> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.brevo.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.brevo.com/_mcp/server.

# Update permission for a user

POST https://api.brevo.com/v3/organization/user/update/permissions
Content-Type: application/json

`Feature` - A Feature represents a specific functionality like Email
campaign, Deals, Calls, Automations, etc. on Brevo. While inviting a user,
determine which feature you want to manage access to. You must specify the
feature accurately to avoid errors. `Permission` - A Permission defines the
level of access or control a user has over a specific feature. While
inviting user, decide on the permission level required for the selected
feature. Make sure the chosen permission is related to the selected feature.
Features and their respective permissions are as below: - `email_campaigns`:
  - "create_edit_delete"
  - "send_schedule_suspend"
- `sms_campaigns`:
  - "create_edit_delete"
  - "send_schedule_suspend"
- `contacts`:
  - "view"
  - "create_edit_delete"
  - "import"
  - "export"
  - "list_and_attributes"
  - "forms"
- `templates`:
  - "create_edit_delete"
  - "activate_deactivate"
- `workflows`:
  - "create_edit_delete"
  - "activate_deactivate_pause"
  - "settings"
- `landing_pages`:
  - "all"
- `transactional_emails`:
  - "settings"
  - "logs"
- `smtp_api`:
  - "smtp"
  - "api_keys"
  - "authorized_ips"
- `user_management`:
  - "all"
- `sales_platform`:
  - "create_edit_deals"
  - "delete_deals"
  - "manage_others_deals_tasks"
  - "reports"
  - "settings"
- `phone`:
  - "all"
- `conversations`:
  - "access"
  - "assign"
  - "configure"
- `senders_domains_dedicated_ips`:
  - "senders_management"
  - "domains_management"
  - "dedicated_ips_management"
- `push_notifications`:
  - "view"
  - "create_edit_delete"
  - "send"
  - "settings"
- `companies`:
  - "manage_owned_companies"
  - "manage_other_companies"
  - "settings"
**Note**: - The privileges array remains the same as in the send invitation;
the user simply needs to provide the permissions that need to be updated. -
The availability of feature and its permission depends on your current plan.
Please select the features and permissions accordingly.

Reference: https://developers.brevo.com/reference/edit-user-permission

## Authentication

- `api-key` header (required) — The API key should be passed in the request headers as `api-key` for authentication.

## Request

### Body (application/json)

This endpoint expects an object.

- `all_features_access` (boolean, required) — All access to the features
- `email` (string, required) — Email address for the organization
- `privileges` (list of object, required)
  - `feature` (enum, optional) — Feature name
    - Allowed values: `email_campaigns`, `sms_campaigns`, `contacts`, `templates`, `workflows`, `landing_pages`, `transactional_emails`, `smtp_api`, `user_management`, `sales_platform`, `phone`, `conversations`, `senders_domains_dedicated_ips`, `push_notifications`, `companies`
  - `permissions` (list of enum, optional) — Permissions for a given feature
    - Allowed values: `create_edit_delete`, `send_schedule_suspend`, `view`, `import`, `export`, `list_and_attributes`, `forms`, `activate_deactivate`, `activate_deactivate_pause`, `settings`, `schedule_pause`, `all`, `logs`, `access`, `assign`, `configure`, `create_edit_deals`, `delete_deals`, `manage_others_deals_tasks`, `manage_owned_companies`, `manage_others_companies`, `reports`, `senders_management`, `domains_management`, `dedicated_ips_management`, `send`, `smtp`, `api_keys`, `authorized_ips`, `none`

## Response

### 200

Success

- `status` (string, required) — Status of the API operation.
- `credit_notes` (list of string, optional) — Credit note
- `invoice_id` (string, optional) — Invoice id

## Errors

### 400 Bad Request Error

bad request

- `code` (enum, required) — Error code displayed in case of a failure
  - Allowed values: `invalid_parameter`, `missing_parameter`, `out_of_range`, `campaign_processing`, `campaign_sent`, `document_not_found`, `not_enough_credits`, `permission_denied`, `duplicate_parameter`, `duplicate_request`, `method_not_allowed`, `unauthorized`, `account_under_validation`, `not_acceptable`, `bad_request`, `unprocessable_entity`, `Domain does not exist`, `Contact email not found`, `Attribute not found`, `Category id not found`, `Invalid parameters passed`, `Record(s) for identifier not found`, `Returned when query params are invalid`, `Returned when invalid data posted`, `Feed not found`, `Campaign ID not found`, `api-key not found`, `DMARC policy requires domain authentication`, `DNS records not properly configured`, `Invalid OTP code provided`, `OTP code has expired`, `Domain already exists in your account`, `The sum of all IP weights must equal 100`, `Authentication failed`, `Insufficient credits`, `Request already processed`
- `message` (string, required) — Readable message associated to the failure

## Examples

**Request**

```json
{
  "all_features_access": true,
  "email": "inviteuser@example.com",
  "privileges": [
    {}
  ]
}
```

**Response**

```json
{
  "status": "OK",
  "credit_notes": [
    "TEST-123"
  ],
  "invoice_id": "string"
}
```

**SDK Code**

```typescript
import { BrevoClient } from "@getbrevo/brevo";

async function main() {
    const client = new BrevoClient({
        apiKey: "YOUR_API_KEY_HERE",
    });
    await client.user.editUserPermission({
        allFeaturesAccess: true,
        email: "inviteuser@example.com",
        privileges: [
            {},
        ],
    });
}
main();

```

```python
from brevo import Brevo, InviteuserPrivilegesItem

client = Brevo(
    api_key="YOUR_API_KEY_HERE",
)

client.user.edit_user_permission(
    all_features_access=True,
    email="inviteuser@example.com",
    privileges=[
        InviteuserPrivilegesItem()
    ],
)

```

```php
<?php

namespace Example;

use Brevo\Brevo;
use Brevo\Types\Inviteuser;
use Brevo\Types\InviteuserPrivilegesItem;

$client = new Brevo(
    apiKey: 'YOUR_API_KEY_HERE',
);
$client->user->editUserPermission(
    new Inviteuser([
        'allFeaturesAccess' => true,
        'email' => 'inviteuser@example.com',
        'privileges' => [
            new InviteuserPrivilegesItem([]),
        ],
    ]),
);

```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.brevo.com/v3/organization/user/update/permissions"

	payload := strings.NewReader("{\n  \"all_features_access\": true,\n  \"email\": \"inviteuser@example.com\",\n  \"privileges\": [\n    {}\n  ]\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("api-key", "<apiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.brevo.com/v3/organization/user/update/permissions")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["api-key"] = '<apiKey>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"all_features_access\": true,\n  \"email\": \"inviteuser@example.com\",\n  \"privileges\": [\n    {}\n  ]\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.brevo.com/v3/organization/user/update/permissions")
  .header("api-key", "<apiKey>")
  .header("Content-Type", "application/json")
  .body("{\n  \"all_features_access\": true,\n  \"email\": \"inviteuser@example.com\",\n  \"privileges\": [\n    {}\n  ]\n}")
  .asString();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.brevo.com/v3/organization/user/update/permissions");
var request = new RestRequest(Method.POST);
request.AddHeader("api-key", "<apiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"all_features_access\": true,\n  \"email\": \"inviteuser@example.com\",\n  \"privileges\": [\n    {}\n  ]\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "api-key": "<apiKey>",
  "Content-Type": "application/json"
]
let parameters = [
  "all_features_access": true,
  "email": "inviteuser@example.com",
  "privileges": [[]]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.brevo.com/v3/organization/user/update/permissions")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```