Skip to main content

setupToken is now required to set a password

POST /api/auth/set-password now requires the setupToken returned by POST /api/auth/verify-code (or the emailed verification link). A request without a valid token is rejected with 401; a token can be used once and expires after 30 minutes.

The browser sign-up flow already sends it. If you automate signup, update your flow to the order below and pass the token from step 2 to step 3:

  1. POST /api/auth/register with the email
  2. POST /api/auth/verify-code with the emailed code: the response includes setupToken
  3. POST /api/auth/set-password with email, password and setupToken

If your request is rejected, request a fresh code and repeat from step 2. The full request shapes are in Authentication and the OpenAPI document.