---
title: "Complete password change"
method: POST
path: "/users/@me/password-change/complete"
tags: ["Users"]
---

# Complete password change

`POST /users/@me/password-change/complete`

Completes the password change after email verification. Requires the verification proof and new password. Invalidates all existing sessions and returns the replacement session token.

## Request body

- PasswordChangeCompleteRequest
  - `ticket` string, required — Password change ticket identifier
  - `verification_proof` string, required — Proof token obtained from verifying the email code
  - `new_password` string, required

## Response `200`

Success

- PasswordChangeCompleteResponse
  - `token` string, required — Authentication token for the newly created session
  - `auth_session_id_hash` string, required — Base64url-encoded hash of the newly created authentication session

## Other responses

- `400` — Bad Request - The request was malformed or contained invalid data
- `401` — Unauthorized - Authentication is required or the token is invalid
- `403` — Forbidden - You do not have permission to perform this action
- `429` — Too Many Requests - You are being rate limited
- `500` — Internal Server Error - An unexpected error occurred

---

[API](https://skmtc.dev/fluxer/apis/fluxer-api.md) · [All operations](https://skmtc.dev/fluxer/apis/fluxer-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/fluxer/fluxer-api/revisions/d9c706133cc5/schema)
