Skip to main content
PATCH
curl

Overview

Moves a User entity between ACTIVE, FLAGGED, and BLOCKED. See entity lifecycle for the full state machine.

When to use it

  • Block a user after confirming fraud or a compliance breach.
  • Flag a user pending manual review without hard-blocking them.
  • Unblock a user after successful remediation.
  • Propagate external signals — e.g. when your own fraud engine scores a user above a threshold, move them to FLAGGED via this endpoint.

Notes

  • Valid values: ACTIVE, FLAGGED, BLOCKED. Invalid values return 400.
  • Passing a reason string is recommended — it is persisted and surfaced in the audit log and webhook payload.
  • BLOCKED users have all new sessions auto-declined and all new transactions auto-declined.
  • Emits a user.status.updated webhook with previous_status, status, and reason.

Enforcement

Permissions

Role must grant update-status:users.

Authorizations

x-api-key
string
header
required

Path Parameters

vendor_data
string
required

Your unique identifier for the user.

Body

application/json
status
enum<string>
required

New lifecycle status. BLOCKED also adds the vendor_data to the system blocklist.

Available options:
ACTIVE,
FLAGGED,
BLOCKED

Response

User status updated. Full user record returned.

Full user detail. Extends UserListItem with metadata, comments, and updated_at.

didit_internal_id
string<uuid>

Didit's stable internal UUID for this user.

vendor_data
string | null

Your unique identifier for this user (passed when creating sessions). This can be null when no vendor identifier was supplied.

display_name
string | null

Custom display name set by you

full_name
string | null

Full name extracted from verified documents

date_of_birth
string<date> | null
effective_name
string | null

Best available name: display_name if set, otherwise full_name

status
enum<string>

Lifecycle status of the user record (NOT a session status). ACTIVE is the default, FLAGGED marks the user for manual attention, BLOCKED prevents new sessions for this vendor_data.

Available options:
ACTIVE,
FLAGGED,
BLOCKED
portrait_image_url
string | null

Presigned URL of the user's portrait photo (expires after a few hours)

session_count
integer

Total number of verification sessions for this user

approved_count
integer

Number of approved sessions

declined_count
integer

Number of declined sessions

in_review_count
integer

Number of sessions in review

issuing_states
string[]

ISO 3166-1 alpha-3 codes of issuing countries seen on this user's approved ID documents, e.g. ["USA", "ESP"]. Empty array when none.

approved_emails
string[]

Verified email addresses collected from this user's approved sessions, e.g. ["john@example.com"].

approved_phones
string[]

Verified phone numbers collected from this user's approved sessions, e.g. ["+14155551234"].

features
object

Aggregated per-feature status across all of this user's sessions. Possible keys: ID_VERIFICATION, NFC, LIVENESS, FACE_MATCH, POA, QUESTIONNAIRE, EMAIL_VERIFICATION, PHONE, AML, IP_ANALYSIS, AGE_ESTIMATION, DATABASE_VALIDATION. Possible values: Approved, Declined, In Review, Not Finished, Resub Requested.

features_list
object[]

Same data as features, as an ordered array of {feature, status} objects.

last_session_at
string<date-time> | null

Timestamp of the most recent session

first_session_at
string<date-time> | null

Timestamp of the first session

last_activity_at
string<date-time> | null

Timestamp of the most recent activity on this user (session, transaction, status change, data edit, etc.).

tags
object[]

Tag assignments. NOTE: on detail responses each entry is a tag link object ({uuid, tag: {...}, added_by_email, added_by_name, created_at}), unlike the flat {uuid, name, color} shape used on list responses.

created_at
string<date-time>
metadata
object

Custom metadata JSON you attached to this user. Defaults to {}.

comments
object[]

Activity log and comments for this user (status changes, profile edits, manual notes).

updated_at
string<date-time>