Skip to main content

Read the password policy

GET 

/auth/password-policy

No token. One of the calls you make before you have one. Send X-Tenant-Code where the operation lists it — that is which tenant you are asking about, not proof of who you are.

The rules a password must satisfy, so you can validate before submitting and word the hint yourself.

Read it once at startup and cache it. These are the same rules the server enforces on every password it accepts, so client-side validation here will never disagree with the server's answer. Unauthenticated — the policy is not a secret.

Responses

OK