Create and verify a new Password verification record. The verification record can only be created if the provided user credentials are correct. Once the interaction already carries a subject (the subject pinned by a step-up authentication, or an identified user), identifier may be omitted: the password is then verified against that user's credential, the subject is read from the interaction storage, and the request never carries a raw identifier. If the password has expired under the password expiration policy, the request is rejected with password.expired and the user must reset their password before continuing.
Responses
-
The Password verification record has been successfully created and verified.
-
The verification attempts have exceeded the maximum limit.
-
The user is suspended or banned from the service.
-
Forbidden
-
identifierwas omitted but the interaction carries no subject (session.identifier_not_found). -
Conflict
-
session.invalid_credentials:Either the user is not found or the provided password is incorrect.password.expired:The password is valid but already expired.
curl \
--request POST 'https://[tenant_id].logto.app/api/experience/verification/password' \
--header "Content-Type: application/json" \
--data '{
"identifier": {
"type": "username",
"value": "string"
}
}'
{
"identifier": {
"type": "username",
"value": "string"
}
}
{}
{
"verificationId": "string"
}