Create password verification record

Add MCP server to your AI tool

Allow AI tools and LLMs to interact with the API documentation portal through MCP.

MCP server URL

https://openapi.logto.io/mcp

Standard setup for AI tools providing an mcp.json file

mcp.json
{
  "Logto API references MCP server": {
    "url": "https://openapi.logto.io/mcp"
  }
}

Close
POST /api/experience/verification/password

Create and verify a new Password verification record. The verification record can only be created if the provided user credentials are correct. Once the interaction already carries a subject (the subject pinned by a step-up authentication, or an identified user), identifier may be omitted: the password is then verified against that user's credential, the subject is read from the interaction storage, and the request never carries a raw identifier. If the password has expired under the password expiration policy, the request is rejected with password.expired and the user must reset their password before continuing.

application/json
Body object Required
One of:

Responses

  • 200 application/json

    The Password verification record has been successfully created and verified.

    Hide response attribute Show response attribute object
    • verificationId string Required

      The unique verification ID of the newly created Password verification record. The verificationId is required when verifying the user's identity via the Identification API.

  • 400

    The verification attempts have exceeded the maximum limit.

  • 401

    The user is suspended or banned from the service.

  • 403

    Forbidden

  • 404

    identifier was omitted but the interaction carries no subject (session.identifier_not_found).

  • 409

    Conflict

  • 422

    session.invalid_credentials: Either the user is not found or the provided password is incorrect.
    password.expired: The password is valid but already expired.

POST /api/experience/verification/password
curl \
 --request POST 'https://[tenant_id].logto.app/api/experience/verification/password' \
 --header "Content-Type: application/json" \
 --data '{
  "identifier": {
    "type": "username",
    "value": "string"
  }
}'
Request examples
{
  "identifier": {
    "type": "username",
    "value": "string"
  }
}
{}
Response examples (200)
{
  "verificationId": "string"
}