> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vellaro.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Change Password

> Cambio password da loggati, con verifica di quella attuale (BOT-20).

`/users/me/change-password` esiste, ma passa dalla risoluzione del negozio:
il super_admin non ha un tenant e l'hub vive su un host di piattaforma,
quindi da lì non aveva modo di cambiare la password se non col reset via
email. Le rotte /auth/* girano senza tenant, come login e reset, e valgono
per qualunque account.

Gli errori sono 400 e non 401: l'hub tratta ogni 401 come sessione scaduta
e butterebbe fuori chi ha solo sbagliato a digitare la password attuale.

HUBFE-02/M8: il cambio chiude tutte le sessioni dell'account. La risposta
porta i token nuovi di QUESTO dispositivo (vedi
`issue_current_device_tokens`): il client li adotta, altrimenti alla
chiamata successiva prende 401 `auth.session_revoked`.



## OpenAPI

````yaml https://api.vellaro.io/openapi.json post /api/v1/auth/change-password
openapi: 3.1.0
info:
  title: Vellaro API
  description: Vellaro 2026 — E-commerce API
  version: 0.1.0
servers:
  - url: https://api.vellaro.io
    description: Produzione
security: []
tags: []
paths:
  /api/v1/auth/change-password:
    post:
      tags:
        - auth
      summary: Change Password
      description: >-
        Cambio password da loggati, con verifica di quella attuale (BOT-20).


        `/users/me/change-password` esiste, ma passa dalla risoluzione del
        negozio:

        il super_admin non ha un tenant e l'hub vive su un host di piattaforma,

        quindi da lì non aveva modo di cambiare la password se non col reset via

        email. Le rotte /auth/* girano senza tenant, come login e reset, e
        valgono

        per qualunque account.


        Gli errori sono 400 e non 401: l'hub tratta ogni 401 come sessione
        scaduta

        e butterebbe fuori chi ha solo sbagliato a digitare la password attuale.


        HUBFE-02/M8: il cambio chiude tutte le sessioni dell'account. La
        risposta

        porta i token nuovi di QUESTO dispositivo (vedi

        `issue_current_device_tokens`): il client li adotta, altrimenti alla

        chiamata successiva prende 401 `auth.session_revoked`.
      operationId: change_password_api_v1_auth_change_password_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/app__modules__auth__schemas__ChangePasswordRequest
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_TokenResponse_'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - HTTPBearer: []
components:
  schemas:
    app__modules__auth__schemas__ChangePasswordRequest:
      properties:
        current_password:
          type: string
          title: Current Password
        new_password:
          type: string
          title: New Password
      type: object
      required:
        - current_password
        - new_password
      title: ChangePasswordRequest
      description: >-
        Self-service password change while logged in (POST
        /auth/change-password).
    ApiResponse_TokenResponse_:
      properties:
        data:
          anyOf:
            - $ref: '#/components/schemas/TokenResponse'
            - type: 'null'
        meta:
          anyOf:
            - $ref: '#/components/schemas/PaginationMeta'
            - type: 'null'
        error:
          anyOf:
            - type: string
            - type: 'null'
          title: Error
        error_code:
          anyOf:
            - type: string
            - type: 'null'
          title: Error Code
      type: object
      title: ApiResponse[TokenResponse]
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    TokenResponse:
      properties:
        access_token:
          type: string
          title: Access Token
        refresh_token:
          anyOf:
            - type: string
            - type: 'null'
          title: Refresh Token
          description: >-
            Omitted with `X-Refresh-Mode: cookie`: the refresh token is then
            only in the httpOnly `vellaro_refresh` cookie.
        token_type:
          type: string
          title: Token Type
          default: bearer
      type: object
      required:
        - access_token
      title: TokenResponse
    PaginationMeta:
      properties:
        page:
          type: integer
          title: Page
        page_size:
          type: integer
          title: Page Size
        total:
          type: integer
          title: Total
        total_pages:
          type: integer
          title: Total Pages
      type: object
      required:
        - page
        - page_size
        - total
        - total_pages
      title: PaginationMeta
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.