Skip to content

Reset a principal's password

POST
/principals/{id}:resetPassword
curl --request POST \
--url https://example.com/api/v1/principals/example:resetPassword \
--header 'Content-Type: application/json' \
--data '{ "password": "example" }'

Sets a new password for another human principal (an administrator action; the target’s current password is not required). Gated by principal:reset-password (all-scope). The new password must meet the password policy; a violation is a 422. Refused on yourself (change your own password from your profile, which verifies your current one), on an owner (owners cannot be reset by anyone), or when it would exceed the caller’s own capabilities (the takeover guard, shared with impersonation). The action is audited with the administrator as the actor.

id
required

The principal, addressed by its uuid or a human username

string

The principal, addressed by its uuid or a human username

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
password
required

The new password (at least 12 characters, not a common password, not containing the username)

string
>= 12 characters <= 256 characters

No Content

Error

Media type application/problem+json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
detail

A human-readable explanation specific to this occurrence of the problem.

string
errors

Optional list of individual error details

Array<object> | null
object
location

Where the error occurred, e.g. ‘body.items[3].tags’ or ‘path.thing-id’

string
message

Error message text

string
value

The value at the given location

instance

A URI reference that identifies the specific occurrence of the problem.

string format: uri
status

HTTP status code

integer format: int64
title

A short, human-readable summary of the problem type. This value should not change between occurrences of the error.

string
type

A URI reference to human-readable documentation for the error.

string format: uri
default: about:blank
Example
{
"$schema": "/api/v1/schemas/ErrorModel.json",
"detail": "Property foo is required but is missing.",
"instance": "https://example.com/error-log/abc123",
"status": 400,
"title": "Bad Request",
"type": "about:blank"
}