> ## Documentation Index
> Fetch the complete documentation index at: https://www.conductor.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace a user's accounts

> Replace a user's entire set of accessible Conductor accounts with a new list using the User Management API.



## OpenAPI

````yaml POST /user-api/v1/users/{userEmail}/accounts
openapi: 3.0.1
info:
  version: 1.0.1, 2023-07-13
  title: User Management API
  license:
    name: Conductor terms of service
    url: https://www.conductor.com/legal/
  termsOfService: https://www.conductor.com/legal/
  x-logo:
    url: https://app.conductor.com/images/global/logo_login.png
  description: >-
    This is Conductor’s REST API for user management.


    ## Getting access to the API


    We use a bearer token except for the `login` endpoint, which uses a username
    and password.


    ### Application Identity


    The application identity is a set of credentials used to interact with this
    API. 

    These credentials must belong to a user configured separately, without SSO
    enabled, and with the Admin user type. 

    Afterward, the Standard and Read-only users belonging to the same accounts
    may be managed through the API.


    ## Permissions in the Conductor Platform


    The Conductor platform has two different dimensions of permissions:

    - User Type: Whether the user can write or read data only. This applies in
    general, not just single accounts. 
      Conductor’s user types include: *Admin*, *Standard*, and *Read-only*.
    - Accounts: Accounts grant access to specific sets of data.


    There are two operations to manage these two dimensions separately.
  contact:
    name: Engineering, core platform
    email: coreplatformeng@conductor.com
servers:
  - url: https://app.conductor.com
    description: Conductor user management API V1
security:
  - JWT: []
tags:
  - name: Authentication resources
    description: Obtain a bearer token.
  - name: User management resources
    description: >-
      **Note**: Only Standard and Read-only users may be created, updated, or
      otherwise managed with this API. 

      The User List endpoint includes Admin users, but they cannot be managed
      with this API.
paths:
  /user-api/v1/users/{userEmail}/accounts:
    parameters:
      - $ref: '#/components/parameters/userEmail'
    post:
      tags:
        - User management resources
      summary: Replace a User’s Access to Conductor Accounts
      description: >-
        Completely replaces the list of accounts a user has access to with the
        given list.

        It is only possible to assign accounts that are already owned by the
        application identity.
      operationId: overwriteUserAccounts
      requestBody:
        description: The list of accounts the user has access to after the operation.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserAccountsDto'
            examples:
              Example:
                value:
                  accounts:
                    - 1
                    - 2
                    - 3
        required: true
      responses:
        '200':
          $ref: '#/components/responses/AccountModificationResponse'
        '401':
          $ref: '#/components/responses/ErrorResponse'
        '403':
          $ref: '#/components/responses/ErrorResponse'
        '404':
          $ref: '#/components/responses/ErrorResponse'
        '500':
          $ref: '#/components/responses/ErrorResponse'
components:
  parameters:
    userEmail:
      name: userEmail
      in: path
      required: true
      schema:
        type: string
        example: user@example.com
      description: The user’s email
  schemas:
    UserAccountsDto:
      title: UserAccountsDto
      type: object
      description: A list of accounts this user has or will have access to
      properties:
        accounts:
          type: array
          items:
            type: integer
    Error:
      type: object
      x-examples:
        Example:
          timestamp: 2023-05-18T19:06:16.449+0000
          status: 403
          error: Forbidden
          message: Forbidden
          path: /api/v1/users/user@example.com
      properties:
        timestamp:
          type: string
          format: date-time
          description: Timestamp rfc3339
        status:
          type: integer
          description: HTTP status code
        error:
          type: string
        message:
          type: string
        path:
          type: string
  responses:
    AccountModificationResponse:
      description: The accounts the user has access to after the operation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/UserAccountsDto'
          examples:
            Example:
              value:
                accounts:
                  - 1
                  - 2
                  - 3
    ErrorResponse:
      description: A standard response for any error (4xx / 5xx)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    JWT:
      type: http
      scheme: bearer

````