Update a shared user's role/access
curl --request PUT \
--url https://api.scanova.io/multi-users/{pk}/ \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"access_level": 3
}
'import requests
url = "https://api.scanova.io/multi-users/{pk}/"
payload = { "access_level": 3 }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({access_level: 3})
};
fetch('https://api.scanova.io/multi-users/{pk}/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.scanova.io/multi-users/{pk}/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'access_level' => 3
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.scanova.io/multi-users/{pk}/"
payload := strings.NewReader("{\n \"access_level\": 3\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.scanova.io/multi-users/{pk}/")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"access_level\": 3\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.scanova.io/multi-users/{pk}/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"access_level\": 3\n}"
response = http.request(request)
puts response.read_bodyShared Users & Roles
Update a shared user
PUT /multi-users//
PUT
/
multi-users
/
{pk}
/
Update a shared user's role/access
curl --request PUT \
--url https://api.scanova.io/multi-users/{pk}/ \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"access_level": 3
}
'import requests
url = "https://api.scanova.io/multi-users/{pk}/"
payload = { "access_level": 3 }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({access_level: 3})
};
fetch('https://api.scanova.io/multi-users/{pk}/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.scanova.io/multi-users/{pk}/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'access_level' => 3
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.scanova.io/multi-users/{pk}/"
payload := strings.NewReader("{\n \"access_level\": 3\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.scanova.io/multi-users/{pk}/")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"access_level\": 3\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.scanova.io/multi-users/{pk}/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"access_level\": 3\n}"
response = http.request(request)
puts response.read_bodyShared users are the teammates you invite into your Scanova account — the same list shown on the dashboard’s Users table. This endpoint lets you list, invite, update, or remove them programmatically.
This endpoint was not previously documented. It requires an API key with
MANAGEMENT_API (or MANAGEMENT_API_SANDBOX) quota, sent as the raw Authorization header value — see the API overview — plus the account’s own Team quota for shared users. For what each role actually grants, see Roles & permissions; for the wire format of roles themselves, see Roles (access levels).integer
required
The shared-user record ID from the list response above.
curl --request PUT \
--url 'https://api.scanova.io/multi-users/118/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{"access_level": 3}'
curl --request PUT \
--url 'https://api.scanova.io/multi-users/118/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{"is_active": false}'
PUT returns the same shape as the invite response above.
email and name are create-only — sending them in a PUT body is silently ignored rather than erroring, since a shared user’s identity can’t be changed after the invite is sent. To update the role, tag scope, or active state, use only the fields you intend to change.Related
- List shared users — find the
pkto operate on here. - Retrieve a shared user — another operation on this same
{pk}endpoint. - Remove a shared user — another operation on this same
{pk}endpoint. - List roles — look up or create the
access_levelID this endpoint’s invite/update calls require. - Create a custom role — look up or create the
access_levelID this endpoint’s invite/update calls require. - Shared users — the dashboard’s own Users table, showing the same invite/deactivate/remove actions.
- Roles & permissions — what each role actually grants a teammate.
Authorizations
Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: YOUR_API_KEY. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.
Path Parameters
Body
application/json
Response
200
Shared user updated.
Was this page helpful?