# Upload user avatar

> **Legacy.** This endpoint is kept for existing integrations. Use the current API reference for new work.

Upload user avatar

- Endpoint: `POST https://api.returning.ai/apis/v1/users/avatar`
- Section: Legacy / Users
- Authentication: `Authorization: Bearer <API_KEY>` (Community API key)
- Guide: generated from the published specification
- Last updated: 26 Sep 2026
- Web page: https://docs.returning.ai/api-reference/legacy-users/upload-user-avatar

## Authentication

- Header: `Authorization: Bearer <API_KEY>`

## Behaviour

**Legacy category**

This endpoint is retained for compatibility, historical admin tooling, or test workflows. Do not use it as the default choice for new integrations unless the backend team confirms this exact route is still supported for your community.

**What it is for**

Upload user avatar.

**How to use it**

Send a POST request to `/apis/v1/users/avatar` with the documented body, query parameters, headers, or multipart fields. Prefer the newer authenticated `/v1/...` integration API where available.

**Successful response**

HTTP 2xx. Older endpoints may return a legacy response envelope or a resource-specific payload rather than the newer `{ status, message, data }` wrapper.

**Common error states**

- `400` invalid request body, query, ObjectId, pagination, file format, or missing required field.
- `401` missing, invalid, expired, or insufficient API key/token.
- `403` key is valid but cannot access this community/channel/user/resource, where supported by the service.
- `404` route or target resource was not found. Several legacy root routes return `404` on `https://api.returning.ai`; confirm with Returning.AI before using them.
- `409` duplicate or conflicting state for create/update operations, where applicable.
- `500` unexpected Returning.AI service error.

**Legacy status**

Compatibility endpoint retained for older integrations. Do not use this endpoint for new integrations unless Returning.AI specifically tells you to maintain a legacy flow. Prefer the current `/v1/...` endpoint in the matching non-Legacy category when one exists.

## Request

### Headers

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `Authorization` | `string` | Yes | API key. (`Bearer <API_KEY>`) |

### Body

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `avatar` | `file` | Yes | Image file (JPEG, PNG, WebP, GIF). Max 5 MB |
| `idOrEmail` | `string` | Yes | User ID or email address |

Send the body as `multipart/form-data`.

### Example request

```bash
curl --request POST \
  --url https://api.returning.ai/apis/v1/users/avatar \
  --header 'Authorization: Bearer <API_KEY>' \
  --form 'avatar=@<file>' \
  --form 'idOrEmail='
```

## Response

### Response fields

| Field | Type | Presence | Description |
| --- | --- | --- | --- |
| `status` | `string` | always | status |
| `data` | `object` | always | - |
| `data.avatar` | `string` | always | - |

### Example response (200)

```json
{
  "status": "success",
  "data": {
    "avatar": "https://avatars.githubusercontent.com/u/57716154"
  }
}
```

## Errors

### Fix the request

| Status | Code | What to do |
| --- | --- | --- |
| 400 | - | Invalid request. Check required parameters, body fields, file format, pagination values, and ObjectId values. |
| 401 | - | Missing, invalid, expired, or insufficient API key/token. Older permission middleware may also return 401 for missing permissions. |
| 403 | - | The API key is valid but is not allowed to access this community, channel, user, or resource. |

### Fix the data

| Status | Code | What to do |
| --- | --- | --- |
| 409 | - | The request conflicts with an existing resource or immutable state, such as a duplicate slug/key/name or an already-processed record. |

### Retry with backoff

| Status | Code | What to do |
| --- | --- | --- |
| 500 | - | Unexpected Returning.AI service error. |

## Next step

- [List integration API keys](https://docs.returning.ai/api-reference/legacy-api-keys/list-integration-api-keys.md): `GET /apis/v1/communities/{communityId}/api-keys`.
