Skip to content
API documentation
View as MarkdownOpen in Claude

Students

Set the sign-in password of one of your students

PUT
/v1/student/{studentId}/password

Replaces the password one of your students signs in with, whichever organization they sign in to. A password you choose lets whoever holds it sign in as the student, like a link from createSigninLink, but it never expires. So it needs the permission a sign-in link needs: auth/signin on mto or on *. A student/* role does not grant it.

Checked in this order, before anything is written:

  1. 400 for a password shorter than 5 characters or longer than 72 bytes. These are rules of the body, so they are checked before the student is looked up.
  2. 404 for a student another account registered, answered exactly like one that does not exist.
  3. 409 once the student has confirmed their email address. The account is theirs from then on, and a password set over theirs would lock them out. Send them a sign-in link with createSigninLink instead.
  4. 400 for a password that contains the student’s first name, surname, username or email address (or the part of it before @), whatever the case. Parts shorter than 4 characters are not checked.

The password is stored hashed and never returned by any operation, and hashing is deliberately slow, so allow a second or more. Setting it again replaces it. The answer is the student, with references as ids.

Parameters

Path parameters

NameTypeDescription
studentIdrequiredstring

The student’s _id, as registerStudent returned it: 24 hexadecimal digits. A student another account registered answers exactly like one that does not exist.

Request body

application/jsonrequired

  • passwordstringrequired

    The student’s new sign-in password. At least 5 characters and at most 72 bytes, and not containing the student’s own first name, surname, username or email address, whatever the case. Stored hashed, and never returned by any operation.

    min length5examplecorrect horse battery staple

Responses

200 OK

Success: message is "Password set.".

Body

  • successbooleanrequired

    Always true on a success.

    one oftrue

  • messagestringrequired

    examplePassword set.

  • dataobject · StudentRecordResponserequired

    One of your students as stored, with country, city, school, grade, supervisor and partner as ids. What registration, the updates and setStudentPassword answer with; read the student to have them resolved.

    20 fields of data
    • _idstringrequired

      The student’s id: what every studentId path parameter and body field takes.

      example6650a1b2c3d4e5f6a7b8c9d0

    • mainIdstring

      Only on an organization’s own copy of a student, which linkStudentSupervisor answers with: there it is the student’s id, and _id is the organization’s own. Absent on every other operation.

      example6650a1b2c3d4e5f6a7b8c9d0

    • usernamestringrequired

      Issued at registration, never chosen by you: the country’s two-letter code, a letter, then a number. It is how the student signs in and how support refers to the account.

      exampleXXB1045

    • firstNamestringrequired

      The student’s first name.

      exampleJane

    • lastNamestringrequired

      The student’s surname.

      exampleDoe

    • fullNamestringrequired

      firstName and lastName joined by a space, kept in step when either changes.

      exampleJane Doe

    • emailstringrequired

      The student’s email address, in lower case.

      examplejane.doe@example.com

    • emailConfirmedbooleanrequired

      Whether the student has confirmed email. It starts false, only the student can make it true, and changing email sets it back to false. Once it is true, setStudentPassword is refused: the account is the student’s.

      examplefalse

    • phonestring

      A phone number, as you sent it.

      example+1 555 0100

    • birthstring

      Date of birth, DD/MM/YYYY.

      example14/05/2008

    • sexstring

      m, f or n.

      one ofmfn

      examplef

    • countrystring

      The id of the student’s country.

      example6650a1b2c3d4e5f6a7b8c9d1

    • citystring

      The id of the student’s city. A city you sent by name is stored as the id it resolved to.

      example6650a1b2c3d4e5f6a7b8c9d2

    • schoolstring

      The id of the student’s school. A school you sent by name is stored as the id it resolved to.

      example6650a1b2c3d4e5f6a7b8c9d3

    • gradestring

      The id of the student’s grade. A grade you sent by name is stored as the id it resolved to.

      example6650a1b2c3d4e5f6a7b8c9d4

    • supervisorstring

      The id of the student’s supervisor, when one is attached.

      example6650a1b2c3d4e5f6a7b8c9d5

    • partnerstring

      The id of the student’s partner, when one is attached.

      example6650a1b2c3d4e5f6a7b8c9d6

    • activatedPlatformsThisSeasonarray of stringrequired

      The organizations the student is active on this season, by slug; common means every organization. Registration sets common unless you send a list. The organization-scoped student operations see a student only when this lists that organization or common, and updating a student through one adds that organization.

      example["common"]

    • createdAtstringrequired

      When the student was registered.

      formatdate-timeexample2026-09-01T09:30:00.000Z

    • updatedAtstringrequired

      When the record last changed.

      formatdate-timeexample2026-09-02T14:05:00.000Z

Headers

X-RateLimit-Limit integer

Requests your account may make to this operation per window (100).

X-RateLimit-Remaining integer

Requests left in the current window.

X-RateLimit-Reset integer

Seconds until the current window ends.

Example

{
  "success": true,
  "message": "Password set.",
  "data": {
    "_id": "6650a1b2c3d4e5f6a7b8c9d0",
    "mainId": "6650a1b2c3d4e5f6a7b8c9d0",
    "username": "XXB1045",
    "firstName": "Jane",
    "lastName": "Doe",
    "fullName": "Jane Doe",
    "email": "jane.doe@example.com",
    "emailConfirmed": false,
    "phone": "+1 555 0100",
    "birth": "14/05/2008",
    "sex": "f",
    "country": "6650a1b2c3d4e5f6a7b8c9d1",
    "city": "6650a1b2c3d4e5f6a7b8c9d2",
    "school": "6650a1b2c3d4e5f6a7b8c9d3",
    "grade": "6650a1b2c3d4e5f6a7b8c9d4",
    "supervisor": "6650a1b2c3d4e5f6a7b8c9d5",
    "partner": "6650a1b2c3d4e5f6a7b8c9d6",
    "activatedPlatformsThisSeason": [
      "common"
    ],
    "createdAt": "2026-09-01T09:30:00.000Z",
    "updatedAt": "2026-09-02T14:05:00.000Z"
  }
}

Example request

# $TOKEN: a short-lived token you minted with your API key and secret
curl -sS -X PUT 'https://api.main-team.org/v1/student/<studentId>/password' \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  --data-binary @- <<'JSON'
{
  "password": "correct horse battery staple"
}
JSON

Search the API documentation

Guides, endpoints by name, path or permission, and error codes such as not_found.