Skip to content

CustomerChangePassword

Endpoint

POST /customer/auth/change-password

Authorization

Requires a valid SESSION_CUSTOMER bearer token. The customer identity is taken only from the authenticated session; a customer_id supplied by the client is not used.

Request Parameters

Field Type Required Description
old_password string Yes Current customer password, 6–128 characters.
new_password string Yes New customer password, 6–128 characters.

Request Example

{
  "old_password": "current-password",
  "new_password": "new-secure-password"
}

Full successful response

HTTP 200:

{
  "success": true
}

Errors

HTTP Error Meaning
400 INVALID_DATA A required field is absent, has the wrong type, or violates the 6–128 character limit.
401 INVALID_CUSTOMER_SESSION The authenticated session does not contain a valid customer identity.
403 RET_INVALID_PASSWORD old_password does not match the current password, or the password changed concurrently.
404 RET_NOT_FOUND The customer no longer exists.
500 RET_ERROR The new password could not be hashed or queued for persistence.

The operation changes only the customer/cabinet password. It does not change passwords of linked trading accounts, disable OTP, issue a new token, or revoke previously issued sessions. Persistence uses the existing asynchronous CustomerManager save queue.