---
title: "Edit a user (Admin)"
method: PATCH
path: "/users/{user_id}"
tags: ["Users"]
---

# Edit a user (Admin)

`PATCH /users/{user_id}`

Update an existing user.

## Path parameters

- `user_id` string, required

## Query parameters

- `password` string
- `email` string
- `fullname` string
- `website` string
- `state` string
- `city` string
- `disable` 0 | 1
- `group` integer
- `maxbitrate` string
- `fullname_public` 0 | 1
- `reset_apikey` 0 | 1
- `reset_streamtoken` 0 | 1
- `clear_stats` 0 | 1

## Request body

- UserEditRequest
  - `password` string — Deprecated: for privacy, send this in a form or JSON request body instead of the query string (query values land in server/proxy logs and browser history). Query-string support is retained for backward compatibility.
  - `email` string
  - `fullname` string
  - `website` string
  - `state` string
  - `city` string
  - `disable` 0 | 1
  - `group` integer
  - `maxbitrate` string — Maximum transcode bitrate for the user, in bits per second (e.g 320000 = 320Kb). API6 and older take this value in kbps.
  - `fullname_public` 0 | 1
  - `reset_apikey` 0 | 1
  - `reset_streamtoken` 0 | 1
  - `clear_stats` 0 | 1

## Response `200`

Updated

- SuccessResponse
  - `success` string

## Other responses

- `400` — HTTP 400 Bad Request (errors 4705, 4710).
- `401` — HTTP 401 Unauthorized (error 4701).
- `403` — HTTP 403 Forbidden (errors 4700, 4703, 4742).
- `404` — HTTP 404 Not Found (error 4704).
- `500` — HTTP 500 Internal Server Error (error 4702).

## Changes

- **2026-07-22** `e8e6b266ea29` — 7 info
  - api operation id `userEdit` was added
  - added optional request body
  - for the `path` request parameter `user_id`, the type/format was generalized from `integer`/`` to `string`/``
  - added the non-success response with the status `401`
  - …3 more
- **2026-07-20** `531d5bc1344e` — 1 info
  - `query` request parameter `password` was deprecated
- **2026-07-17** `9abb9bf6d3bf` — 1 info
  - removed the non-success response with the status `400`
- **2026-06-25** `7ed7a764efd9` — 1 info
  - added the non-success response with the status `400`
- **2026-02-19** `07f53972fdd7` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/ampache/apis/ampache-rest-api/changes/users/:user_id/patch.md)

---

[API](https://skmtc.dev/ampache/apis/ampache-rest-api.md) · [All operations](https://skmtc.dev/ampache/apis/ampache-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ampache/ampache-rest-api/revisions/f37b545b95d7/schema)
