## Update

`zones.users.update(strid, UserUpdateParams**kwargs)  -> User`

**patch** `/zones/{zoneId}/users/{id}`

Update a user

### Parameters

- `zone_id: str`

- `id: str`

- `identifier: Optional[str]`

  Zone-scoped user identifier

- `status: Optional[Literal["active", "disabled"]]`

  Status of the user. Set to `disabled` to prevent the user from authenticating and revoke their active sessions, or `active` to re-enable.

  - `"active"`

  - `"disabled"`

### Returns

- `class User: …`

  An authenticated user entity

  - `id: str`

    Unique identifier of the user

  - `created_at: datetime`

    Entity creation timestamp

  - `email: str`

    Email address of the user

  - `email_verified: bool`

    Whether the email address has been verified

  - `identifier: str`

    Zone-scoped user identifier. Defaults to the user's Keycard ID. When the provider has user_identifier_claim configured, the value is set from that claim at user creation time.

  - `organization_id: str`

    Organization that owns this user

  - `status: Literal["active", "disabled"]`

    Status of the user. Disabled users cannot authenticate.

    - `"active"`

    - `"disabled"`

  - `updated_at: datetime`

    Entity update timestamp

  - `zone_id: str`

    Zone this user belongs to

  - `authenticated_at: Optional[str]`

    Date when the user was last authenticated

  - `credentials: Optional[List[Credential]]`

    Authentication credentials for this user, each carrying its identity provider for federation credentials. Populated only when `expand[]=credentials` is set on the listing endpoint.

    - `class CredentialIamUserCredentialFederation: …`

      Federation credential: the user authenticates through an identity provider.

      - `created_at: datetime`

        Entity creation timestamp

      - `provider_id: Optional[str]`

        ID of the identity provider backing this credential. `null` when the source provider has been deleted.

      - `type: Literal["federation"]`

        - `"federation"`

      - `updated_at: datetime`

        Entity update timestamp

      - `issuer: Optional[str]`

        Issuer identifier of the identity provider.

      - `provider: Optional[Provider]`

        A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

        - `id: str`

          Unique identifier of the provider

        - `created_at: datetime`

          Entity creation timestamp

        - `identifier: str`

          User specified identifier, unique within the zone

        - `name: str`

          Human-readable name

        - `organization_id: str`

          Organization that owns this provider

        - `owner_type: Literal["platform", "customer"]`

          Who owns this provider. Platform-owned providers cannot be modified via API.

          - `"platform"`

          - `"customer"`

        - `slug: str`

          URL-safe identifier, unique within the zone

        - `updated_at: datetime`

          Entity update timestamp

        - `zone_id: str`

          Zone this provider belongs to

        - `client_id: Optional[str]`

          OAuth 2.0 client identifier

        - `client_secret_set: Optional[bool]`

          Indicates whether a client secret is configured

        - `description: Optional[str]`

          Human-readable description

        - `metadata: Optional[Metadata]`

          Provider metadata

          - `icon_url: Optional[str]`

            Icon URL

        - `protocols: Optional[Protocols]`

          Protocol-specific configuration

          - `oauth2: Optional[ProtocolsOauth2]`

            OAuth 2.0 protocol configuration

            - `issuer: str`

              OIDC issuer URL used for discovery and token validation.

            - `authorization_endpoint: Optional[str]`

            - `authorization_parameters: Optional[Dict[str, str]]`

              Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

            - `authorization_resource_enabled: Optional[bool]`

              Whether to include the resource parameter in authorization requests.

            - `authorization_resource_parameter: Optional[str]`

              The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

            - `code_challenge_methods_supported: Optional[List[str]]`

            - `jwks_uri: Optional[str]`

            - `registration_endpoint: Optional[str]`

            - `scope_parameter: Optional[str]`

              The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

            - `scope_separator: Optional[str]`

              The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

            - `scopes_supported: Optional[List[str]]`

            - `token_endpoint: Optional[str]`

            - `token_response_access_token_pointer: Optional[str]`

              Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

          - `openid: Optional[ProtocolsOpenid]`

            OpenID Connect protocol configuration

            - `external_id_claim: Optional[str]`

              Name of the OIDC claim carrying the stable external id used to correlate logins with externally provisioned (SCIM) users. Defaults to "sub". Set to "oid" for Entra, whose pairwise "sub" differs from the SCIM externalId.

            - `scopes: Optional[List[str]]`

              Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).

            - `single_logout_enabled: Optional[bool]`

              When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.

            - `user_identifier_claim: Optional[str]`

              Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.

            - `userinfo_endpoint: Optional[str]`

        - `type: Optional[Literal["external", "keycard-vault", "keycard-sts"]]`

          - `"external"`

          - `"keycard-vault"`

          - `"keycard-sts"`

      - `subject: Optional[str]`

        Subject identifier from the identity provider.

    - `class CredentialIamUserCredentialPassword: …`

      Password credential: the user authenticates with email and password. The email lives on the user.

      - `created_at: datetime`

        Entity creation timestamp

      - `type: Literal["password"]`

        - `"password"`

      - `updated_at: datetime`

        Entity update timestamp

  - `grant_count: Optional[int]`

    Delegated-grant count for this user. Populated only when `expand[]=grant_count` is set on the listing endpoint.

  - `groups: Optional[List[Group]]`

    Groups this user belongs to within the zone. Populated only when `expand[]=groups` is set on the listing endpoint.

    - `id: str`

      Unique identifier of the group

    - `identifier: str`

      Zone-unique slug that policy rules match on.

    - `name: str`

      Human-readable group name

  - `issuer: Optional[str]`

    Issuer identifier of the identity provider

  - `provider_id: Optional[str]`

    Reference to the identity provider. This field is undefined when the source identity provider is deleted but the user is not deleted.

  - `role_assignments: Optional[List[RoleAssignment]]`

    Role grants for this user within the zone. Populated only when `expand[]=role-assignments` is set on the listing endpoint.

    - `role_id: str`

      ID of the assigned role

    - `role_identifier: str`

      Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

    - `role_owner_type: Literal["platform", "customer"]`

      Owner type of the granted role. Disambiguates roles that share an identifier across owner types.

      - `"platform"`

      - `"customer"`

    - `scope: Optional[RoleAssignmentScope]`

      The resource this grant is scoped to, or null when the grant is unscoped (applies to the owning zone itself).

      - `id: str`

        The ID of the scoped resource.

      - `type: str`

        The kind of resource this grant is scoped to (e.g. `zone`).

    - `source: Literal["user", "group"]`

      The principal that holds this grant: `user` when assigned directly to the user, or `group` when inherited through group membership.

      - `"user"`

      - `"group"`

    - `group_id: Optional[str]`

      ID of the group this grant is inherited from. Present only when `source` is `group`.

  - `session_count: Optional[int]`

    Session count for this user. Populated only when `expand[]=session_count` is set on the listing endpoint.

  - `subject: Optional[str]`

    Subject identifier from the identity provider

### Example

```python
import os
from keycardai_api import KeycardAPI

client = KeycardAPI(
    api_key=os.environ.get("KEYCARD_API_API_KEY"),  # This is the default and can be omitted
)
user = client.zones.users.update(
    id="id",
    zone_id="zoneId",
)
print(user.id)
```
