Check a user password
API operation: Open the endpoint in the API Reference
Use POST /users/check_password to check a password for the authenticated user. The documented operation is User.checkPassword.
Send the user's accepted bearer session or API key. Never put a token in the URL.
Authorization: Bearer YOUR_ACCESS_TOKEN
{
"password": "[REDACTED]"
}
The operation returns result: "OK" when the password matches and an error response when it does not. Do not log the submitted password.
For login context, see Authorize user login.