PingOne Platform APIs

Password Recover

   

POST {{apiPath}}/environments/{{envID}}/users/{{userID}}/password

The POST {{apiPath}}/environments/{{envID}}/users/{{userID}}/password endpoint is called to recover a forgotten password and set a new password. The request body requires the recoveryCode and newPassword attributes. This operation uses the application/vnd.pingidentity.password.recover+json custom media type as the content type in the request header.

The sample shows the POST {{apiPath}}/environments/{{envID}}/users/{{userID}}/password operation to recover a password for the user identified by the environment ID and user ID.

The password reset failure count is set at five (5) failed attempts with a given code. After five failed attempts, the response returns a Maximum password recovery failures exceeded error message. Initiating another password recovery process resets the failure count and allows the API to be called again. The new password recovery process starts by calling the Send (Resend) Recovery Code endpoint.

When successful, it returns a 200 OK message, generates a USER.UNLOCKED event, and resets the MFA lockout counter.

Prerequisites

Request Model
Property Type Required?

recoveryCode

String

Required

newPassword

String

Required

Refer to the User passwords data model for full property descriptions.

Headers

Authorization      Bearer {{accessToken}}

Content-Type      application/vnd.pingidentity.password.recover+json

Body

raw ( application/vnd.pingidentity.password.recover+json )

{
  "recoveryCode": "{{code}}",
  "newPassword": "{{newPassword}}"
}

Example Request

  • cURL

  • C#

  • Go

  • HTTP

  • Java

  • jQuery

  • NodeJS

  • Python

  • PHP

  • Ruby

  • Swift

curl --location --globoff '{{apiPath}}/environments/{{envID}}/users/{{userID}}/password' \
--header 'Content-Type: application/vnd.pingidentity.password.recover+json' \
--header 'Authorization: Bearer {{accessToken}}' \
--data '{
  "recoveryCode": "{{code}}",
  "newPassword": "{{newPassword}}"
}'
var options = new RestClientOptions("{{apiPath}}/environments/{{envID}}/users/{{userID}}/password")
{
  MaxTimeout = -1,
};
var client = new RestClient(options);
var request = new RestRequest("", Method.Post);
request.AddHeader("Content-Type", "application/vnd.pingidentity.password.recover+json");
request.AddHeader("Authorization", "Bearer {{accessToken}}");
var body = @"{" + "\n" +
@"  ""recoveryCode"": ""{{code}}""," + "\n" +
@"  ""newPassword"": ""{{newPassword}}""" + "\n" +
@"}";
request.AddStringBody(body, DataFormat.Json);
RestResponse response = await client.ExecuteAsync(request);
Console.WriteLine(response.Content);
package main

import (
  "fmt"
  "strings"
  "net/http"
  "io"
)

func main() {

  url := "{{apiPath}}/environments/{{envID}}/users/{{userID}}/password"
  method := "POST"

  payload := strings.NewReader(`{
  "recoveryCode": "{{code}}",
  "newPassword": "{{newPassword}}"
}`)

  client := &http.Client {
  }
  req, err := http.NewRequest(method, url, payload)

  if err != nil {
    fmt.Println(err)
    return
  }
  req.Header.Add("Content-Type", "application/vnd.pingidentity.password.recover+json")
  req.Header.Add("Authorization", "Bearer {{accessToken}}")

  res, err := client.Do(req)
  if err != nil {
    fmt.Println(err)
    return
  }
  defer res.Body.Close()

  body, err := io.ReadAll(res.Body)
  if err != nil {
    fmt.Println(err)
    return
  }
  fmt.Println(string(body))
}
POST /environments/{{envID}}/users/{{userID}}/password HTTP/1.1
Host: {{apiPath}}
Content-Type: application/vnd.pingidentity.password.recover+json
Authorization: Bearer {{accessToken}}

{
  "recoveryCode": "{{code}}",
  "newPassword": "{{newPassword}}"
}
OkHttpClient client = new OkHttpClient().newBuilder()
  .build();
MediaType mediaType = MediaType.parse("application/vnd.pingidentity.password.recover+json");
RequestBody body = RequestBody.create(mediaType, "{\n  \"recoveryCode\": \"{{code}}\",\n  \"newPassword\": \"{{newPassword}}\"\n}");
Request request = new Request.Builder()
  .url("{{apiPath}}/environments/{{envID}}/users/{{userID}}/password")
  .method("POST", body)
  .addHeader("Content-Type", "application/vnd.pingidentity.password.recover+json")
  .addHeader("Authorization", "Bearer {{accessToken}}")
  .build();
Response response = client.newCall(request).execute();
var settings = {
  "url": "{{apiPath}}/environments/{{envID}}/users/{{userID}}/password",
  "method": "POST",
  "timeout": 0,
  "headers": {
    "Content-Type": "application/vnd.pingidentity.password.recover+json",
    "Authorization": "Bearer {{accessToken}}"
  },
  "data": JSON.stringify({
    "recoveryCode": "{{code}}",
    "newPassword": "{{newPassword}}"
  }),
};

$.ajax(settings).done(function (response) {
  console.log(response);
});
var request = require('request');
var options = {
  'method': 'POST',
  'url': '{{apiPath}}/environments/{{envID}}/users/{{userID}}/password',
  'headers': {
    'Content-Type': 'application/vnd.pingidentity.password.recover+json',
    'Authorization': 'Bearer {{accessToken}}'
  },
  body: JSON.stringify({
    "recoveryCode": "{{code}}",
    "newPassword": "{{newPassword}}"
  })

};
request(options, function (error, response) {
  if (error) throw new Error(error);
  console.log(response.body);
});
import requests
import json

url = "{{apiPath}}/environments/{{envID}}/users/{{userID}}/password"

payload = json.dumps({
  "recoveryCode": "{{code}}",
  "newPassword": "{{newPassword}}"
})
headers = {
  'Content-Type': 'application/vnd.pingidentity.password.recover+json',
  'Authorization': 'Bearer {{accessToken}}'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)
<?php
require_once 'HTTP/Request2.php';
$request = new HTTP_Request2();
$request->setUrl('{{apiPath}}/environments/{{envID}}/users/{{userID}}/password');
$request->setMethod(HTTP_Request2::METHOD_POST);
$request->setConfig(array(
  'follow_redirects' => TRUE
));
$request->setHeader(array(
  'Content-Type' => 'application/vnd.pingidentity.password.recover+json',
  'Authorization' => 'Bearer {{accessToken}}'
));
$request->setBody('{\n  "recoveryCode": "{{code}}",\n  "newPassword": "{{newPassword}}"\n}');
try {
  $response = $request->send();
  if ($response->getStatus() == 200) {
    echo $response->getBody();
  }
  else {
    echo 'Unexpected HTTP status: ' . $response->getStatus() . ' ' .
    $response->getReasonPhrase();
  }
}
catch(HTTP_Request2_Exception $e) {
  echo 'Error: ' . $e->getMessage();
}
require "uri"
require "json"
require "net/http"

url = URI("{{apiPath}}/environments/{{envID}}/users/{{userID}}/password")

http = Net::HTTP.new(url.host, url.port);
request = Net::HTTP::Post.new(url)
request["Content-Type"] = "application/vnd.pingidentity.password.recover+json"
request["Authorization"] = "Bearer {{accessToken}}"
request.body = JSON.dump({
  "recoveryCode": "{{code}}",
  "newPassword": "{{newPassword}}"
})

response = http.request(request)
puts response.read_body
let parameters = "{\n  \"recoveryCode\": \"{{code}}\",\n  \"newPassword\": \"{{newPassword}}\"\n}"
let postData = parameters.data(using: .utf8)

var request = URLRequest(url: URL(string: "{{apiPath}}/environments/{{envID}}/users/{{userID}}/password")!,timeoutInterval: Double.infinity)
request.addValue("application/vnd.pingidentity.password.recover+json", forHTTPHeaderField: "Content-Type")
request.addValue("Bearer {{accessToken}}", forHTTPHeaderField: "Authorization")

request.httpMethod = "POST"
request.httpBody = postData

let task = URLSession.shared.dataTask(with: request) { data, response, error in
  guard let data = data else {
    print(String(describing: error))
    return
  }
  print(String(data: data, encoding: .utf8)!)
}

task.resume()