---
title: "Checks a password or passwordless token for the requested account."
method: POST
path: "/accounts/{email}/ispasswordvalid"
tags: ["accounts"]
---

# Checks a password or passwordless token for the requested account.

`POST /accounts/{email}/ispasswordvalid`

<Check title="Required Permissions" icon="key">The user must be an admin.</Check>

## Path parameters

- `email` string, required

## Headers

- `aw-internal-request` string, required

## Request body

- PasswordForm
  - `password` string, nullable — The password to validate.

## Response `200`

OK

- boolean

## Other responses

- `400` — Bad Request
- `401` — Unauthorized

## Changes

- **2026-09-20** `5332322ffca3` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/awork-io/apis/api-v1-reference/changes/accounts/:email/ispasswordvalid/post.md)

---

[API](https://skmtc.dev/awork-io/apis/api-v1-reference.md) · [All operations](https://skmtc.dev/awork-io/apis/api-v1-reference/llms.txt) · [OpenAPI document](https://skmtc.dev/awork-io/apis/api-v1-reference/revisions/eadefd26df12?raw)
