SpendRock Docs
Auth

Add or change the caller's password (ACCT-2)

Changing an existing password needs `current_password` (401 `bad_credentials`). If the account's email isn't verified yet, a verification link is emailed and the password works once it's verified (`verification_sent`). Needs a signed-in session: personal access tokens get 403 `session_required`.

PUT
/me/password

Changing an existing password needs current_password (401 bad_credentials). If the account's email isn't verified yet, a verification link is emailed and the password works once it's verified (verification_sent).

Needs a signed-in session: personal access tokens get 403 session_required.

Authorization

bearerAuth
AuthorizationBearer <token>

Authorization: Bearer <token>: a mobile session token, or a personal access token (srp_…) created in Account → API tokens (DEV-1).

Personal access tokens:

  • Act as their user. The household comes from X-SpendRock-Household, else the user's default.
  • Carry scopes (DEV-2), and each operation's description names the one it needs: budget:read / budget:write (months, groups, items, funds, favorites, harvest), transactions:read / transactions:write (transactions, merchant suggestions), households:read / households:manage (households, members, invites), account:read / account:write (me, settings). A write scope includes its read scope. A call outside the token's scopes gets 403 insufficient_scope, with the needed scope in details.required_scope.
  • Can't manage tokens or passwords (403 session_required).
  • May expire (401 unauthenticated afterwards).
  • Are rate-limited (DEV-3): 120 requests/minute per token with bursts up to 120. Every response carries X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (seconds until the bucket is full again); over the limit the answer is 429 rate_limited with Retry-After (seconds). Limits are kept per server instance, so they're approximate.

Sessions (web cookie or mobile bearer) have every scope and aren't limited this way. Cross-origin browser calls (CORS, for the API docs playground) must use a bearer token; cookies are never accepted cross-origin.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PUT "https://example.com/me/password" \  -H "Content-Type: application/json" \  -d '{    "password": "stringstri"  }'
{  "verification_sent": true}