Change password
Profile & security
Change password
Session-only. Change the account password. Policy: 10–200 characters including an uppercase letter, a lowercase letter, and a digit. Success bumps the account’s token version (every other session is invalidated) and refreshes the current session cookie.
POST
Change password
Authorizations
Browser session cookie minted by POST /auth/login (or passkey
login). httpOnly, SameSite=Lax, 24 h TTL. Endpoints marked
Session-only accept only this credential and return
403 session_required for API keys.
Body
application/json