Skip to content

Update Current User ​

You can partially update a user's profile by sending only the fields you want to change. Nested objects are merged the same way — send only the attributes you want to change; company.businessId and company.vatId can be set to null to clear them.

HTTP Request ​

PUT /api/v1/me

Below is a summary of updateable fields. All others remain unchanged if omitted. Some fields are only accepted for one role — the request is validated against the authenticated user's role.

ParameterDescription
email string, optionalUser's email address (max 255 chars). Validated strictly, including a DNS/MX lookup of the domain. Changing it resets the email verification — see Side Effects.
phone string, optionalPhone number in international format with country code (e.g., +421901234567). See Phone Numbers.
password string, optionalNew password (min. 8 characters, including letters and numbers). Requires currentPassword and passwordConfirmation.
passwordConfirmation stringRequired together with password; must match it.
currentPassword stringRequired together with password; the user's current password.
firstName string, optionalFirst name (clients only).
lastName string, optionalLast name (clients only).
billingAddress object, BillingAddress, optionalBilling address. The first write must contain all of line1, line2, city, postalCode and country; later writes may send only the attributes to change. See Address.
shippingAddress object, ShippingAddress, optionalShipping address incl. optional firstName/lastName (clients only). Same first-write rule as billingAddress.
company object, Company, optionalCompany details. Only the attributes sent are changed; businessId and vatId may be null.
bankAccount object, BankAccount, optionalBank details (experts only). iban must be a Slovak IBAN.
newsletterSubscribed boolean, optionalIf omitted, subscription status remains unchanged. true updates timestamp; false cancels the subscription.
regions array, optionalArray of region codes where expert provides services (experts only). Min 1, max 8 regions. See Regions.

Response ​

200 OK

Returns the updated User Object wrapped in a data key.

Side Effects ​

  • Password change — every other token of the user is revoked; only the token used for this request keeps working, other devices get 401 Unauthorized on their next request. Re-submitting the current password is not a change.
  • Email change — emailVerified becomes false, a verification email is sent to the new address and a notice email to the previous one. The current token stays valid, but the endpoints that require a verified email (creating offers, checkout, accepting offers, completing, cancelling and downloading testimonies) respond with 403 Forbidden until the new address is verified — see Verify Email and Resend Verification Email. Re-submitting the current email changes nothing.
  • Bank account change (experts) — a notice email showing the last four IBAN characters is sent to the expert's previous email address.

Authentication ​

Requires authentication via Bearer token.

401 Unauthorized

json
{
  "message": "Unauthenticated."
}

Error Handling ​

Validation Errors ​

422 Unprocessable Entity

json
{
  "message": "Pole Aktuálne heslo je povinné, keď je nastavené Heslo.",
  "errors": {
    "currentPassword": [
      "Pole Aktuálne heslo je povinné, keď je nastavené Heslo."
    ]
  }
}

Returned when validation fails for any field. Common issues:

  • password sent without currentPassword or passwordConfirmation, or currentPassword is wrong
  • Email already in use, or its domain does not accept mail
  • Phone number already registered
  • Password doesn't meet requirements
  • First write of an address missing one of line1, line2, city, postalCode, country
  • IBAN must be a valid Slovak (SK) IBAN