v1

latestOpenAPI 3.0.3Apache 2.02026-07-173769114.2 KB
public

Complete Settings Flow with Username/Email Password Method

Use this endpoint to complete a settings flow by sending an identity's updated password. This endpoint behaves differently for API and browser flows.

API-initiated flows expect application/json to be sent in the body and respond with HTTP 200 and an application/json body with the session token on success; HTTP 302 redirect to a fresh settings flow if the original flow expired with the appropriate error messages set; HTTP 400 on form validation errors. HTTP 401 when the endpoint is called without a valid session token. HTTP 403 when selfservice.flows.settings.privileged_session_max_age was reached. Implies that the user needs to re-authenticate.

Browser flows expect application/x-www-form-urlencoded to be sent in the body and responds with a HTTP 302 redirect to the post/after settings URL or the return_to value if it was set and if the flow succeeded; a HTTP 302 redirect to the Settings UI URL with the flow ID containing the validation errors otherwise. a HTTP 302 redirect to the login endpoint when selfservice.flows.settings.privileged_session_max_age was reached.

More information can be found at Ory Kratos User Settings & Profile Management Documentation.

post/self-service/settings/methods/password

Query parameters

flowstring

Flow is flow ID.

Request body

csrf_tokenstring

CSRFToken is the anti-CSRF token

type: string

passwordstring required

Password is the updated password

type: string

Response

settingsViaApiResponse