---
title: "Validate the proposed password"
method: POST
path: "/v2/users/self/password/validate"
tags: ["Users"]
---

# Validate the proposed password

`POST /v2/users/self/password/validate`

validate the password and return a score

## Request body

- PasswordRequest
  - `password` string, required — a password that passes validation

## Response `200`

the password was checked and a score returned

- ValidatePasswordResponse
  - `score` integer — More secure passwords are given a higher score. <P> For a password to be acceptable for use in Velo, it must score at least 3
  - `valid` boolean — if true then the password can be accepted
  - `warning` string — Any warning message as a reason for the given score.
  - `suggestions` string[]

## Other responses

- `400` — Invalid request. See Error message payload for details of failure
- `401` — Invalid access token. May be expired or invalid
- `403` — The authentication does not have permissions to access the resource This usually occurs when there is a valid authentication instance (client or user) but they do not have the required permissions

## Changes

- **2026-07-13** `05c3f09fc50a` — 2 breaking
  - the `password` request property's maxLength was decreased to `64`
  - the `password` request property's minLength was increased from `8` to `10`
- **2020-09-25** `dd71433847a6` — 3 breaking, 18 info
  - the `errors/items/` response's property type/format changed from ``/`` to `object`/`` for status `400`
  - the `errors/items/` response's property type/format changed from ``/`` to `object`/`` for status `401`
  - the `errors/items/` response's property type/format changed from ``/`` to `object`/`` for status `403`
  - added the optional property `errors/items/errorCode` to the response with the `400` status
  - …17 more
- **2020-01-28** `1b2abf26b5d6` — 6 breaking, 3 warning
  - the response's body type/format changed from `object`/`` to ``/`` for status `400`
  - the response's body type/format changed from `object`/`` to ``/`` for status `401`
  - the response's body type/format changed from `object`/`` to ``/`` for status `403`
  - the `errors/items/` response's property type/format changed from `object`/`` to ``/`` for status `400`
  - …5 more
- **2019-12-11** `a0b19fa311c0` — 1 info
  - endpoint added
- **2019-07-15** `ced8e167a97c` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/velopaymentsapi/apis/velo-payments-apis/changes/v2/users/self/password/validate/post.md)

---

[API](https://skmtc.dev/velopaymentsapi/apis/velo-payments-apis.md) · [All operations](https://skmtc.dev/velopaymentsapi/apis/velo-payments-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/velopaymentsapi/velo-payments-apis/revisions/05c3f09fc50a/schema)
