openapi: 3.2.0 info: title: Authelia Password Reset API description: Authelia is an open-source authentication and authorization server and portal fulfilling the identity and access management (IAM) role of information security in providing multi-factor authentication and single sign-on (SSO) for your applications via a web portal. Authelia is an OpenID Connect 1.0 Provider which is OpenID Certified™ allowing comprehensive integrations, and acts as a companion for common reverse proxies. contact: name: Support url: https://www.authelia.com/contact/ email: team@authelia.com license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 version: 1.0.0 servers: - url: https://auth.example.com description: Authelia API tags: - name: Password Reset description: Password reset endpoints paths: /api/reset-password/identity/start: post: operationId: postResetPasswordIdentityStart tags: - Password Reset summary: Identity Verification Token Creation description: 'This endpoint is step 1 of 3 in the password reset process. It validates the user session and sends the user an email with a token and a link to reset their password. This step also generates a session cookie for the rest of the process. The same session cookie must be used for all steps in this process.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/handlers.PasswordResetStep1RequestBody' responses: '200': description: Successful Operation content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.OK' '429': description: Too Many Requests content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.KO' headers: Retry-After: schema: type: string format: http-date description: The date time that the request can be retried. security: - authelia_auth: [] /api/reset-password/identity/finish: post: operationId: postResetPasswordIdentityFinish tags: - Password Reset summary: Identity Verification Token Validation description: 'This endpoint is step 2 of 3 in the password reset process. It validates the user session and reset token. The same session cookie must be used for all steps in this process.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/middlewares.IdentityVerificationFinishBody' responses: '200': description: Successful Operation content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.OK' '429': description: Too Many Requests content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.KO' headers: Retry-After: schema: type: string format: http-date description: The date time that the request can be retried. security: - authelia_auth: [] /api/reset-password: post: operationId: postResetPassword tags: - Password Reset summary: Password Reset description: 'The password reset endpoint validates the user session and changes the password. The same session cookie must be used for all steps in this process. This endpoint is step 3 of 3 in the password reset process.' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/handlers.PasswordResetStep2RequestBody' responses: '200': description: Successful Operation content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.OK' '429': description: Too Many Requests content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.KO' headers: Retry-After: schema: type: string format: http-date description: The date time that the request can be retried. security: - authelia_auth: [] delete: operationId: deleteResetPassword tags: - Password Reset summary: Password Reset description: The password reset endpoint revokes a JWT associated with a password reset operation. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/handlers.PasswordResetBodyDELETE' responses: '200': description: Successful Operation content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.API' '429': description: Too Many Requests content: application/json: schema: $ref: '#/components/schemas/middlewares.Response.KO' headers: Retry-After: schema: type: string format: http-date description: The date time that the request can be retried. security: - authelia_auth: [] components: schemas: handlers.PasswordResetBodyDELETE: required: - token type: object properties: token: type: string middlewares.Response.KO: type: object required: - status properties: status: enum: - KO type: string examples: - KO message: type: string examples: - Operation Failed. handlers.PasswordResetStep1RequestBody: required: - username type: object properties: username: type: string examples: - john middlewares.Response.OK: type: object required: - status properties: status: enum: - OK type: string examples: - OK data: type: object description: The data content for the response. middlewares.Response.API: oneOf: - $ref: '#/components/schemas/middlewares.Response.OK' - $ref: '#/components/schemas/middlewares.Response.KO' handlers.PasswordResetStep2RequestBody: required: - password type: object properties: password: type: string examples: - password middlewares.IdentityVerificationFinishBody: required: - token type: object properties: token: type: string examples: - eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MDc5MjU1OTYsImlzcyI6IkF1dGhlbGlhIiwiYWN0aW9uIjoiUmVzZXRQYXNzd29yZCIsInVzZXJuYW1lIjoiQW1pciJ9.636yqRrUCGCe4jsMCsonleX5CYWHncYqZum-YYb6VaY securitySchemes: authelia_auth: type: apiKey name: authelia_session in: cookie openid: type: openIdConnect openIdConnectUrl: https://auth.example.com/.well-known/openid-configuration