Change password
| Method | Path |
|---|---|
PATCH | /v2/auth/change-password |
Authentication · Account routes
Changes the password of the signed-in user. Use it from an account settings screen where the user knows the current password. A user who has forgotten it uses Send a password reset email.
note
This is an account-level route. It has no /auth/tenant/ variant. Use the access token that a tenant sign-in returns.
Auth: Bearer token of a patient or a practitioner. Scope: The User of the token.
Request
Body
| Name | Type | Required | Description |
|---|---|---|---|
oldPassword | string | Yes | The current password. |
newPassword | string | Yes | The new password. Ovok applies no length or strength rule, so check it in your app. It can equal the old password. |
Behaviour
oldPasswordmust match the current password. A wrongoldPassword, or an account with no password set, gives401.- That
401has the same status and body as an invalid token. Do not treat it as an expired session: show an error next to the field, and call Get account information if you need to tell the two apart. - The route does not end existing sessions. Use Revoke sessions with
otherto sign out the other devices. - The email address is not marked as verified by this route.
- The response is the updated User, without its password hash.
Example
curl -X PATCH 'https://api.sandbox.ovok.com/v2/auth/change-password' \
-H "Authorization: Bearer ${OVOK_TOKEN}" \
-H 'Content-Type: application/json' \
-d '{
"oldPassword": "<current password>",
"newPassword": "<new password>"
}'
Successful response
200 — The password is changed. The body is the User, trimmed here.
{
"resourceType": "User",
"id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"meta": { "lastUpdated": "2026-10-09T09:15:00.000Z" },
"firstName": "Alex",
"lastName": "Example",
"email": "alex@example.com"
}
| Field | Type | Description |
|---|---|---|
resourceType | "User" | Always User. |
id | string (uuid) | User id. |
meta.lastUpdated | string | When the User was last changed. ISO 8601. |
firstName | string | First name. |
lastName | string | Last name. |
email | string | Sign-in email address. |
The password hash is never returned. Other fields of the User can be present.
Errors
| Status | Meaning |
|---|---|
401 | The bearer token is missing, invalid, expired or revoked, oldPassword is wrong, or the account has no password. |
422 | oldPassword or newPassword is missing or not a string. |
429 | Too many requests. |