nexalwarenexalwaredocs
API ReferenceAuthentication

Request a one-time code to change your password

POST
/api/v1/auth/password/request-otp

Emails a 6-digit code to the logged-in user, valid briefly. Submit it to /auth/change-password along with the new password. Requires an existing session (log in first) and an Admin or Owner role - a Member/Viewer session gets a 403 here.

Authorization

sessionAuth
AuthorizationBearer <token>

A session token for an existing account, obtained from POST /auth/login (see the Authentication endpoints) - not an API key. Endpoints marked with this scheme reject API key callers outright, regardless of what that key is granted. Outside the Authentication endpoints themselves, everything requiring this scheme manages dashboard resources (schedules, rules, grants, keys, device configuration) and mirrors what a human does in the Nexalware web app - it is not meant to be automated by a third-party integration the way the Device Control endpoints are.

In: header

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/auth/password/request-otp"
{  "ok": true}