Skip to main content

Change Password

When to Use​

When you need to replace the current OpenAPI login password, call the Reset Password API. This is a synchronous API: no prior login is required, and no token header is needed.

Each call must submit the currently effective password; once the change succeeds, you can call the same API again whenever needed.

Workflow​

  1. Prepare the account name, the current password, and a new password that meets the policy.
  2. Call the Reset Password API; the password is updated immediately on success.
  3. Tokens issued with the old password become invalid, and MQTT clients are disconnected as well; re-establish connections with the new password.

Request Example​

curl -L -X POST 'https://lb.solinteg-cloud.com/openapi/v2/loginv2/resetPassword' \
-H 'Content-Type: application/json' \
--data-raw '{
"authAccount": "YOUR_ACCOUNT",
"currentPassword": "CURRENT_PASSWORD",
"newPassword": "NEW_PASSWORD"
}'
tip

New password policy

  • Length must be 6 to 18 characters.
  • Must contain at least three of the four character classes: uppercase letters, lowercase letters, digits, and special characters.
  • Only these special characters are allowed: ~!@#$%^&*?+=,-.; spaces, Chinese characters, and other special characters are not allowed.
  • Must not be identical to the current password.

Response Handling​

On success, the API returns:

{
"errorCode": 0,
"info": null,
"body": null,
"successful": true
}

On failure, the API returns the corresponding error code and description, for example:

Incorrect account or current password​

{
"errorCode": 1,
"info": {
"code": "error.45001",
"description": "Account or current password is invalid"
},
"body": null,
"successful": false
}

Both a non-existent account and a wrong current password return error.45001; the specific reason is not distinguished.

New password violates the policy​

{
"errorCode": 1,
"info": {
"code": "error.45002",
"description": "New password does not meet the password policy"
},
"body": null,
"successful": false
}

Too many attempts​

{
"errorCode": 1,
"info": {
"code": "error.45005",
"description": "Too many password reset attempts. Please try again after 24 hours."
},
"body": null,
"successful": false
}

Each account can submit at most 10 password-change requests within 24 hours, counting both successes and failures. The 11th and subsequent requests return error.45005.

Security Recommendations​

  • Only call the API over HTTPS; avoid exposing account credentials in browsers, app frontends, or logs.