Authenticate with a password
POST/nevisidm/api/auth/v1/:clientExtId/users/:userExtId/password/login
Since: 2.88.0
Required permission(s): AccessControl.CredentialView
Verifies the provided password against the user's password credential.
The credential must be in an active state and within its validity period. A 200 response does not mean authentication succeeded, check the statusCode in the response body. Login failures (wrong password) are returned as statusCode 2 or higher within the 200 response body, not as HTTP errors. Pre-condition failures (credential not found, not active, expired) result in 4xx HTTP errors.
On repeated failures, the credential may transition to a locked state based on the configured password policy, which is reflected in the statusCode of subsequent responses.
Request
Responses
- 200
- 403
- 404
- 422
- 423
Authentication attempt processed. Check the statusCode in the response body for the actual result.
Operation restricted
Referenced resource not found
Invalid request parameters
Credential not active