openapi: 3.0.3 info: version: 1.2.0 title: Hanko Admin Audit Logs Password API description: '## Introduction This is the OpenAPI specification for the [Hanko Admin API](https://github.com/teamhanko/hanko/blob/main/backend/README.md#start-private-api). ## Authentication The Admin API must be protected by an access management system. --- ' contact: email: developers@hanko.io license: name: AGPL-3.0-or-later url: https://www.gnu.org/licenses/agpl-3.0.txt servers: - url: https://{tenant_id}.hanko.io/admin variables: tenant_id: default: '' description: The (UU)ID of a tenant. Replace the default value with your tenant ID. tags: - name: Password paths: /password/login: post: summary: Do password login description: 'Perform a password login for the user identified by `user_id` and a given `password`. This endpoint is only available if passwords have been enabled via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `passwords.enabled`. ' operationId: passwordLogin tags: - Password deprecated: true requestBody: content: application/json: schema: type: object properties: user_id: description: The ID of the user to perform a password login for allOf: - $ref: '#/components/schemas/UUID4' password: $ref: '#/components/schemas/Password' required: - user_id - password responses: '200': description: Successful password login headers: X-Auth-Token: description: 'Present only when enabled via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `session.enable_auth_token_header` for purposes of cross-domain communication between client and Hanko API. ' schema: $ref: '#/components/schemas/X-Auth-Token' X-Session-Lifetime: description: 'Contains the seconds until the session expires. ' schema: $ref: '#/components/schemas/X-Session-Lifetime' Set-Cookie: description: 'Contains the JSON Web Token (JWT) that must be provided to protected endpoints. Cookie attributes (e.g. domain) can be set via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `session.cookie`. ' schema: $ref: '#/components/schemas/CookieSession' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalServerError' /password: put: summary: Create/Set a password description: 'Create a or update an existing `password` for the user identified by `user_id`. This endpoint is only available if passwords have been enabled via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `passwords.enabled`. ' operationId: password tags: - Password deprecated: true security: - CookieAuth: [] - BearerTokenAuth: [] requestBody: content: application/json: schema: type: object properties: user_id: description: The ID of the user to create/set a password for allOf: - $ref: '#/components/schemas/UUID4' password: $ref: '#/components/schemas/Password' required: - user_id - password responses: '200': description: Successful password update '201': description: Successful password creation '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalServerError' components: schemas: X-Session-Lifetime: description: 'Contains the seconds until the session expires. ' type: number UUID4: type: string format: uuid4 example: c339547d-e17d-4ba7-8a1d-b3d5a4d17c1c Error: type: object required: - code - message properties: code: type: integer format: int32 message: type: string X-Auth-Token: description: 'Enable via [configuration](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) option `session.enable_auth_token_header` for purposes of cross-domain communication between client and Hanko API. ' type: string format: JWT externalDocs: url: https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config CookieSession: type: string description: Value `` is a [JSON Web Token](https://www.rfc-editor.org/rfc/rfc7519.html) example: hanko=; Path=/; HttpOnly Password: description: 'The actual password, its `minLength` defaults to 8 but can be [configured](https://github.com/teamhanko/hanko/blob/main/backend/docs/Config.md#hanko-backend-config) through the `password.min_password_length` option. ' type: string minLength: 8 maxLength: 72 example: 9UnCBEx924a45P7p responses: InternalServerError: description: Internal server error content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 500 message: Internal Server Error Unauthorized: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 401 message: Unauthorized BadRequest: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 400 message: Bad Request NotFound: description: Not Found content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 404 message: Not found Forbidden: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 403 message: Forbidden securitySchemes: BearerApiKeyAuth: description: Bearer authentication header of the form `Bearer `, where `` is your API key. Must only be used when using Hanko Cloud. type: http scheme: bearer bearerFormat: API Key externalDocs: description: More about Hanko url: https://github.com/teamhanko/hanko