Okta Password API

The MyAccount Password API provides operations to enroll, update, and delete passwords. > **Note:** Super admins can enable the IDP MyAccount API password feature. See [Enable self-service features](https://help.okta.com/okta_help.htm?type=oie&id=ext_secur_manage_ea_bata). ### API versioning A valid API version in the `Accept` header is required to access the API. Current version: `1.0.0` ```json Accept: application/json; okta-version=1.0.0 ```

Operations 4

GET /idp/myaccount/password Retrieve a Password #
POST /idp/myaccount/password Create a Password #
PUT /idp/myaccount/password Replace a Password #
DELETE /idp/myaccount/password Delete a Password #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/okta:okta-password-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

okta-password-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: MyAccount Management Password API
  version: 2025.01.1
  description: 'APIs for managing a user''s own emails, phones, profile, and app authenticators.

    > **Note:** The MyAccount API doesn''t support delegated authentication.'
  termsOfService: https://developer.okta.com/terms/
  contact:
    name: Okta Developer Team
    url: https://developer.okta.com/
    email: devex-public@okta.com
  license:
    name: Apache-2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  x-logo:
    url: logo.svg
    backgroundColor: transparent
    altText: Okta Developer
servers:
- url: https://{yourOktaDomain}
  variables:
    yourOktaDomain:
      default: subdomain.okta.com
      description: The domain of your organization. This can be an official Okta domain (for example, `okta.com` or `oktapreview.com`) or one of your configured custom domains.
tags:
- name: Password
  description: 'The MyAccount Password API provides operations to enroll, update, and delete passwords.


    > **Note:** Super admins can enable the IDP MyAccount API password feature. See Enable self-service features.


    ### API versioning

    A valid API version in the `Accept` header is required to access the API. Current version: `1.0.0`

    ```json

    Accept: application/json; okta-version=1.0.0

    ```'
paths:
  /idp/myaccount/password:
    get:
      summary: Retrieve a Password
      description: 'Retrieves the current user''s password status

        > **Note:** This request only returns information about the password, not the password itself.'
      operationId: getPassword
      responses:
        '200':
          $ref: '#/components/responses/Password-Enrolled-Response'
        '401':
          $ref: '#/components/responses/Error-IdpMyAccountNotEnabled-Response-401'
      security:
      - oauth2:
        - okta.myAccount.password.read
      tags:
      - Password
      x-okta-lifecycle:
        lifecycle: GA
        isGenerallyAvailable: true
    post:
      summary: Create a Password
      description: Creates and enrolls a password for the current user
      operationId: createPassword
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                profile:
                  type: object
                  description: Defines the password on the profile
                  required:
                  - password
                  properties:
                    password:
                      type: string
                      example: Abcd12345
                      writeOnly: true
              required:
              - profile
            examples:
              New-Password:
                value:
                  profile:
                    password: Abcd1234
        description: New password
      responses:
        '201':
          $ref: '#/components/responses/Password-Enrolled-Response'
        '400':
          $ref: '#/components/responses/Error-InvalidPassword-Reponse-400'
        '401':
          $ref: '#/components/responses/Error-IdpMyAccountNotEnabled-Response-401'
        '403':
          $ref: '#/components/responses/Error-PasswordConflict-Response-409'
      security:
      - oauth2:
        - okta.myAccount.password.manage
      tags:
      - Password
      x-okta-lifecycle:
        lifecycle: GA
        isGenerallyAvailable: true
    put:
      summary: Replace a Password
      description: Replaces the password for the current user
      operationId: replacePassword
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                profile:
                  type: object
                  description: Defines the password on the profile
                  required:
                  - password
                  properties:
                    password:
                      type: string
                      example: Abcd12345
                      writeOnly: true
              required:
              - profile
            examples:
              New-Password:
                value:
                  profile:
                    password: Abcd1234
        description: New password
      responses:
        '201':
          $ref: '#/components/responses/Password-Enrolled-Response'
        '400':
          $ref: '#/components/responses/Error-InvalidPassword-Reponse-400'
        '401':
          $ref: '#/components/responses/Error-IdpMyAccountNotEnabled-Response-401'
        '403':
          $ref: '#/components/responses/Error-Email-Response-403'
      security:
      - oauth2:
        - okta.myAccount.password.manage
      tags:
      - Password
      x-okta-lifecycle:
        lifecycle: GA
        isGenerallyAvailable: true
    delete:
      summary: Delete a Password
      description: Deletes the current user's enrolled password
      operationId: deletePassword
      responses:
        '204':
          description: No Content
          content:
            application/json;okta-version=1.0.0: {}
        '401':
          $ref: '#/components/responses/Error-IdpMyAccountNotEnabled-Response-401'
        '404':
          $ref: '#/components/responses/Error-PasswordResourceNotFound-Response-404'
      security:
      - oauth2:
        - okta.myAccount.password.manage
      tags:
      - Password
      x-okta-lifecycle:
        lifecycle: GA
        isGenerallyAvailable: true
components:
  responses:
    Error-IdpMyAccountNotEnabled-Response-401:
      description: Unauthorized
      content:
        application/json;okta-version=1.0.0:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            IDP-MyAccount-not-enabled-401:
              value:
                errorCode: E0000015
                errorSummary: You do not have permission to access the feature you are requesting
                errorLink: E0000015
                errorId: oaeStOuPPxDRUm3PJhf-tL7bQ
                errorCauses: []
    Error-Email-Response-403:
      description: Forbidden
      content:
        application/json;okta-version=1.0.0:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            Secondary-Email:
              value:
                errorCode: E0000038
                errorSummary: This operation is not allowed in the user's current status.
                errorLink: E0000038
                errorId: oaejUwz8U5FQ_SyggQwz1kC3w
                errorCauses:
                - errorSummary: Secondary email is not enabled as an authenticator for your org.
    Error-PasswordConflict-Response-409:
      description: Conflict
      content:
        application/json;okta-version=1.0.0:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            Password-Conflict-409:
              value:
                errorCode: E0000157
                errorSummary: This account already has a password set as an authenticator.
                errorLink: E0000157
                errorId: oaejUwz8U5FQ_SyggQwz1kC3w
                errorCauses:
                - errorSummary: This account already has a password set as an authenticator.
    Password-Enrolled-Response:
      description: Example response
      content:
        application/json;okta-version=1.0.0:
          schema:
            $ref: '#/components/schemas/PasswordResponse'
          examples:
            Success-Response:
              value:
                id: 00T196qTp3LIMZQ0L0g3
                status: ACTIVE
                created: '2020-01-14T20:05:32.000Z'
                lastUpdated: '2020-01-14T20:05:32.000Z'
                _links:
                  self:
                    href: https://example.okta.com/idp/myaccount/password
                    hints:
                      allow:
                      - GET
                      - DELETE
                      - PUT
    Error-PasswordResourceNotFound-Response-404:
      description: Not Found
      content:
        application/json;okta-version=1.0.0:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            Password-Resource-Not-Found-404:
              value:
                errorCode: E0000007
                errorSummary: 'Not found: Resource not found: 796bc844c1802c5ad5a65e1dbd26c30a (UserProfilePassword)'
                errorLink: E0000007
                errorId: oaejUwz8U5FQ_SyggQwz1kC3w
                errorCauses: []
    Error-InvalidPassword-Reponse-400:
      description: Bad Request
      content:
        application/json;okta-version=1.0.0:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            Invalid-Password-400:
              value:
                errorCode: E0000001
                errorSummary: 'Api validation failed: Password'
                errorLink: E0000001
                errorId: oaejUwz8U5FQ_SyggQwz1kC3w
                errorCauses:
                - errorSummary: Invalid password.
  schemas:
    Error:
      description: Standard API error object
      type: object
      properties:
        errorCauses:
          type: array
          description: (Optional) Further information about what caused this error
          items:
            type: object
            properties:
              errorSummary:
                type: string
                description: A natural language explanation of the error
                example: Bad request because XYZ is missing.
                readOnly: true
        errorCode:
          type: string
          description: A code that is associated with this error type
          example: E0000001
          readOnly: true
        errorId:
          type: string
          description: A unique identifier for this error. This can be used by Okta Support to help with troubleshooting.
          example: oaeWGQKoQHeQmy0u8w8bPwi_Q
          readOnly: true
        errorLink:
          type: string
          description: A link to documentation with a more detailed explanation of the error (not yet implemented and is currently the same value as the 'errorCode')
          example: E0000001
          readOnly: true
        errorSummary:
          type: string
          description: A natural language explanation of the error
          example: Bad request because XYZ is missing.
          readOnly: true
    PasswordResponse:
      description: Password response object
      type: object
      properties:
        created:
          type: string
          description: If password is `ACTIVE`, returns the date when password was first enrolled
        id:
          type: string
          minLength: 1
          readOnly: true
        lastUpdated:
          type: string
          description: If password is `ACTIVE`, returns the date when password was last updated
        status:
          type: string
          description: '`ACTIVE`, `EXPIRED`, `SUSPENDED`, `NOT_ENROLLED`'
        _links:
          type: object
          description: Discoverable resources related to the password
          properties:
            self:
              type: object
              description: Link to the resource (self)
              properties:
                href:
                  type: string
                  description: Link URI
                  minLength: 1
                hints:
                  type: object
                  description: Describes the allowed HTTP verbs for the `href`
                  properties:
                    allow:
                      type: array
                      items:
                        type: string
                        enum:
                        - DELETE
                        - GET
                        - PUT
  securitySchemes:
    oauth2:
      type: oauth2
      description: 'Pass the access_token as the value of the Authorization header: `Authorization: Bearer {access_token}`'
      flows:
        authorizationCode:
          authorizationUrl: /oauth2/v1/authorize
          tokenUrl: /oauth2/v1/token
          scopes:
            okta.myAccount.appAuthenticator.maintenance.manage: Write access to non-sensitive attributes of user app authenticator enrollments
            okta.myAccount.appAuthenticator.maintenance.read: Read access to non-sensitive attributes of user app authenticator enrollments
            okta.myAccount.appAuthenticator.manage: Write access to user app authenticator enrollments
            okta.myAccount.appAuthenticator.read: Read access to user app authenticator enrollments
            okta.myAccount.authenticators.manage: Write access to user authenticator enrollments
            okta.myAccount.authenticators.read: Read access to user authenticator configurations and enrollments
            okta.myAccount.email.manage: Write access to user emails
            okta.myAccount.email.read: Read access to user emails
            okta.myAccount.oktaApplications.read: Read access to the Okta apps list
            okta.myAccount.organization.read: Read access to org details
            okta.myAccount.password.manage: Write access to user password
            okta.myAccount.password.read: Read access to user password metadata
            okta.myAccount.phone.manage: Write access to user phones
            okta.myAccount.phone.read: Read access to user phones
            okta.myAccount.profile.manage: Write access to user profile and schema
            okta.myAccount.profile.read: Read access to user profile and schema
            okta.myAccount.sessions.manage: Write access to user sessions
externalDocs:
  description: Find more info here
  url: https://developer.okta.com