Update Current User
You can partially update a user's profile by sending only the fields you want to change. Nested objects are merged the same way — send only the attributes you want to change; company.businessId and company.vatId can be set to null to clear them.
HTTP Request
PUT /api/v1/me
Below is a summary of updateable fields. All others remain unchanged if omitted. Some fields are only accepted for one role — the request is validated against the authenticated user's role.
| Parameter | Description |
|---|---|
email string, optional | User's email address (max 255 chars). Validated strictly, including a DNS/MX lookup of the domain. Changing it resets the email verification — see Side Effects. |
phone string, optional | Phone number in international format with country code (e.g., +421901234567). See Phone Numbers. |
password string, optional | New password (min. 8 characters, including letters and numbers). Requires currentPassword and passwordConfirmation. |
passwordConfirmation string | Required together with password; must match it. |
currentPassword string | Required together with password; the user's current password. |
firstName string, optional | First name (clients only). |
lastName string, optional | Last name (clients only). |
billingAddress object, BillingAddress, optional | Billing address. The first write must contain all of line1, line2, city, postalCode and country; later writes may send only the attributes to change. See Address. |
shippingAddress object, ShippingAddress, optional | Shipping address incl. optional firstName/lastName (clients only). Same first-write rule as billingAddress. |
company object, Company, optional | Company details. Only the attributes sent are changed; businessId and vatId may be null. |
bankAccount object, BankAccount, optional | Bank details (experts only). iban must be a Slovak IBAN. |
newsletterSubscribed boolean, optional | If omitted, subscription status remains unchanged. true updates timestamp; false cancels the subscription. |
regions array, optional | Array of region codes where expert provides services (experts only). Min 1, max 8 regions. See Regions. |
Response
200 OK
Returns the updated User Object wrapped in a data key.
Side Effects
- Password change — every other token of the user is revoked; only the token used for this request keeps working, other devices get
401 Unauthorizedon their next request. Re-submitting the current password is not a change. - Email change —
emailVerifiedbecomesfalse, a verification email is sent to the new address and a notice email to the previous one. The current token stays valid, but the endpoints that require a verified email (creating offers, checkout, accepting offers, completing, cancelling and downloading testimonies) respond with403 Forbiddenuntil the new address is verified — see Verify Email and Resend Verification Email. Re-submitting the current email changes nothing. - Bank account change (experts) — a notice email showing the last four IBAN characters is sent to the expert's previous email address.
Authentication
Requires authentication via Bearer token.
401 Unauthorized
json
{
"message": "Unauthenticated."
}Error Handling
Validation Errors
422 Unprocessable Entity
json
{
"message": "Pole Aktuálne heslo je povinné, keď je nastavené Heslo.",
"errors": {
"currentPassword": [
"Pole Aktuálne heslo je povinné, keď je nastavené Heslo."
]
}
}Returned when validation fails for any field. Common issues:
passwordsent withoutcurrentPasswordorpasswordConfirmation, orcurrentPasswordis wrong- Email already in use, or its domain does not accept mail
- Phone number already registered
- Password doesn't meet requirements
- First write of an address missing one of
line1,line2,city,postalCode,country - IBAN must be a valid Slovak (SK) IBAN