Auth
auth.changePassword
Tenant-scoped tRPC mutation auth.changePassword. Requires a verified session cookie or an OAuth Bearer token; OAuth callers additionally need the simrs:write scope. Mutations are RBAC-gated server-side (requireRoles) — a broad scope never widens the user's roles.
AuthorizationBearer <token>
OAuth 2.0 / OIDC issued by the API itself (better-auth oidcProvider). Dynamic client registration per RFC 7591 at /api/auth/oauth2/register.
In: header
Scope: simrs:write
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
email*string
Match
^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$Format
emailcurrentPassword*string
Length
1 <= lengthnewPassword*string
Length
8 <= lengthResponse Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/trpc/auth.changePassword" \ -H "Content-Type: application/json" \ -d '{ "email": "user@example.com", "currentPassword": "string", "newPassword": "stringst" }'{ "result": { "data": null }}{ "error": { "message": "string", "code": 0, "data": { "code": "string", "httpStatus": 0, "path": "string" } }}{ "error": { "message": "string", "code": 0, "data": { "code": "string", "httpStatus": 0, "path": "string" } }}{ "error": { "message": "string", "code": 0, "data": { "code": "string", "httpStatus": 0, "path": "string" } }}{ "error": { "message": "string", "code": 0, "data": { "code": "string", "httpStatus": 0, "path": "string" } }}Is this page helpful?