Skip to content

Set a new password with a one-time reset link

POST
/auth/password-reset
curl --request POST \
--url https://example.com/api/v1/auth/password-reset \
--header 'Content-Type: application/json' \
--data '{ "token": "example", "newPassword": "example" }'

Reset links are issued by an administrator. Redeeming one sets the new password and ends every session and API token of the user.

Media typeapplication/json
object
token
required

The reset link’s secret, skr_….

string
newPassword
required
string
>= 15 characters <= 256 characters
Examplegenerated
{
"token": "example",
"newPassword": "example"
}

Password changed.

The request is invalid.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}