> ## Documentation Index
> Fetch the complete documentation index at: https://docs.falkordb.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> FalkorDB is a graph database that speaks the Redis protocol. Queries are issued as OpenCypher through the GRAPH.QUERY and GRAPH.RO_QUERY commands, not over Bolt or a SQL connection.
> FalkorDB implements a subset of OpenCypher with proprietary extensions. Do not assume Neo4j-only syntax or procedures are available — check /cypher/cypher-support and /cypher/known-limitations before using a clause.
> FalkorDB is the successor to RedisGraph, but they are separate products. Do not present RedisGraph commands, versions, or limitations as current FalkorDB behavior.
> Use the official clients listed in /getting-started/clients rather than generic Redis or Neo4j drivers, and prefer the language the user is already working in.
> Configuration parameters are set with GRAPH.CONFIG SET or at startup; cite the exact parameter name from /getting-started/configuration rather than inventing one.
> This site covers four products: FalkorDB (core), FalkorDB Cloud, FalkorDB Enterprise, and the GraphRAG SDK. Name which one an answer applies to, since setup and operations differ.

# Update database user

> Rotate the password or change the ACL of a database user.

Updates a database user. Send only the fields you want to change; omitting `password` leaves the current password in place.

<Note>
  This endpoint uses the FalkorDB API host and bearer token authentication. See [Database users overview](/cloud/api-reference/database-users/overview).
</Note>

## Authorization

<ParamField header="Authorization" type="string" required>
  `Bearer <jwt>`, using the token issued by [Sign in](/cloud/api-reference/authentication/signin).
</ParamField>

## Path parameters

<ParamField path="instanceId" type="string" required>
  ID of the deployment instance.
</ParamField>

<ParamField path="username" type="string" required>
  Username of the database user to update.
</ParamField>

## Query parameters

<ParamField query="subscriptionId" type="string" required>
  Subscription that owns the instance.
</ParamField>

## Body

<ParamField body="password" type="string">
  New password. Omit to keep the current password.
</ParamField>

<ParamField body="acl" type="string">
  New ACL string. See [ACL format](/cloud/api-reference/database-users/overview#acl-format).
</ParamField>

```json Request theme={null}
{
  "acl": "~* +GRAPH.QUERY +GRAPH.RO_QUERY +GRAPH.DELETE +INFO +PING"
}
```

## Response

<ResponseField name="message" type="string">
  Confirmation message.
</ResponseField>

## Errors

Returns `401 Unauthorized` when the bearer token is missing or expired, and `400 Bad Request` when the ACL contains a command that is not allowed.
