> ## Documentation Index
> Fetch the complete documentation index at: https://docs.falkordb.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Create database user

> Add a database user to a deployment instance.

Creates a database user with a password and an ACL.

<Note>
  This endpoint uses the FalkorDB API host and bearer token authentication. See [Database users overview](/api-reference/database-users/overview).
</Note>

## Authorization

<ParamField header="Authorization" type="string" required>
  `Bearer <jwt>`, using the token issued by [Sign in](/api-reference/authentication/signin).
</ParamField>

## Path parameters

<ParamField path="instanceId" type="string" required>
  ID of the deployment instance.
</ParamField>

## Query parameters

<ParamField query="subscriptionId" type="string" required>
  Subscription that owns the instance.
</ParamField>

## Body

<ParamField body="username" type="string" required>
  Username for the new database user.
</ParamField>

<ParamField body="password" type="string" required>
  Password for the new database user.
</ParamField>

<ParamField body="acl" type="string" required>
  ACL string. See [ACL format](/api-reference/database-users/overview#acl-format).
</ParamField>

```json Request theme={null}
{
  "username": "analytics",
  "password": "REDACTED",
  "acl": "~* +GRAPH.RO_QUERY +GRAPH.EXPLAIN +GRAPH.INFO +GRAPH.LIST +INFO +PING"
}
```

## Response

<ResponseField name="message" type="string">
  Confirmation message.
</ResponseField>

## Errors

Returns `401 Unauthorized` when the bearer token is missing or expired, and `400 Bad Request` when the ACL contains a command that is not allowed.
