Update User Status
Flip only the lifecycle status of a user — ACTIVE/FLAGGED/BLOCKED (NOT session statuses). BLOCKED adds the vendor_data to the system blocklist; moving away from BLOCKED removes that entry. Each change is recorded as a STATUS_CHANGED activity on the user.
Overview
Moves a User entity betweenACTIVE, FLAGGED, and BLOCKED. See entity lifecycle for the full state machine.
When to use it
- Block a user after confirming fraud or a compliance breach.
- Flag a user pending manual review without hard-blocking them.
- Unblock a user after successful remediation.
- Propagate external signals — e.g. when your own fraud engine scores a user above a threshold, move them to
FLAGGEDvia this endpoint.
Notes
- Valid values:
ACTIVE,FLAGGED,BLOCKED. Invalid values return 400. - Passing a
reasonstring is recommended — it is persisted and surfaced in the audit log and webhook payload. BLOCKEDusers have all new sessions auto-declined and all new transactions auto-declined.- Emits a
user.status.updatedwebhook withprevious_status,status, andreason.
Enforcement
Permissions
Role must grantupdate-status:users.
Related
Authorizations
Path Parameters
Your unique identifier for the user.
Body
New lifecycle status. BLOCKED also adds the vendor_data to the system blocklist.
ACTIVE, FLAGGED, BLOCKED Response
User status updated. Full user record returned.
Full user detail. Extends UserListItem with metadata, comments, and updated_at.
Didit's stable internal UUID for this user.
Your unique identifier for this user (passed when creating sessions). This can be null when no vendor identifier was supplied.
Custom display name set by you
Full name extracted from verified documents
Best available name: display_name if set, otherwise full_name
Lifecycle status of the user record (NOT a session status). ACTIVE is the default, FLAGGED marks the user for manual attention, BLOCKED prevents new sessions for this vendor_data.
ACTIVE, FLAGGED, BLOCKED Presigned URL of the user's portrait photo (expires after a few hours)
Total number of verification sessions for this user
Number of approved sessions
Number of declined sessions
Number of sessions in review
ISO 3166-1 alpha-3 codes of issuing countries seen on this user's approved ID documents, e.g. ["USA", "ESP"]. Empty array when none.
Verified email addresses collected from this user's approved sessions, e.g. ["john@example.com"].
Verified phone numbers collected from this user's approved sessions, e.g. ["+14155551234"].
Aggregated per-feature status across all of this user's sessions. Possible keys: ID_VERIFICATION, NFC, LIVENESS, FACE_MATCH, POA, QUESTIONNAIRE, EMAIL_VERIFICATION, PHONE, AML, IP_ANALYSIS, AGE_ESTIMATION, DATABASE_VALIDATION. Possible values: Approved, Declined, In Review, Not Finished, Resub Requested.
Same data as features, as an ordered array of {feature, status} objects.
Timestamp of the most recent session
Timestamp of the first session
Timestamp of the most recent activity on this user (session, transaction, status change, data edit, etc.).
Tag assignments. NOTE: on detail responses each entry is a tag link object ({uuid, tag: {...}, added_by_email, added_by_name, created_at}), unlike the flat {uuid, name, color} shape used on list responses.
Custom metadata JSON you attached to this user. Defaults to {}.
Activity log and comments for this user (status changes, profile edits, manual notes).