Changelog
Guides

Change a user's email or password

Read account info, change the password, and change the email after the user confirms the new address.

A signed-in user changes their email or password through /identity/manage/info. POST requires a CSRF token in the RequestVerificationToken header and a fresh ReAuth proof. The body is Identity's InfoRequest: { "newEmail"?, "newPassword"?, "oldPassword"? }.

Read the account info

Send GET /identity/manage/info. The response is { "email", "isEmailConfirmed" }. This route needs no CSRF token and no ReAuth.

Change the password

  1. Complete step-up. See Require step-up before sensitive actions.
  2. Send POST /identity/manage/info with { "oldPassword", "newPassword" } and the CSRF header.
  3. Check the response:
    • 200 { "email", "isEmailConfirmed" }: the password changed.
    • 400 validation problem OldPasswordRequired: the request had newPassword but no oldPassword.
    • 400 validation problem PasswordMismatch: oldPassword was wrong. Password-rule failures return their own codes.

A user who forgot the current password uses Reset a forgotten password instead.

Change the email

  1. Complete step-up.
  2. Send POST /identity/manage/info with { "newEmail" } and the CSRF header.
  3. The response is 200 and still shows the old email. AuthEndpoints sends a change-email link to the new address through IEmailSender<TUser>.SendConfirmationLinkAsync.
  4. The user opens the link: GET /identity/confirmEmail?userId=...&code=...&changedEmail=.... The email and the user name change only now.
  5. With EmailConfirmation.ConfirmEmailRedirectUri set, the link redirects with flow=change-email and status=confirmed or status=failed. Without it, the link returns 200 text or 401.

An invalid newEmail returns a 400 validation problem InvalidEmail. You can send newEmail and newPassword in one request. AuthEndpoints changes the password first.

Know the limits

  • POST /identity/manage/info cannot set a first password on an account that has none, such as a passkey-only or OAuth-only account. It returns OldPasswordRequired.
  • No endpoint deletes an account.