---
title: "Add roles to admin user or API Key"
method: PUT
path: "/api/license-manager/users/{userId}/roles"
tags: ["Roles"]
---

# Add roles to admin user or API Key

`PUT /api/license-manager/users/{userId}/roles`

Allows you to add License Manager [roles](https://help.vtex.com/en/tutorial/roles--7HKK5Uau2H6wxE1rH5oRbc) to a particular admin user or API key by specifying the list of role IDs on the request body. 

## Permissions

Any user or [API key](https://developers.vtex.com/docs/guides/api-authentication-using-api-keys) must have at least one of the appropriate [License Manager resources](https://help.vtex.com/en/tutorial/license-manager-resources--3q6ztrC8YynQf6rdc6euk3) to be able to successfully run this request. Otherwise they will receive a status code `403` error. These are the applicable resources for this endpoint:

| **Product** | **Category** | **Resource** |
| --------------- | ----------------- | ----------------- |
| License Manager | Services access control | **Save user** |

You can [create a custom role](https://help.vtex.com/en/tutorial/roles--7HKK5Uau2H6wxE1rH5oRbc#creating-a-role) with that resource or use one of the following [predefined roles](https://help.vtex.com/en/tutorial/predefined-roles--jGDurZKJHvHJS13LnO7Dy):

| **Role** | **Resource** | 
| --------------- | ----------------- | 
| User Administrator - RESTRICTED | Save user |

>❗ Assigning a [predefined role](https://help.vtex.com/en/tutorial/predefined-roles--jGDurZKJHvHJS13LnO7Dy) to users or application keys usually grants permission to multiple [License Manager resources](https://help.vtex.com/en/tutorial/license-manager-resources--3q6ztrC8YynQf6rdc6euk3). If some of these permissions are not necessary, consider creating a custom role instead. For more information regarding security, see [Best practices for using application keys](https://help.vtex.com/en/tutorial/best-practices-api-keys--7b6nD1VMHa49aI5brlOvJm).

To learn more about machine authentication at VTEX, see [Authentication overview](https://developers.vtex.com/docs/guides/authentication).

## Path parameters

- `userId` string, required

## Request body

- integer[] — Array containing role IDs.

## Response `204`

Success - A no-content response, but the roles were added successfully.

## Other responses

- `400` — Bad Request - A userId or role list with invalid format. The message on the body of the response will contain further information.
- `500` — Unexpected error - One possible reason is that the userId is not present on the database.

## Changes

- **2022-01-28** `ca8bd421f133` — 2 warning
  - deleted the `path` request parameter `accountName`
  - deleted the `path` request parameter `environment`
- **2021-11-09** `7a2ee1e98a24` — 1 breaking, 3 info
  - removed the success response with the status `200`
  - added the non-success response with the status `400`
  - added the non-success response with the status `500`
  - added the success response with the status `204`

[Change history](https://skmtc.dev/vtex/apis/license-manager-api/changes/api/license-manager/users/:userId/roles/put.md)

---

[API](https://skmtc.dev/vtex/apis/license-manager-api.md) · [All operations](https://skmtc.dev/vtex/apis/license-manager-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/vtex/license-manager-api/revisions/a7dd68911d51/schema)
