Skip to main content

Change password

MethodPath
PATCH/v2/auth/change-password

Authentication · Account routes

Changes the password of the signed-in user. Use it from an account settings screen where the user knows the current password. A user who has forgotten it uses Send a password reset email.

note

This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.

Auth: Bearer token of a patient or a practitioner. Scope: The User of the token.

Request​

Body​

NameTypeRequiredDescription
oldPasswordstringYesThe current password.
newPasswordstringYesThe new password. Ovok applies no length or strength rule, so check it in your app. It can equal the old password.

Behaviour​

  • oldPassword must match the current password. A wrong oldPassword, or an account with no password set, gives 401.
  • That 401 has the same status and body as an invalid token. Do not treat it as an expired session: show an error next to the field, and call Get account information if you need to tell the two apart.
  • The route does not end existing sessions. Use Revoke sessions with other to sign out the other devices.
  • The email address is not marked as verified by this route.
  • The response is the updated User, without its password hash.

Example​

curl -X PATCH 'https://api.sandbox.ovok.com/v2/auth/change-password' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"oldPassword": "<current password>",
"newPassword": "<new password>"
}'

Successful response​

200 — The password is changed. The body is the User, trimmed here.

{
"resourceType": "User",
"id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"meta": { "lastUpdated": "2026-10-09T09:15:00.000Z" },
"firstName": "Alex",
"lastName": "Example",
"email": "alex@example.com"
}
FieldTypeDescription
resourceType"User"Always User.
idstring (uuid)User id.
meta.lastUpdatedstringWhen the User was last changed. ISO 8601.
firstNamestringFirst name.
lastNamestringLast name.
emailstringSign-in email address.

The password hash is never returned. Other fields of the User can be present.

Errors​

StatusMeaning
401The bearer token is missing, invalid, expired or revoked, oldPassword is wrong, or the account has no password.
422oldPassword or newPassword is missing or not a string.
429Too many requests.