Set an initial password

Set a password for the current user when none exists yet (account created via social sign-in). Creates the email/password credential so the user can also sign in with email. Fails with 409 when a password is already set — use the Better Auth change-password flow instead. The user's own credential only (session, CLI or instance token); delegated credentials — API keys, third-party OAuth clients — and end-user tokens are refused.

POST/api/profile/password

Authorization

better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Request Body

application/json

curl -X POST "https://your-instance/api/profile/password" \  -H "Content-Type: application/json" \  -d '{    "newPassword": "stringst"  }'
{
  "status": true
}

{
  "type": "https://docs.appstrate.dev/errors/validation-failed",
  "title": "Validation Failed",
  "status": 400,
  "detail": "name: Invalid input: expected string, received undefined (+2 more)",
  "code": "validation_failed",
  "request_id": "req_abc123",
  "errors": [
    {
      "field": "name",
      "code": "required",
      "message": "Invalid input: expected string, received undefined"
    },
    {
      "field": "email",
      "code": "invalid_format",
      "message": "Invalid email address"
    },
    {
      "field": "age",
      "code": "invalid_type",
      "message": "Invalid input: expected number, received string"
    }
  ]
}

{
  "type": "https://docs.appstrate.dev/errors/unauthorized",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Invalid or missing session",
  "code": "unauthorized",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "Insufficient permissions",
  "code": "forbidden",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/password-already-set",
  "title": "Conflict",
  "status": 409,
  "detail": "A password is already set for this account. Use the change password form instead.",
  "code": "password_already_set",
  "request_id": "req_abc123"
}