---
title: "POST /mobile-sync/devices/{device_id}/rotate-password"
method: POST
path: "/mobile-sync/devices/{device_id}/rotate-password"
tags: ["mobile-sync"]
---

# POST /mobile-sync/devices/{device_id}/rotate-password

`POST /mobile-sync/devices/{device_id}/rotate-password`

## Path parameters

- `device_id` string, required

## Request body

- RotateMobilePasswordRequest — Request body for `POST /mobile-sync/devices/{device_id}/rotate-password`. `password` absent → auto-mint a new plaintext; a value is validated.
  - `password` string, nullable

## Response `200`

Password rotated (one-time echo)

- RotateMobilePasswordEnvelope — Canonical success envelope: `{ "data": T, "ts": <unix millis i64> }`. `ts` is `chrono::Utc::now().timestamp_millis()`, set in the webserver handler via [`ApiEnvelope::now`] (the contract carries only the type + the clock helper, not a hard dependency on when the handler reads the clock). `rename_all = "camelCase"` is a no-op for the single-word fields here but is declared for forward-compat. IMPORTANT (utoipa v4): every concrete `ApiEnvelope<X>` that needs a named OpenAPI component is declared in the `#[aliases(...)]` block below. Add a new alias line whenever a new payload type needs enveloping. NEVER register the bare `ApiEnvelope` in `components(schemas(...))` — utoipa errors on a bare generic, and an un-aliased generic inlines an anonymous schema.
  - `data` RotateMobilePasswordResultDto, required — Result of rotating a device password. `password` is the one-time plaintext echo; the old password is immediately invalidated.
    - `deviceId` string, required
    - `password` string, required
    - `username` string, required
  - `ts` integer, required — Server time when the response was built (unix epoch milliseconds).

## Other responses

- `404` — Device not found
- `422` — Invalid password
- `500` — Internal server error
- `503` — Mobile sync facade unavailable

---

[API](https://skmtc.net/uniclipboard/apis/uniclipboard-daemon-api.md) · [All operations](https://skmtc.net/uniclipboard/apis/uniclipboard-daemon-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/uniclipboard/uniclipboard-daemon-api/versions/10dd20bcf330/schema)
