> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a shared user

> PUT /multi-users/{pk}/

Shared users are the teammates you invite into your Scanova account — the same list shown on the dashboard's **Users** table. This endpoint lets you list, invite, update, or remove them programmatically.

<Note>
  This endpoint was not previously documented. It requires a Management API key with `MANAGEMENT_API` (or `MANAGEMENT_API_SANDBOX`) quota, sent as the raw `Authorization` header value — see the [Management API overview](/api-reference/management-api/overview) — plus the account's own Team quota for shared users. For what each role actually grants, see [Roles & permissions](/team/roles-and-permissions); for the wire format of roles themselves, see [Roles (access levels)](/api-reference/management-api/shared-users/roles-list).
</Note>

<ParamField path="pk" type="integer" required>
  The shared-user record ID from the list response above.
</ParamField>

<CodeGroup>
  ```bash Update role theme={null}
  curl --request PUT \
    --url 'https://management.scanova.io/multi-users/118/' \
    --header 'Authorization: YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{"access_level": 3}'
  ```

  ```bash Deactivate theme={null}
  curl --request PUT \
    --url 'https://management.scanova.io/multi-users/118/' \
    --header 'Authorization: YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{"is_active": false}'
  ```
</CodeGroup>

`PUT` returns the same shape as the invite response above.

<Note>
  `email` and `name` are create-only — sending them in a `PUT` body is silently ignored rather than erroring, since a shared user's identity can't be changed after the invite is sent. To update the role, tag scope, or active state, use only the fields you intend to change.
</Note>

## Related

* [List shared users](/api-reference/management-api/shared-users/list) — find the `pk` to operate on here.
* [Retrieve a shared user](/api-reference/management-api/shared-users/retrieve) — another operation on this same `{pk}` endpoint.
* [Remove a shared user](/api-reference/management-api/shared-users/remove) — another operation on this same `{pk}` endpoint.
* [List roles](/api-reference/management-api/shared-users/roles-list) — look up or create the `access_level` ID this endpoint's invite/update calls require.
* [Create a custom role](/api-reference/management-api/shared-users/roles-create) — look up or create the `access_level` ID this endpoint's invite/update calls require.
* [Shared users](/team/shared-users) — the dashboard's own Users table, showing the same invite/deactivate/remove actions.
* [Roles & permissions](/team/roles-and-permissions) — what each role actually grants a teammate.


## OpenAPI

````yaml api-reference/openapi/management-api.json PUT /multi-users/{pk}/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    management.scanova.io (QR codes, folders, tags, leads, forms, analytics,
    plans, shared users & roles), plus the token-creation and usage-stats
    endpoints used to authenticate against it. Every path and request/response
    shape below was verified live against a real API key and the actual running
    backend (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://management.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /multi-users/{pk}/:
    put:
      summary: Update a shared user's role/access
      description: >-
        email and name are create-only and are silently ignored if sent here — a
        shared user's identity can't change after invite.
      operationId: updateManagedSharedUser
      parameters:
        - name: pk
          in: path
          required: true
          schema:
            type: integer
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                access_level:
                  type: integer
                is_active:
                  type: boolean
                tags:
                  type: array
                  items:
                    type: integer
                enable_tag_permission:
                  type: boolean
                include_untagged:
                  type: boolean
            example:
              access_level: 3
      responses:
        '200':
          description: Shared user updated.
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. management.scanova.io) — the same key sent to
        the regular API host will not authenticate.

````