---
title: "POST /policies/password/"
method: POST
path: "/policies/password/"
tags: ["policies"]
---

# POST /policies/password/

`POST /policies/password/`

Password Policy Viewset

## Request body

- PasswordPolicyRequest — Password Policy Serializer
  - `name` string, required
  - `execution_logging` boolean — When this option is enabled, all executions of this policy will be logged. By default, only execution errors are logged.
  - `password_field` string — Field key to check, field keys defined in Prompt stages are available.
  - `amount_digits` integer
  - `amount_uppercase` integer
  - `amount_lowercase` integer
  - `amount_symbols` integer
  - `length_min` integer
  - `symbol_charset` string
  - `error_message` string
  - `check_static_rules` boolean
  - `check_have_i_been_pwned` boolean
  - `check_zxcvbn` boolean
  - `hibp_allowed_count` integer — How many times the password hash is allowed to be on haveibeenpwned
  - `zxcvbn_score_threshold` integer — If the zxcvbn score is equal or less than this value, the policy will fail.

## Response `201`

- PasswordPolicy — Password Policy Serializer
  - `pk` string, uuid, required
  - `name` string, required
  - `execution_logging` boolean — When this option is enabled, all executions of this policy will be logged. By default, only execution errors are logged.
  - `component` string, required — Get object component so that we know how to edit the object
  - `verbose_name` string, required — Return object's verbose_name
  - `verbose_name_plural` string, required — Return object's plural verbose_name
  - `meta_model_name` string, required — Return internal model name
  - `bound_to` integer, required — Return objects policy is bound to
  - `last_updated` string, date-time, required
  - `created` string, date-time, required
  - `password_field` string — Field key to check, field keys defined in Prompt stages are available.
  - `amount_digits` integer
  - `amount_uppercase` integer
  - `amount_lowercase` integer
  - `amount_symbols` integer
  - `length_min` integer
  - `symbol_charset` string
  - `error_message` string
  - `check_static_rules` boolean
  - `check_have_i_been_pwned` boolean
  - `check_zxcvbn` boolean
  - `hibp_allowed_count` integer — How many times the password hash is allowed to be on haveibeenpwned
  - `zxcvbn_score_threshold` integer — If the zxcvbn score is equal or less than this value, the policy will fail.

## Other responses

- `400`
- `403`

## Changes

- **2026-09-08** `c5b9786ece16` — 2 info
  - added the required property `created` to the response with the `201` status
  - added the required property `last_updated` to the response with the `201` status

[Change history](https://skmtc.dev/goauthentik/apis/authentik/changes/policies/password/post.md)

---

[API](https://skmtc.dev/goauthentik/apis/authentik.md) · [All operations](https://skmtc.dev/goauthentik/apis/authentik/llms.txt) · [OpenAPI document](https://skmtc.dev/goauthentik/apis/authentik/revisions/72050dd9f6ba?raw)
