post/auth/recover

Recover account with recovery kit

Set a new password using the recovery key from a recovery kit. Only available on instances where people sign in with a username. Ends every session, replaces the recovery kit and returns the new recovery key. Returns an MFA ticket instead of a token when the account has two-factor authentication. Requires a solved captcha challenge (X-Captcha-Token).

recover_account

Request body

application/json

json
{
  "type": "object",
  "properties": {
    "login": {
      "description": "Username of the account to recover",
      "type": "string"
    },
    "recovery_key": {
      "description": "Recovery key from the recovery kit. Spaces and dashes are ignored",
      "type": "string"
    },
    "password": {
      "description": "New password to set",
      "$ref": "#/components/schemas/PasswordType"
    }
  },
  "required": [
    "login",
    "recovery_key",
    "password"
  ]
}

Responses

200

Success

json
{
  "anyOf": [
    {
      "type": "object",
      "properties": {
        "token": {
          "type": "string",
          "description": "Authentication token for API requests"
        },
        "user_id": {
          "description": "ID of the authenticated user",
          "$ref": "#/components/schemas/SnowflakeStringType"
        },
        "user": {
          "description": "Partial user data for the authenticated account",
          "$ref": "#/components/schemas/UserPartialResponse"
        },
        "recovery_key": {
          "type": "string",
          "description": "New recovery key as 8 groups of 4 joined by dashes. It replaces the one just used and is shown only once"
        },
        "recovery_kit_created_at": {
          "type": "string",
          "format": "date-time",
          "pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$",
          "description": "ISO 8601 timestamp when the new recovery kit was created"
        }
      },
      "required": [
        "token",
        "user_id",
        "user",
        "recovery_key",
        "recovery_kit_created_at"
      ],
      "additionalProperties": false
    },
    {
      "type": "object",
      "properties": {
        "mfa": {
          "type": "boolean",
          "const": true,
          "description": "Indicates MFA is required to complete authentication"
        },
        "ticket": {
          "type": "string",
          "description": "MFA ticket to use when completing MFA verification"
        },
        "allowed_methods": {
          "maxItems": 10,
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "List of allowed MFA methods"
        },
        "totp": {
          "type": "boolean",
          "description": "Whether TOTP authenticator MFA is available"
        },
        "webauthn": {
          "type": "boolean",
          "description": "Whether WebAuthn security key MFA is available"
        },
        "backup_codes": {
          "type": "boolean",
          "description": "Whether the account has at least one unconsumed backup code"
        },
        "recovery_key": {
          "type": "string",
          "description": "New recovery key as 8 groups of 4 joined by dashes. It replaces the one just used and is shown only once"
        },
        "recovery_kit_created_at": {
          "type": "string",
          "format": "date-time",
          "pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d:[0-5]\\d(?:\\.\\d+)?(?:Z))$",
          "description": "ISO 8601 timestamp when the new recovery kit was created"
        }
      },
      "required": [
        "mfa",
        "ticket",
        "allowed_methods",
        "totp",
        "webauthn",
        "backup_codes",
        "recovery_key",
        "recovery_kit_created_at"
      ],
      "additionalProperties": false
    }
  ]
}
400

Bad Request - The request was malformed or contained invalid data

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
429

Too Many Requests - You are being rate limited

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    },
    "retry_after": {
      "type": "number",
      "description": "Seconds to wait before retrying"
    },
    "global": {
      "type": "boolean",
      "description": "Whether this is a global rate limit"
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
500

Internal Server Error - An unexpected error occurred

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}