---
title: "Change password"
method: POST
path: "/change"
---

# Change password

`POST /change`

## Headers

- `X-CSRF-Token` XCSRFToken — unresolved $ref

## Request body

- ChangePassword
  - `password` string, required — Password
  - `new_password` string, required — New password
  - `new_password_confirm` string, required — New password - again

## Response `200`

Change password response.

- DefaultJsonResponse
  - `user` object, required — By default just 'id', and 'authentication_token' are returned. However by overriding _User::get_security_payload()_ any attributes of the User model can be returned.
    - `id` integer, required — Unique user id (primary key)
    - `authentication_token` string — Token to be used in future token-based API calls.
  - `csrf_token` string — Session CSRF token

## Other responses

- `302` — Password has been changed (non-json)
- `400` — Errors while validating form

## Changes

- **2019-07-23** `11c8459a5c04` — 2 breaking, 3 warning, 5 info
  - the response's body type changed from no type to `object` for status `200` (media type: application/json)
  - the `response/errors` response's property type changed from `array` to `object` for status `400`
  - deleted the `header` request parameter `X-XSRF-Token`
  - deleted the `query` request parameter `include_auth_token`
  - …6 more

[Change history](https://skmtc.dev/pallets-eco/apis/flask-security-external-api/changes/change/post.md)

---

[API](https://skmtc.dev/pallets-eco/apis/flask-security-external-api.md) · [All operations](https://skmtc.dev/pallets-eco/apis/flask-security-external-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/pallets-eco/flask-security-external-api/revisions/11c8459a5c04/schema)
