---
title: Change password
sidebar_label: Change password
sidebar_position: 6
description: Change the password of the signed-in user with PATCH /v2/auth/change-password, using the current password as proof.
---

# Change password

| Method | Path |
| --- | --- |
| `PATCH` | `/v2/auth/change-password` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes)

Changes the password of the signed-in user. Use it from an account settings screen where the user knows the current password. A user who has forgotten it uses [Send a password reset email](/authentication/account/reset-password).

:::note
This is an account-level route. It has no `/auth/tenant/` variant. Use the access token that a [tenant sign-in](/authentication) returns.
:::

**Auth:** Bearer token of a patient or a practitioner.
**Scope:** The User of the token.

## Request

### Body

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `oldPassword` | `string` | Yes | The current password. |
| `newPassword` | `string` | Yes | The new password. Ovok applies no length or strength rule, so check it in your app. It can equal the old password. |

## Behaviour

- `oldPassword` must match the current password. A wrong `oldPassword`, or an account with no password set, gives `401`.
- That `401` has the same status and body as an invalid token. Do not treat it as an expired session: show an error next to the field, and call [Get account information](/authentication/account/get-account-information) if you need to tell the two apart.
- The route does not end existing sessions. Use [Revoke sessions](/authentication/account/revoke-sessions) with `other` to sign out the other devices.
- The email address is not marked as verified by this route.
- The response is the updated User, without its password hash.

## Example

```bash
curl -X PATCH 'https://api.sandbox.ovok.com/v2/auth/change-password' \
  -H "Authorization: Bearer ${OVOK_TOKEN}" \
  -H 'Content-Type: application/json' \
  -d '{
    "oldPassword": "<current password>",
    "newPassword": "<new password>"
  }'
```

## Successful response

`200` — The password is changed. The body is the User, trimmed here.

```json
{
  "resourceType": "User",
  "id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
  "meta": { "lastUpdated": "2026-10-09T09:15:00.000Z" },
  "firstName": "Alex",
  "lastName": "Example",
  "email": "alex@example.com"
}
```

| Field | Type | Description |
| --- | --- | --- |
| `resourceType` | `"User"` | Always `User`. |
| `id` | `string (uuid)` | User id. |
| `meta.lastUpdated` | `string` | When the User was last changed. ISO 8601. |
| `firstName` | `string` | First name. |
| `lastName` | `string` | Last name. |
| `email` | `string` | Sign-in email address. |

The password hash is never returned. Other fields of the User can be present.

## Errors

| Status | Meaning |
| --- | --- |
| `401` | The bearer token is missing, invalid, expired or revoked, `oldPassword` is wrong, or the account has no password. |
| `422` | `oldPassword` or `newPassword` is missing or not a string. |
| `429` | Too many requests. |
