> ## Documentation Index
> Fetch the complete documentation index at: https://docs.falkordb.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Update database user

> Rotate the password or change the ACL of a database user.

Updates a database user. Send only the fields you want to change; omitting `password` leaves the current password in place.

<Note>
  This endpoint uses the FalkorDB API host and bearer token authentication. See [Database users overview](/api-reference/database-users/overview).
</Note>

## Authorization

<ParamField header="Authorization" type="string" required>
  `Bearer <jwt>`, using the token issued by [Sign in](/api-reference/authentication/signin).
</ParamField>

## Path parameters

<ParamField path="instanceId" type="string" required>
  ID of the deployment instance.
</ParamField>

<ParamField path="username" type="string" required>
  Username of the database user to update.
</ParamField>

## Query parameters

<ParamField query="subscriptionId" type="string" required>
  Subscription that owns the instance.
</ParamField>

## Body

<ParamField body="password" type="string">
  New password. Omit to keep the current password.
</ParamField>

<ParamField body="acl" type="string">
  New ACL string. See [ACL format](/api-reference/database-users/overview#acl-format).
</ParamField>

```json Request theme={null}
{
  "acl": "~* +GRAPH.QUERY +GRAPH.RO_QUERY +GRAPH.DELETE +INFO +PING"
}
```

## Response

<ResponseField name="message" type="string">
  Confirmation message.
</ResponseField>

## Errors

Returns `401 Unauthorized` when the bearer token is missing or expired, and `400 Bad Request` when the ACL contains a command that is not allowed.
