Update user Administrative permissions (internal/domain)
curl --request PUT \
--url https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"admin_permission_keys": [
"<string>"
]
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions"
payload = { "admin_permission_keys": ["<string>"] }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({admin_permission_keys: ['<string>']})
};
fetch('https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'admin_permission_keys' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions"
payload := strings.NewReader("{\n \"admin_permission_keys\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"admin_permission_keys\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"admin_permission_keys\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Users
Update Admin Permissions
Syteca ACB REST API endpoint to update a user’s administrative permissions — User Management, Privileged Accounts Management, Tenant Management, and other admin capabilities.
PUT
/
api
/
user-management
/
users
/
{userId}
/
admin-permissions
Update user Administrative permissions (internal/domain)
curl --request PUT \
--url https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"admin_permission_keys": [
"<string>"
]
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions"
payload = { "admin_permission_keys": ["<string>"] }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({admin_permission_keys: ['<string>']})
};
fetch('https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'admin_permission_keys' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions"
payload := strings.NewReader("{\n \"admin_permission_keys\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"admin_permission_keys\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/user-management/users/{userId}/admin-permissions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"admin_permission_keys\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Updates a user’s administrative permissions — the global capabilities a user holds (e.g. User Management, Privileged Accounts Management, Tenant Management, System Configuration). This is replacement semantics: the supplied set of permissions becomes the user’s full set.
For ACB deployments updated from a version prior to 1.2, switch to the
https://{hostname}/EkranACB server in the Playground.Permissions required
The Access Token must be issued to a user with the administrative User Management permission.Replacement semantics — read before write
This endpoint replaces the user’s administrative permissions with the supplied set. To add or remove individual permissions, first call Get user details to read the current set, then PUT the desired modified set.Don’t accidentally remove your own User Management permission. If the Access Token’s user is the one being modified, removing User Management permission ends API access mid-call. Syteca prevents removing User Management from the last holder, but you can lock yourself out of admin functions by removing it from yourself when others still hold it.
Common use cases
- Role promotion — A user moves into an admin role; grant administrative permissions programmatically.
- Periodic permission audit — Quarterly automation reads, validates, and corrects each user’s permissions against an external policy source of truth.
- Compliance remediation — Bulk-remove a permission from all users who shouldn’t have it after a policy change.
Errors
See Status codes. Common errors:- 400 Bad Request — invalid permission identifier.
- 403 Forbidden — caller lacks User Management permission.
- 404 Not Found — user doesn’t exist.
- 409 Conflict — attempting to remove User Management from the last holder.
Related
Get user details
Read current permissions before updating.
Update client access
Modify per-Client access rules.
Update user access
Modify User-to-User access rules.
Administrative permissions
List of all admin permissions.
Authorizations
Access token for authentication
Path Parameters
ID of the user to update Administrative permissions
Body
application/json
List of administrative permission identifiers to assign directly to the user
Administrative permission identifier
Response
Administrative permissions for a user updated successfully