Help Center/ GeminiDB/ API Reference/ API v3/ Managing Databases and Accounts/ Changing Permissions for a Database Account
Updated on 2026-09-22 GMT+08:00

Changing Permissions for a Database Account

Function

This API is used to change permissions for a GeminiDB Redis database account.

Constraints

  • Only the GeminiDB Redis API is supported.
  • This operation cannot be performed when the instance is in any of the following states: creating, changing specifications, changing database port, frozen, or abnormal.

Authorization Information

Each account has permissions to call all APIs, but IAM users must have the required permissions specifically assigned.

  • If you are using role/policy-based authorization, see the required permissions in Permissions and Supported Actions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependencies

    gaussdbfornosql:instance:updateDbUserPrivilege

    Write

    instance *

    • g:ResourceTag/<tag-key>
    • g:EnterpriseProjectId

    nosql:instance:modifyDbUserPrivilege

    -

URI

PUT /v3/{project_id}/redis/instances/{instance_id}/db-users/privilege

Table 1 URI parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID of a tenant in a region. To obtain this value, see Obtaining a Project ID.

Constraints

N/A

Range

The value contains 32 characters. Only letters and digits are allowed.

Default Value

N/A

instance_id

Yes

String

Definition

Instance ID. To obtain the value, call the Querying Instances and Details API. If no instance is available, call the Creating an Instance API to create one.

Constraints

N/A

Range

N/A

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token

You can obtain the token by calling the IAM API by following Obtaining a User Token Through Password Authentication.

Constraints

N/A

Range

N/A

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

users

No

Array of Table 4 objects

Definition

Database accounts whose permissions need to be modified. The array elements are objects in Table 4.

Constraints

N/A

Table 4 ModifyDbUserPrivilegeRequestBody

Parameter

Mandatory

Type

Description

name

Yes

String

Definition

Account name.

Constraints

N/A

Range

The name must start with a letter and contain fewer than 36 characters, including only digits, letters, hyphens (-), and underscores (_).

Default Value

N/A

privilege

Yes

String

Definition

Account permission.

Constraints

N/A

Range

  • ReadOnly: The account has the read-only permission.
  • ReadWrite: The account has the read and write permissions.

Default Value

N/A

databases

No

Array of strings

Definition

All databases that the account has access permissions for.

Constraints

If this parameter is not transferred, the databases remain unchanged.

Response Parameters

Status code: 202

Table 5 Response body parameters

Parameter

Type

Description

job_id

String

Definition

Task ID.

Range

N/A

Example Requests

Changing permissions for two database accounts (Set privilege of user test1 to ReadOnly and databases to [ "1", "2" ], and privilege of user test2 to ReadWrite and databases to [ "3", "4" ].)
PUT https://{endpoint}/v3/054e292c9880d4992f02c0196d3ea468/redis/instances/3d39c18788b54a919bab633874c159dfin12/db-users/privilege
 
{
  "users" : [ { 
    "name" : "test1", 
    "privilege" : "ReadOnly", 
    "databases" : [ "1", "2" ] 
  }, { 
    "name" : "test2", 
    "privilege" : "ReadWrite", 
    "databases" : [ "3", "4" ] 
  } ] 
}

Example Responses

Status code: 202

Accepted

{ 
  "job_id" : "f85104b5-4a9c-4e0f-9505-fc5409d8f7ae" 
}

Status Codes

For details, see Status Codes.

Error Codes

For details, see Error Codes.