 Rate Too Low theme={null}
  {
    "message": "The custom minute rate field must be at least 0.09.",
    "errors": {
      "custom_minute_rate": ["The custom minute rate field must be at least 0.09."]
    }
  }
  ```

  ```json 422 Unknown Plan theme={null}
  {
    "message": "The appearance.visible_plans field contains a plan that does not exist.",
    "errors": {
      "appearance.visible_plans": ["The appearance.visible_plans field contains a plan that does not exist."]
    }
  }
  ```

  ```json 422 Email Already Used theme={null}
  {
    "message": "The email has already been taken.",
    "errors": {
      "email": ["The email has already been taken."]
    }
  }
  ```

  ```json 422 Unsupported Field theme={null}
  {
    "message": "The balance field is not supported.",
    "errors": {
      "balance": ["The balance field is not supported."]
    }
  }
  ```

  ```json 429 Too Many Requests theme={null}
  {
    "message": "Too Many Attempts."
  }
  ```
</ResponseExample>

### Permissions

The first three permissions let a team member open your administration panel, where every administrator can manage your users. They can then use these user settings endpoints, and the other endpoints their permissions allow.

| Key | Permission | What it allows |
| - | - | - |
| `platform_admin` | Platform Admin | Opens the administration panel, including Data Migration. Pages and features hidden by appearance settings stay visible to this user |
| `settings_access` | Settings Access | Opens the administration panel and allows changing your platform settings, including through [Update platform settings](/api-reference/white-label/update-settings). The checkout settings also need Billing Access |
| `billing_access` | Billing Access | Opens the administration panel and allows managing billing: plans, pricing, trials, default limits and checkout settings |
| `revenue_reports_access` | Revenue Reports Access | Shows revenue figures (MRR, ARPU, plan prices) on the administration dashboard and user pages. Does not open the panel on its own |
| `impersonate_owner` | Allow impersonate owner | Allows opening the owner account (User view and Admin view) from the users list. Does not open the panel on its own |

### Partial updates

* Keys you leave out stay unchanged. Inside `permissions` and `limits`, only the keys you send change.
* A list you send (`hide_pages`, `hide_features` or `visible_plans`) replaces that list for the user. An `appearance` object without one of these lists keeps the user's current value for it.
* An unknown top-level field returns 422 with "The X field is not supported.", and an unknown key inside `permissions`, `limits` or `appearance` returns 422 with "The X field must be an object with only the supported keys.". In both cases nothing is saved, not even the valid parts of the request.
* Leading and trailing spaces are removed from text values.
* Send only the keys you want to change.

### Rate limit

The platform settings, default limits, user settings and plan endpoints share a limit of 60 requests per minute for each account. Above it they return `429`, and the `Retry-After` response header tells you how many seconds to wait.

### Example: Change a user's rate, limits and appearance

```bash theme={null}
curl -X PATCH https://app.autocalls.ai/api/white-label/users/123 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "custom_minute_rate": 0.12,
    "limits": {
      "assistants": 3,
      "web_widget": false,
      "parallel_calls": null
    },
    "appearance": {
      "hide_pages": ["hide_blacklist_page"],
      "visible_plans": [12]
    }
  }'
```

### Example: Give a team member Settings Access (owner only)

```bash theme={null}
curl -X PATCH https://app.autocalls.ai/api/white-label/users/124 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "permissions": {
      "settings_access": true
    }
  }'
```

### Example: Return a user to your defaults

```bash theme={null}
curl -X PATCH https://app.autocalls.ai/api/white-label/users/123 \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "custom_minute_rate": null,
    "limits": null,
    "appearance": null
  }'
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.