Verify the current admin password
curl --request POST \
--url https://your-syteca-host/SytecaACB/api/auth/verify \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"password": "<string>"
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/auth/verify"
payload = { "password": "<string>" }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({password: '<string>'})
};
fetch('https://your-syteca-host/SytecaACB/api/auth/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/auth/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'password' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/auth/verify"
payload := strings.NewReader("{\n \"password\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/api/auth/verify")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"password\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/auth/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"password\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"verified": true
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Endpoints
Verify Admin Password
Syteca ACB REST API endpoint to verify the current built-in admin password matches the value the caller expects — used before triggering a rotation to confirm vault/Syteca sync.
POST
/
api
/
auth
/
verify
Verify the current admin password
curl --request POST \
--url https://your-syteca-host/SytecaACB/api/auth/verify \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"password": "<string>"
}
'import requests
url = "https://your-syteca-host/SytecaACB/api/auth/verify"
payload = { "password": "<string>" }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({password: '<string>'})
};
fetch('https://your-syteca-host/SytecaACB/api/auth/verify', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/api/auth/verify",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'password' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/api/auth/verify"
payload := strings.NewReader("{\n \"password\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/api/auth/verify")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"password\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/api/auth/verify")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"password\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"verified": true
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Verifies the current built-in
admin password matches a value the caller provides. The canonical “pre-flight check” for an automated rotation workflow — call this before Change admin password to confirm the value in your secrets vault is still the current one. Catches desync between vault and Syteca before you replace a value that’s already been changed elsewhere.
For ACB deployments updated from a version prior to 1.2, switch to the
https://{hostname}/EkranACB server in the Playground.Permissions required
- The Access Token must be issued to an Internal or Active Directory user (not an Application Account) with the administrative User Management permission.
- The Refresh Token holder should not be the built-in
adminuser itself — see Admin password rotation → Prerequisites.
What the response means
The response has a single booleanverified field:
| Value | Meaning |
|---|---|
true | The provided password matches the current admin password. Safe to proceed with rotation. |
false | The provided password does not match. Don’t rotate — investigate desync first (someone may have rotated the admin password through the Management Tool UI without updating your secrets vault). |
A
false response is an alert condition. Either your vault is out of sync, or the admin password was rotated by someone else. Investigate before calling Change admin password — overwriting an unknown-current value can lock administrative access if your rotation fails partway through.Rate limit
5 requests per minute per Access Token. Intentionally bandwidth-limited to make brute-force attacks impractical.Errors
See Status codes. Common errors:- 401 Unauthorized — invalid or expired Access Token.
- 403 Forbidden — user lacks administrative User Management permission.
- 429 Too Many Requests — rate limit exceeded.
Related
Admin password rotation
Concept page — how verify + change work together.
Change admin password
Step 2 — actually rotate.
API reference
Authentication, status codes.
Administrative permissions
User Management permission details.