Skip to content

MngCheckClientPassword

Verifies a client cabinet password without changing it. The answer is a boolean: the stored hash is never returned.

The command is available through the manager command API only; there is no REST path for it. The kind is fixed by the command name, so customer_kind is not accepted on input. See Clients and Leads Commands.

It replaces the deprecated MngCheckCustomerPassword.

Access Control

Allowed sessions:

  • SESSION_MANAGER
  • SESSION_ADMIN
  • SESSION_DEALER
  • SESSION_CRM_MANAGER
  • SESSION_CRM_ADMIN

The caller must have CRM access and see_clients_contacts. The record brand and desk must be inside the manager scope; admin scope bypasses this check.

Request

{
  "command": "MngCheckClientPassword",
  "extID": "1",
  "data": {
    "customer_id": 1,
    "password": "strong-password"
  }
}

Request Data

Field Type Required Description
customer_id int Yes Target customer id, 1 or greater
password string Yes Password to verify, 6 to 128 characters

Response Data

{
  "customer_id": 1,
  "valid": true
}
Field Type Description
customer_id int The identifier passed in the request
valid bool Whether the supplied password matches the stored one

A wrong password is not an error: the command answers 200 with valid: false.

Errors

HTTP Error Description
400 INVALID_DATA Request validation failed
400 RET_INVALID_DATA The customer exists but is not a client
403 RET_NOT_ENOUGH_RIGHTS Missing permission, missing scope, or the record is outside the caller's visibility
404 RET_NOT_FOUND No customer with that identifier exists

Every error carries a message field with free-form text. Its contents are not part of the contract; branch on error.