Guides
Change a user's email or password
Read account info, change the password, and change the email after the user confirms the new address.
A signed-in user changes their email or password through /identity/manage/info. POST requires a CSRF token in the RequestVerificationToken header and a fresh ReAuth proof. The body is Identity's InfoRequest: { "newEmail"?, "newPassword"?, "oldPassword"? }.
Read the account info
Send GET /identity/manage/info. The response is { "email", "isEmailConfirmed" }. This route needs no CSRF token and no ReAuth.
Change the password
- Complete step-up. See Require step-up before sensitive actions.
- Send
POST /identity/manage/infowith{ "oldPassword", "newPassword" }and the CSRF header. - Check the response:
200 { "email", "isEmailConfirmed" }: the password changed.400validation problemOldPasswordRequired: the request hadnewPasswordbut nooldPassword.400validation problemPasswordMismatch:oldPasswordwas wrong. Password-rule failures return their own codes.
A user who forgot the current password uses Reset a forgotten password instead.
Change the email
- Complete step-up.
- Send
POST /identity/manage/infowith{ "newEmail" }and the CSRF header. - The response is
200and still shows the old email. AuthEndpoints sends a change-email link to the new address throughIEmailSender<TUser>.SendConfirmationLinkAsync. - The user opens the link:
GET /identity/confirmEmail?userId=...&code=...&changedEmail=.... The email and the user name change only now. - With
EmailConfirmation.ConfirmEmailRedirectUriset, the link redirects withflow=change-emailandstatus=confirmedorstatus=failed. Without it, the link returns200text or401.
An invalid newEmail returns a 400 validation problem InvalidEmail. You can send newEmail and newPassword in one request. AuthEndpoints changes the password first.
Know the limits
POST /identity/manage/infocannot set a first password on an account that has none, such as a passkey-only or OAuth-only account. It returnsOldPasswordRequired.- No endpoint deletes an account.