---
title: "Changes to Update the current user avatar"
method: POST
path: "/me/avatar"
---

# Changes to Update the current user avatar

`POST /me/avatar`

> Every recorded change to this endpoint, newest first.

## Timeline

Changed in 2 of 7 revisions.

- **2026-03-18** `e271d0e41f6d` — 4 breaking, 6 info
- **2026-02-03** `fc0a40f3b859` — 2 breaking, 4 warning, 6 info

## Changes

- **2026-03-18** `e271d0e41f6d` — 4 breaking, 6 info
  - request body became required
  - removed the media type `application/json` from the request body
  - removed the media type `application/x-www-form-urlencoded` from the request body
  - the `success` response's property type changed from `string` to `boolean` for status `200`
  - api operation id `post_me_avatar` removed and replaced with `postMeAvatar`
  - the endpoint scheme security `XF-Api-Key` was added to the API
  - the endpoint scheme security `XF-OAuth2` was added to the API
  - added the new optional `header` request parameter `XF-Api-User` to all path's operations
  - added the new optional `query` request parameter `api_bypass_permissions` to all path's operations
  - added the media type `multipart/form-data` to the request body
- **2026-02-03** `fc0a40f3b859` — 2 breaking, 4 warning, 6 info
  - removed the media type `multipart/form-data` from the request body
  - the `success` response's property type changed from `boolean` to `string` for status `200`
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - the optional response header `XF-Used-Api-Version` removed for the status `200`
  - api operation id `postMeAvatar` removed and replaced with `post_me_avatar`
  - the endpoint scheme security `XF-Api-Key` was removed from the API
  - the endpoint scheme security `XF-OAuth2` was removed from the API
  - request body became optional
  - added the media type `application/json` to the request body
  - added the media type `application/x-www-form-urlencoded` to the request body

---

[Operation](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/docs/me/avatar/post.md) · [API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [Page](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/me/avatar/post)
