parameters: - name: id in: path required: true description: User primary key. schema: type: string format: uuid example: 11111111-1111-4111-8111-111111111111 get: tags: [Master data] summary: Get a user description: Returns one user by id. operationId: get-api-users-id responses: "200": description: User. content: application/json: schema: $ref: ../components/schemas.yaml#/User "400": description: Invalid id. content: application/json: schema: $ref: ../components/schemas.yaml#/Error "401": description: Missing session. content: application/json: schema: $ref: ../components/schemas.yaml#/Error "404": description: User not found. content: application/json: schema: $ref: ../components/schemas.yaml#/Error patch: tags: [Master data] summary: Update a user role description: Admin-only role update. Does not rebind email across Cognito subjects. operationId: patch-api-users-id requestBody: required: true content: application/json: schema: type: object required: [role] properties: role: type: string enum: [admin, ap_processor, approver, viewer] example: approver responses: "200": description: Updated user. content: application/json: schema: $ref: ../components/schemas.yaml#/User "400": description: Validation failed. content: application/json: schema: $ref: ../components/schemas.yaml#/Error "403": description: Caller lacks admin:settings. content: application/json: schema: $ref: ../components/schemas.yaml#/Error "404": description: User not found. content: application/json: schema: $ref: ../components/schemas.yaml#/Error