> ## Documentation Index
> Fetch the complete documentation index at: https://docs.prisme.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Change Password

> Set a new password for the current user (or a first one for a passkey-only account). Needs a recent re-authentication (403 `StepUpRequired` otherwise). Every other session of the user is signed out, this one stays open, and the user is told by email. Refused with 400 `InvalidPassword` when the password breaks the policy; `details.reason` says why (`length`, `policy`, `breached`, `personalInfo`, `reused`).



## OpenAPI

````yaml /api-reference/swagger.yml put /v2/user/password
openapi: 3.0.0
info:
  version: 1.0.0
  title: Prisme.ai APIs
  description: Prisme.ai APIs specifications
  termsOfService: https://www.prisme.ai/mentions-legales
  contact:
    name: Prisme.ai Support Team
    email: support@prisme.ai
    url: https://www.prisme.ai
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - url: https://api.studio.prisme.ai
    description: Prisme.ai Cloud
  - url: https://{customDomain}
    description: Self-hosted Prisme.ai instance
    variables:
      customDomain:
        default: api.your-prisme-instance.com
        description: API hostname of your self-hosted Prisme.ai deployment
  - url: http://localhost:3001
    description: Local development
security:
  - BearerAuth: []
  - OrgApiKeyAuth: []
  - BearerAuth: []
    OrgApiKeyAuth: []
tags:
  - name: API Gateway
    description: >-
      Authentication, session management, SSO providers, and user profile
      endpoints.
  - name: Prisme.ai Workspaces
    description: >-
      CRUD operations for workspaces and their resources (pages, apps,
      automations, imports, variables).
  - name: Prisme.ai Runtime
    description: Execute workspace automations and manage their runtime lifecycle.
  - name: Prisme.ai Events
    description: Event ingestion, delivery, and subscription filtering across the platform.
  - name: Organizations
    description: >-
      Manage organizations, members, roles, invites, groups, and org-level
      service accounts.
  - name: Subscriptions
    description: >-
      Manage organization subscription plans and tier assignments (SuperAdmin
      only).
  - name: Secrets
    description: Read and patch encrypted key-value secrets scoped to a workspace.
  - name: ApiKeys
    description: Create, list, rotate, and validate workspace-scoped API keys.
  - name: Permissions
    description: >-
      Share or unshare resources (workspaces, pages, …) with users via roles or
      fine-grained rules.
  - name: Monitoring
    description: Platform readiness checks across services (SuperAdmin only).
  - name: AuthProviders
  - name: OIDC
    description: >-
      Endpoints of the embedded OpenID Connect provider, mounted under /oidc.
      The protocol endpoints follow OpenID Connect Core / OAuth 2.0 and are best
      resolved from GET /oidc/.well-known/openid-configuration; the
      /oidc/interaction/* routes are Prisme.ai-specific and covered by no
      standard.
paths:
  /v2/user/password:
    put:
      tags:
        - API Gateway
      summary: Change Password
      description: >-
        Set a new password for the current user (or a first one for a
        passkey-only account). Needs a recent re-authentication (403
        `StepUpRequired` otherwise). Every other session of the user is signed
        out, this one stays open, and the user is told by email. Refused with
        400 `InvalidPassword` when the password breaks the policy;
        `details.reason` says why (`length`, `policy`, `breached`,
        `personalInfo`, `reused`).
      operationId: changePassword
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - password
              properties:
                password:
                  type: string
                  description: New user password
      responses:
        '200':
          description: Success Response
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - revokedSessions
                properties:
                  success:
                    type: boolean
                  revokedSessions:
                    type: number
                    description: How many other sessions were signed out
                  revocationIncomplete:
                    type: boolean
                    description: >-
                      The password changed but some sessions could not be signed
                      out; the user should check their devices
        '400':
          description: Bad parameters
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BadParametersError'
        '401':
          description: Unauthenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthenticationError'
        '403':
          description: >-
            A recent re-authentication is required, or this account has no local
            identity
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
components:
  schemas:
    BadParametersError:
      type: object
      properties:
        error:
          type: string
          example: BadParameters
        message:
          type: string
        details: {}
    AuthenticationError:
      type: object
      properties:
        error:
          type: string
          example: AuthenticationError
        message:
          type: string
          example: Unauthenticated
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          example: ForbiddenError
        message:
          type: string
          example: Forbidden
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    OrgApiKeyAuth:
      type: apiKey
      in: header
      name: x-prismeai-api-key

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.