---
title: "Change current user's password"
method: POST
path: "/auth/change-password"
tags: ["auth"]
---

# Change current user's password

`POST /auth/change-password`

Allows a locally authenticated builtin user to change their own password. Externally authenticated users do not have Dagu passwords.

## Request body

- ChangePasswordRequest — Request body for changing password
  - `currentPassword` string, required — Current password for verification
  - `newPassword` string, required — New password to set

## Response `200`

Password changed successfully

- SuccessResponse — Generic success response
  - `message` string, required — Success message

## Other responses

- `400` — Invalid request (e.g., weak password)
- `401` — Not authenticated or wrong current password
- `403` — Password is managed by the authentication provider
- `default` — Unexpected error

## Changes

- **2026-07-23** (v1) `75b8e91aaf57` — 12 warning
  - added the new `conflict` enum value to the `code` response property for the response status `400`
  - added the new `conflict` enum value to the `code` response property for the response status `401`
  - added the new `conflict` enum value to the `code` response property for the response status `403`
  - added the new `conflict` enum value to the `code` response property for the response status `default`
  - …8 more
- **2026-07-20** (v1) `a53d29bdca9e` — 1 info
  - added the non-success response with the status `403`
- **2026-05-24** (v1) `8a2d5d3e9608` — 3 warning
  - added the new `rate_limited` enum value to the `code` response property for the response status `400`
  - added the new `rate_limited` enum value to the `code` response property for the response status `401`
  - added the new `rate_limited` enum value to the `code` response property for the response status `default`
- **2026-04-30** (v1) `50e1d517afc1` — 3 info
  - removed the `rate_limited` enum value from the `code` response property for the response status `400`
  - removed the `rate_limited` enum value from the `code` response property for the response status `401`
  - removed the `rate_limited` enum value from the `code` response property for the response status `default`

[Change history](https://skmtc.dev/dagucloud/apis/dagu/changes/auth/change-password/post.md)

---

[API](https://skmtc.dev/dagucloud/apis/dagu.md) · [All operations](https://skmtc.dev/dagucloud/apis/dagu/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/dagucloud/dagu/revisions/f6dcf7250db7/schema)
