Change the built-in admin user's password
curl --request PUT \
--url https://your-syteca-host/SytecaACB/api/users/admin/password \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"newPassword": "<string>",
"currentPassword": "<string>"
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/users/admin/password"
payload = {
"newPassword": "<string>",
"currentPassword": "<string>"
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({newPassword: '<string>', currentPassword: '<string>'})
};
fetch('https://your-syteca-host/SytecaACB/api/users/admin/password', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/users/admin/password",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'newPassword' => '<string>',
'currentPassword' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/users/admin/password"
payload := strings.NewReader("{\n \"newPassword\": \"<string>\",\n \"currentPassword\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://your-syteca-host/SytecaACB/api/users/admin/password")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"newPassword\": \"<string>\",\n \"currentPassword\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/users/admin/password")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"newPassword\": \"<string>\",\n \"currentPassword\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Users
Change Admin Password
Syteca ACB REST API endpoint to rotate the built-in admin user’s password — for automated rotation from external secrets vaults, CMDB, or compliance workflows.
PUT
/
api
/
users
/
admin
/
password
Change the built-in admin user's password
curl --request PUT \
--url https://your-syteca-host/SytecaACB/api/users/admin/password \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"newPassword": "<string>",
"currentPassword": "<string>"
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/users/admin/password"
payload = {
"newPassword": "<string>",
"currentPassword": "<string>"
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({newPassword: '<string>', currentPassword: '<string>'})
};
fetch('https://your-syteca-host/SytecaACB/api/users/admin/password', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/users/admin/password",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'newPassword' => '<string>',
'currentPassword' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/users/admin/password"
payload := strings.NewReader("{\n \"newPassword\": \"<string>\",\n \"currentPassword\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://your-syteca-host/SytecaACB/api/users/admin/password")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"newPassword\": \"<string>\",\n \"currentPassword\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/users/admin/password")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"newPassword\": \"<string>\",\n \"currentPassword\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Rotates the built-in
admin user’s password. The new password takes effect immediately — subsequent admin logins must use the new value. Call Verify admin password first to confirm the stored value in your vault is the current one before triggering this change.
For ACB deployments updated from a version prior to 1.2, switch to the
https://{hostname}/EkranACB server in the Playground.Permissions required
- The Access Token must be issued to an Internal or Active Directory user (not an Application Account) with the administrative User Management permission.
- The Refresh Token holder should not be the built-in
adminuser itself.
Password policy
The new password must meet the Syteca password policy — failing the policy returns 400 Bad Request with the specific violation in the response body. Typical requirements include minimum length, character classes, and disallowing recently-used passwords.No rollback. Once this call returns 204, the previous password is gone — Syteca doesn’t keep the prior value. If the new password isn’t successfully written back to your secrets vault before the call completes, you can lose admin access until you can recover via the Application Server’s local fallback mechanism.Always:
- Generate the new password.
- Write it to your secrets vault first.
- Then call this endpoint.
Rate limit
5 requests per minute per Access Token.Errors
See Status codes. Common errors:- 400 Bad Request — new password does not meet the Syteca password policy.
- 401 Unauthorized — invalid or expired Access Token.
- 403 Forbidden — user lacks administrative User Management permission.
Related
Admin password rotation
Concept page — how verify + change work together.
Verify admin password
Step 1 — confirm sync before rotating.
API reference
Authentication, status codes.
Password policy
The policy your new password must meet.
Authorizations
Access token for authentication
Body
application/json
Response
Password changed successfully