Frontegg Password Settings API

The Password Settings API from Frontegg — 11 operation(s) for password settings.

Business capability
Identity & Access Management BC-620.20

Operations 15

POST /resources/configurations/v1/password Create or Update Password Configuration #
GET /resources/configurations/v1/password Get Password Policy Configuration #
POST /resources/configurations/v1/password-history-policy Create Password History Policy #
PATCH /resources/configurations/v1/password-history-policy Update Password History Policy #
GET /resources/configurations/v1/password-history-policy Get Password History Policy #
POST /resources/users/v1/passwords/reset Reset Password #
POST /resources/users/v1/passwords/reset/verify Verify Password #
POST /resources/users/v1/passwords/change Change Password #
GET /resources/users/v1/passwords/config Get Strictest Password Configuration #
POST /resources/users/v2/passwords/reset/email Reset Password via Email #
POST /resources/users/v2/passwords/reset/sms Reset Password via SMS #
POST /resources/users/v2/passwords/reset/sms/verify Verify Password Reset Code Sent via SMS #
GET /resources/configurations/v1/password-rotation Get Password Expiration Period Configuration #
POST /resources/configurations/v1/password-rotation Manage Password Expiration #
GET /resources/configurations/v1/password-rotation/vendor Get Environment Configuration for Password Expiration Period #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/frontegg-password-settings-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

frontegg-password-settings-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Entitlements Agent (PDP) Password Settings API
  description: 'The endpoints in this section pertain to the usage of an Entitlements Agent. When your application or service needs to verify entitlements, it can query the Entitlements Agent directly via HTTP.


    These endpoints can be integrated into any backend framework, enabling you to leverage entitlements for advanced authorization needs.'
  version: '1.0'
tags:
- name: Password Settings
  x-displayName: Password settings
paths:
  /resources/configurations/v1/password:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: PasswordPolicyController_addOrUpdatePasswordConfig
      summary: Create or Update Password Configuration
      description: Create or update the password policy for the entire environment.
      parameters:
      - name: frontegg-tenant-id
        in: header
        description: The account (tenant) ID identifier
        required: false
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PasswordConfigRequest'
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordConfigResponse'
      tags:
      - Password Settings
      security:
      - bearer: []
    get:
      operationId: PasswordPolicyController_getPasswordConfig
      summary: Get Password Policy Configuration
      description: Retrieve the password policy for all accounts (tenants).
      parameters:
      - name: frontegg-tenant-id
        in: header
        description: The account (tenant) ID identifier
        required: false
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordConfigResponse'
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/configurations/v1/password-history-policy:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: PasswordHistoryPolicyController_createPolicy
      summary: Create Password History Policy
      description: 'Create a password history policy for all accounts (tenants).


        To enable the password history policy, set the `enabled` parameter to `true` and specify the `passwordHistorySize` as a number between 1 and 10.'
      parameters:
      - name: frontegg-tenant-id
        in: header
        description: The account (tenant) ID identifier
        required: false
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PasswordHistoryPolicyRequest'
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordHistoryPolicyResponse'
        '409':
          description: Policy already exists. Use the Update Password History Policy API.
      tags:
      - Password Settings
      security:
      - bearer: []
    patch:
      operationId: PasswordHistoryPolicyController_updatePolicy
      summary: Update Password History Policy
      description: 'Update the password history policy for all accounts (tenants).


        To disable the password history policy, set the `enabled` parameter to `false`. You can also update the `passwordHistorySize` value to a number between 1 and 10.'
      parameters:
      - name: frontegg-tenant-id
        in: header
        description: The account (tenant) ID identifier
        required: false
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PasswordHistoryPolicyRequest'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordHistoryPolicyResponse'
        '404':
          description: History size must to be between 1 to 10
      tags:
      - Password Settings
      security:
      - bearer: []
    get:
      operationId: PasswordHistoryPolicyController_getPolicy
      summary: Get Password History Policy
      description: Retrieve the password history policy for all accounts (tenants) or for a specific account (tenant).
      parameters:
      - name: frontegg-tenant-id
        in: header
        description: The account (tenant) ID identifier
        required: false
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordHistoryPolicyResponse'
        '404':
          description: Password History Policy not found. Policy is disabled
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v1/passwords/reset:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: UsersPasswordControllerV1_resetPassword
      summary: Reset Password
      description: 'Send a reset password email to a user.


        Provide the user''s email in the request body. If your email template uses metadata, include the email metadata in the request body as well.'
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResetPasswordDto'
      responses:
        '201':
          description: ''
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v1/passwords/reset/verify:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: UsersPasswordControllerV1_verifyResetPassword
      summary: Verify Password
      description: 'Verify a user''s password using a verification token.


        Provide the `userId`, `token`, and `password` in the request body. The `token` can be obtained using the route for generating a user password reset token.'
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/VerifyPasswordDto'
      responses:
        '201':
          description: ''
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v1/passwords/change:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: UsersPasswordControllerV1_changePassword
      summary: Change Password
      description: 'Change the password for a logged-in user.


        Include the current and new passwords in the request body.'
      parameters:
      - name: frontegg-user-id
        in: header
        description: The user ID identifier
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateUserPasswordDto'
      responses:
        '201':
          description: ''
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v1/passwords/config:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    get:
      operationId: UsersPasswordControllerV1_getUserPasswordConfig
      summary: Get Strictest Password Configuration
      description: 'Retrieve the user''s strictest password configuration.


        This is useful when a user belongs to multiple accounts (tenants) with varying password complexity requirements. The route returns the strictest setting the user is subject to.'
      parameters:
      - name: userId
        required: false
        in: query
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordConfigResponse'
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v2/passwords/reset/email:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: UsersPasswordControllerV2_resetPasswordViaEmail
      summary: Reset Password via Email
      description: Sends a password reset email to the user. Provide the user's email address in the request body to initiate the reset process.
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResetPasswordDto'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResetPasswordViaSmsResponseDto'
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v2/passwords/reset/sms:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: UsersPasswordControllerV2_resetPasswordViaSms
      summary: Reset Password via SMS
      description: Sends a password reset SMS with a one-time code (OTP) to the user. Provide the user's phone number in the request body to initiate the reset process.
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ResetPasswordDto'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResetPasswordViaSmsResponseDto'
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/users/v2/passwords/reset/sms/verify:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    post:
      operationId: UsersPasswordControllerV2_verifyResetPasswordViaSmsOtc
      summary: Verify Password Reset Code Sent via SMS
      description: Verifies the one-time code (OTP) sent via SMS for password reset. Provide the OTP in the request body. If valid, returns the user ID and reset token.
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/VerifyPasswordViaSmsRequestDto'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VerifyPasswordViaSmsResponseDto'
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/configurations/v1/password-rotation:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    get:
      operationId: PasswordRotationConfigControllerV1_getPasswordRotationConfiguration
      summary: Get Password Expiration Period Configuration
      description: Retrieve the password expiration period configuration for your environment or for a specific account (tenant).
      parameters: []
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordRotationConfigurationResponse'
        '404':
          description: Password rotation configuration not found
      tags:
      - Password Settings
      security:
      - bearer: []
    post:
      operationId: PasswordRotationConfigControllerV1_upsertPasswordRotationConfiguration
      summary: Manage Password Expiration
      description: 'Create or update the configuration for the password expiration policy.


        If no configuration exists, a default policy will be applied.'
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateOrUpdatePasswordRotationDto'
      responses:
        '200':
          description: ''
      tags:
      - Password Settings
      security:
      - bearer: []
  /resources/configurations/v1/password-rotation/vendor:
    servers:
    - url: https://api.frontegg.com/identity
      description: EU Region
    - url: https://api.us.frontegg.com/identity
      description: US Region
    - url: https://api.ca.frontegg.com/identity
      description: CA Region
    - url: https://api.au.frontegg.com/identity
      description: AU Region
    - url: https://{domain}.frontegg.com/identity
      description: Frontegg sub-domain for use with user tokens
      variables:
        domain:
          default: app-xxx
    get:
      operationId: PasswordRotationConfigControllerV1_getVendorPasswordRotationConfiguration
      summary: Get Environment Configuration for Password Expiration Period
      description: Retrieve the password expiration period configuration for your environment or for a specific account (tenant).
      parameters: []
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PasswordRotationConfigurationResponse'
        '404':
          description: Password rotation configuration not found
      tags:
      - Password Settings
      security:
      - bearer: []
components:
  schemas:
    UpdateUserPasswordDto:
      type: object
      properties:
        password:
          type: string
        newPassword:
          type: string
      required:
      - password
      - newPassword
    PasswordHistoryPolicyRequest:
      type: object
      properties:
        enabled:
          type: boolean
          description: Detemine whether the history policy is enbaled.
          default: false
        historySize:
          type: number
          description: Number of passwords per user to remember in the history.
          maximum: 10
          minimum: 1
          default: 1
      required:
      - enabled
      - historySize
    RequiredTestsConfig:
      type: object
      properties:
        checkThreeRepeatedChars:
          type: boolean
          description: Check if the password contains three repeated characters
    ResetPasswordViaSmsResponseDto:
      type: object
      properties:
        sessionId:
          type: string
      required:
      - sessionId
    VerifyPasswordDto:
      type: object
      properties:
        userId:
          type: string
        token:
          type: string
        password:
          type: string
      required:
      - userId
      - token
      - password
    OptionalTestsConfig:
      type: object
      properties:
        requireLowercase:
          type: boolean
          description: Require at least one lowercase letter
        requireUppercase:
          type: boolean
          description: Require at least one uppercase letter
        requireNumbers:
          type: boolean
          description: Require at least one number
        requireSpecialChars:
          type: boolean
          description: Require at least one special character
    PasswordRotationConfigurationResponse:
      type: object
      properties:
        createdAt:
          format: date-time
          type: string
        updatedAt:
          format: date-time
          type: string
        isActive:
          type: boolean
        rotationPeriod:
          type: number
        notificationPeriod:
          type: number
        tenantId:
          type: string
      required:
      - createdAt
      - updatedAt
      - isActive
      - rotationPeriod
      - notificationPeriod
      - tenantId
    PasswordHistoryPolicyResponse:
      type: object
      properties:
        id:
          type: string
        enabled:
          type: boolean
        historySize:
          type: number
        createdAt:
          format: date-time
          type: string
        updatedAt:
          format: date-time
          type: string
      required:
      - id
      - enabled
      - historySize
      - createdAt
      - updatedAt
    VerifyPasswordViaSmsResponseDto:
      type: object
      properties:
        userId:
          type: string
        token:
          type: string
      required:
      - userId
      - token
    CreateOrUpdatePasswordRotationDto:
      type: object
      properties:
        isActive:
          type: boolean
          description: Indicates whether password expiration is enabled
          default: false
        rotationPeriod:
          type: number
          minimum: 1
          maximum: 2628000
          description: The password expiration period, in minutes
          default: 129600
        notificationPeriod:
          type: number
          minimum: 0
          maximum: 2628000
          description: Notification period before password expiration, in minutes
          default: 10080
    PasswordConfigRequest:
      type: object
      properties:
        allowPassphrases:
          type: boolean
        maxLength:
          type: number
        minLength:
          type: number
        minPhraseLength:
          type: number
        minOptionalTestsToPass:
          type: number
        blockPwnedPasswords:
          type: boolean
        optionalTests:
          $ref: '#/components/schemas/OptionalTestsConfig'
        requiredTests:
          $ref: '#/components/schemas/RequiredTestsConfig'
    VerifyPasswordViaSmsRequestDto:
      type: object
      properties:
        otcToken:
          type: string
        sessionId:
          type: string
      required:
      - otcToken
      - sessionId
    PasswordConfigResponse:
      type: object
      properties:
        allowPassphrases:
          type: boolean
        maxLength:
          type: number
        minLength:
          type: number
        minPhraseLength:
          type: number
        minOptionalTestsToPass:
          type: number
        blockPwnedPasswords:
          type: boolean
        optionalTests:
          type: object
        requiredTests:
          type: object
      required:
      - blockPwnedPasswords
    ResetPasswordDto:
      type: object
      properties:
        identifier:
          type: string
          description: User identifier (phone number or email)
        identifierType:
          enum:
          - email
          - phoneNumber
          - username
          type: string
          description: Type of the identifier
        emailMetadata:
          type: object
      required:
      - identifier
      - identifierType
  securitySchemes:
    bearer:
      scheme: bearer
      bearerFormat: JWT
      type: http
x-tagGroups:
- name: Entitlements Agent (PDP)
  tags:
  - Entitlements Check
- name: Audits Overview
  tags:
  - Main
  - Metrics
- name: Entitlements Overview
  tags:
  - Plans
  - API Access Control
  - API Access Control Configurations
  - Features
  - Entitlements
  - Feature Flags
  - ReBAC
- name: Authentication and Identity Management
  tags:
  - API token
  - API tokens
  - Account invitations
  - Account invitations settings
  - Account roles
  - Approval Flows
  - Core settings
  - Custom social OAuth provider
  - Data migration
  - Delegation
  - Domain restrictions
  - Email configuration
  - Email templates
  - General
  - IP restrictions
  - Lockout policy
  - M2M tokens
  - MFA
  - MFA configuration
  - MFA settings
  - Password settings
  - Passwordless
  - Permissions
  - Permissions categories
  - Personal tokens
  - Roles
  - SMS
  - SMS configuration
  - SMS templates
  - Sessions configuration
  - Sessions management
  - User emails policy
  - User groups
  - User management
  - Users
  - User pools
  - User sessions
  - Users-applications management
- name: SCIM Provisioning Overview
  tags:
  - SCIM settings
  - SCIM configurations
- name: Single Sign-On Overview
  tags:
  - SAML configurations
  - SSO settings
  - SSO configurations
  - OIDC configurations
- name: Account Management Overview
  tags:
  - Accounts
  - tenants_other
  - Sub-accounts
  - Account settings
  - Account migration
  - Sub-accounts and hierarchy