Change password
POST
/cognito/change-password
Changes the password of an email/password account, given the current one.
Cookie session only. A request authenticated with an Authorization: Bearer header or an API key answers 401 Not authenticated. Google and Apple accounts have no password to change.
Rate limited at 10 requests/minute per IP (authentication bucket).
Authorizations
BearerAuth
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Type
HTTP (bearer)
Request Body
application/json
JSON
{
"currentPassword": "string",
"newPassword": "string"
}
Responses
Password changed
application/json
JSON
{
"success": true,
"message": "string"
}