---
id: user-grants-replace-all
title: "Replace all grants for a user"
description: "Replace all existing grants for a user with a new set of grants. This operation **deletes all existing grants** and creates the new ones."
sidebar_label: "Replace all grants for a user"
hide_title: true
hide_table_of_contents: true
api: eJztWW1v2zgS/isEPzWGYjtpcr0TsAe4adrNXa8NHAe3h8RIJuLY4lYiVZJK4jX03w9DSrZsq026r4fF5YNfZHI488wzD8nJkgu0iZGFk1rxmI+xyCBBBlnG8FFaJ9WczQ0oZ9lMGwastGjYg3QpA6bwgVl0TM/qMX02SaVlukADZJH1egIzdGi7LPZ6DJRgiUGgES5Fb1ErtP1rda322QUqwYDMYF64BQNjYNHrsdur6S1zmhnM9X3wtnHS6NxbIj/7axus11Na7W+a8RbWAdcmfHBkwhaYyJlEsXZpkmIrOmlZr+cMKAsJPYCs14uZnDFQCx+Kt8hmIDPL7iGTws+LmNIsSUHNCReDLAeB3vx/dMkSH29pkaF0KRp2a3SGN1LcMt18sVk5v+31fEoQkrReSCrvt8HPJVrXv1Y84g7mlsdXfKwz9HD7oXwa8VUcZ4LHnPCKAwJxDco+ZBmPuMWkNNIteHy15HcIBs2odCmPr6bVNOIFGMjRobF+gIIcecyl4BGXRKkCXMqjLZ4RjqWSn0tkUqByBLPx4axyxyNOgUiDgsfOlBhxm6SYA4+X3C0Kv4pyOEfDq4jjI+RFhjx+9de/kVs1CK+1WNCERCuHytFHKIpMJj7ywY+W3FnuWvYU2XF7RE/XdCcCEf83/F6RtsW1Tq6G/OTweOYwtzw+GA4jLsPnJdcKP848ok46iotfWiodyj+j/FNug6/67kdM3AZeV1wZsr5iCyW8MJRyJ9EvQAPW8VpnpJp35unD+AOFHJhldWkSZA8pGgyPyB9pGVgr5woF5W2VC67NHJT8yYP93UEMSaJL5b47pIytfXuWGzRy5Qct6nS9qC+dv7MP2mHMLhDZFZHdTl8MhE7sAEqXalM7MaCpds+nLNcGmVQzHTKx9lrgPWaEFa+qKurMwNmb5+Mvxf8q+lJ0FFOXF2dvfh/oXw2HLw9evTr+S1VV0ypaIX9XZp/eUdXUG9Q4VHer8D2qzfblJXwlwP6ne8hKDApF0H8Zmw1ichC5VNz7Mt4u4LbZaUV/RAFbaGWDO4fDIb1twvmu3mUohbXQCmbLJEFrZ2WWLSiHv7JchS1WDMpC0HsjQLylN1/jshfzQGiSuBv/vSFQxK0DV9pdjj+bXV/eCbyjG6Q+OHx5dFxFf3wBNUh8awGFA1RKG0KC8h7FFwKlfewXlmlnUOsS++US3I1aSz5X5Oiwj6rMiV10drpHHvEClaCfpp1rezvN6rtwNWaqbtUIVcm7fvRVsh7hy/hweLRbuaPWGTFULwmCYC/aO/0DWGZRub0+LXbUpQCT9RnNnw1RtA6HfS+j5x8vJgyVKLRU4XyR6DzXiiVQWqyPDt8qEp21HXA90QK9Rf+GxmgiWI7Wwhx3K7s16Wlifj+ZnDfpowU20nY0HFb1uk9S8F+QpFLhvkEQcJch837u2uTj04uPl+OT05t349GHyUX/9eX7f96cjE9Hk9Obt6Oz96dv/Mbho3xy1e/LHNT2mjRlc83XIFhrV2qge9L8G3T+egB3unSe236FTeNvA0ucrpW8oaFUjGhMC3pidCX7qeXqW05S3yFcCg0ryYfNvD8vT5O21XWOVqJec76jhrcT9+by/P3ZCaXNP6A4hQ/gW3F9SBfM0dV0fSPbVq1JIysMMsr2IlxXLS0qlcDHZ2rwT2j0/h1YFMxP25CsNrxb17WgH5t7XRCjHcU69cwNPx798MOuwpxkEpWrsV8dSZgo/dFNKi83TKqidHSpzKX1J9v1Ve7nnEGelpffVlfoNGWQtJdi2aB20sbjBfbn/YgdDYf0ckAvL+nlaO9nK9OI5V/WppDzBBzO6Sxcdzosmns66IDMSrOlJXcgbkzrhPs8oRqxOyNxFrF0U7FaoxourkWsQeO6LWDXnB5cqub4juKa7/06cjcSQoZWCRPPUb72Xklbaw7ZTJucejKErnIglS+lQOk2g6v6SH7cVSEXAf7tCpFKeJ6rOd3gpbUlMh3KdHR+xqwMW82fqDRsG4iaDMdUGsfDQ3p5uZn44z+uKihYoyC7CYNuAmS/W32c1cuzmjpehEOl0BOZILtUcA8yI6s7BdM5/TctnZFipcLHAhO68oWQdJKUxqDos/MMwSJzZsFgDlKxDBx13aqmbHJ0qabOYFESc30bL+YDur4MllJUg9BIpP4gBRS6f6XJeMxT5wobDwZQyL4qs6zIwFHV9hOdc2rONS3FCyqUwO92Y3GFBBnidd/PC6MfxKP6w1ttcnA85v/498Qf/KkAx+vG32mDxbfe+ts3mOdOpUva+m41pUPDTPsWARobMnjQH/aHfL2hj9rtEeJCoa3LwWtI3Ucd7/an1334bYq02pz/7+T/+Tr5oSYcPrpBkYH0jPEFt6yr84rXrIh9X2bV6U+1dfTrcknn0kuTVRU9/lyioa7+NOL3YCTJli8VIS19FjyeQWbxKyR7Ma73sz32vI5+ZwxND0tRB6tuqHEe8U+4CP9J8O23FEGg8Q6GH06CG/sTmr6euLMhUwmHGaMkwcJ9dey0JXznlxOSmvo/CLnf87iBB6p4eAg+ao+KVzD/bMkzUPPSCzoPJkmYYFPXtnQstPm7UFguw4iJ/oSqqlagOPpOuFTVfwGOWZoS
sidebar_class_name: "put api-method"
info_path: docs/api/authorization
custom_edit_url: null
---

import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import ParamsDetails from "@theme/ParamsDetails";
import RequestSchema from "@theme/RequestSchema";
import StatusCodes from "@theme/StatusCodes";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";
import Heading from "@theme/Heading";

<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Replace all grants for a user"}
>
</Heading>

<MethodEndpoint
  method={"put"}
  path={"/user/{id}/grant"}
  context={"endpoint"}
>
  
</MethodEndpoint>



Replace all existing grants for a user with a new set of grants. This operation **deletes all existing grants** and creates the new ones.

- Send an **empty array** `[]` to remove all grants from the user.
- Send a **non-empty array** to replace all grants with the specified ones.

The operation is **transactional**: if any new grant fails validation, no changes are made.

You can **use either `role_id` or `role_slug`** for each grant in the request.


<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={[{"name":"id","in":"path","description":"The unique identifier for the user.","required":true,"schema":{"type":"integer"},"example":789}]}
>
  
</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"content":{"application/json":{"schema":{"type":"array","description":"Array of grants to set for the user. Send an empty array to remove all grants.\n","maxItems":100,"items":{"oneOf":[{"title":"Using role slug","type":"object","required":["nrn","role_slug"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the role is assigned.","example":"organization=1:account=2"},"role_slug":{"type":"string","description":"The slug of the role to assign.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n","example":"developer"}}},{"title":"Using role ID","type":"object","required":["nrn","role_id"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the role is assigned.","example":"organization=1:account=2"},"role_id":{"type":"integer","description":"The ID of the role to assign.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n","example":700317756}}}]},"title":"bulkGrantReplaceRequest"},"examples":{"Replace with new grants":{"value":[{"nrn":"organization=1:account=2","role_slug":"admin"}]},"Remove all grants":{"value":[]}}}}}}
>
  
</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"200":{"description":"Grants were replaced successfully.","content":{"application/json":{"schema":{"type":"array","description":"Array of created/updated grants.","items":{"type":"object","required":["id","nrn","user_id","role_id","status"],"properties":{"id":{"type":"integer","description":"The unique identifier for the grant.","example":12345},"nrn":{"type":"string","description":"The NRN of the resource where the role is assigned.","example":"organization=1:account=2"},"user_id":{"type":"integer","description":"The ID of the user who received the grant.","example":789},"role_id":{"type":"integer","description":"The ID of the role assigned.","example":700317756},"role_slug":{"type":"string","description":"The slug of the role assigned.","example":"developer"},"status":{"type":"string","enum":["active","pending"],"description":"The status of the grant.","example":"active"}},"title":"bulkGrantResponse"},"title":"bulkGrantArrayResponse"}}}},"204":{"description":"All grants were removed (empty array was sent)."},"400":{"description":"The request failed validation. See POST endpoint for common causes.\n","content":{"application/json":{"schema":{"type":"object","required":["statusCode","code","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code.","example":400},"code":{"type":"string","description":"Machine-readable error code.","example":"RESOURCE_GRANTS.BULK_CREATE_FAILED"},"error":{"type":"string","description":"Human-readable error type.","example":"Bad Request"},"message":{"type":"string","description":"Details about the error.","example":"Failed to create grants in bulk"},"cause":{"type":"object","description":"Details about the specific grant that failed.","properties":{"code":{"type":"string","description":"The specific error code for the failed grant.","example":"RESOURCE_GRANTS.DUPLICATE_GRANT"},"detail":{"type":"string","description":"Details about why this grant failed.","example":"The grant already exists"},"index":{"type":"integer","description":"The zero-based index of the grant that failed in the request array.","example":1}}}},"title":"bulkGrantError"}}}},"4XX":{"description":"Client error responses due to invalid input or missing parameters.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific client error (e.g., 400, 401, 403, 404).","example":400},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"bad_request"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Bad Request\", \"Unauthorized\").","example":"Bad Request"},"message":{"type":"string","description":"Additional details about the error.","example":"The request was malformed or contained invalid parameters."}}}}}},"5XX":{"description":"Server error responses indicating an issue on the API side.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific server error (e.g., 500, 502, 503).","example":500},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"internal_server_error"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Internal Server Error\", \"Service Unavailable\").","example":"Internal Server Error"},"message":{"type":"string","description":"Additional details about the error.","example":"An unexpected error occurred. Please try again later."}}}}}}}}
>
  
</StatusCodes>


      