---
title: "Forgot-password step 2: set new password and re-enter signin"
method: POST
path: "/identity/forgot_password/step_2"
tags: ["identity", "password"]
---

# Forgot-password step 2: set new password and re-enter signin

`POST /identity/forgot_password/step_2`

## Request body

- IdentityForgotPasswordStep2Input
  - `new_password` string
  - `session_token` string

## Response `200`

OK

- IdentitySignInStep1Output
  - `masked_phone_number` string
  - `session_token` string
  - `totp_secret` IdentityTOTPSecretOutput
    - `secret` string
    - `url` string
  - `twofa_method` string

## Other responses

- `default` — Error response.

## Changes

- **2026-09-01** `f2d9f80610d9` — 1 info
  - added the optional property `error/api_client_id` to the response with the `default` status

[Change history](https://skmtc.dev/stablesea/apis/stable-sea-backend/changes/identity/forgot_password/step_2/post.md)

---

[API](https://skmtc.dev/stablesea/apis/stable-sea-backend.md) · [All operations](https://skmtc.dev/stablesea/apis/stable-sea-backend/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/stablesea/stable-sea-backend/revisions/f2d9f80610d9/schema)
