> ## Documentation Index
> Fetch the complete documentation index at: https://docs.framesports.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Change the current user's password

> Requires the user's current password for verification.



## OpenAPI

````yaml /api-reference/openapi.yaml patch /api/v1/password
openapi: 3.0.3
info:
  title: Framesports API
  version: 1.0.0
  description: >
    The Framesports API exposes read access to the same domain model used by the

    product: **accounts**, **fixtures**, **games**, and **events**.


    This reference documents the v1 surface. It is intentionally small — the API
    is

    used primarily by a small number of integration partners (e.g.
    broadcast-graphics

    tooling). If you need a capability that is not listed here, contact

    `support@framesports.ai` before building around private endpoints.


    ### Base URL


    ```

    https://app.framesports.ai

    ```


    ### Authentication


    All endpoints (except `POST /api/v1/auth` and `POST /api/v1/users`) require
    a

    bearer token in the `Authorization` header:


    ```

    Authorization: Bearer <token>

    ```


    To get a token, sign in to Framesports and open

    [API tokens](https://2.framesports.ai/settings/my/api_tokens).

    Choose **Create token**, give it a name, pick the club it is for and how
    long

    it lasts. The token is shown once, so copy it straight away. The same page

    shows the club's account ID and lists your tokens, and **Delete token**
    stops

    one on its next request.

    A token acts as the person who made it; every request has their access.


    ### Account scoping


    Most endpoints are scoped to a single account (the multi-tenant unit — a
    club or

    governing body). The account is selected in priority order:


    1. The `Account-Id` header on the request (prefix ID, e.g.
    `acct_Ex4mpLeAcc0unt1d567890`).
       The user must have access to that account directly, or through a governance
       relationship to it.
    2. Otherwise, the club the token was made for.

    3. Otherwise, the account stored in the user's session (for
    browser-originated
       calls).
    4. Otherwise, the user's newest / fallback account.


    > **Note on the header name.** The server currently reads `Account-Id`, not

    > `X-Account-Id`. If you send `X-Account-Id`, it is silently ignored and the

    > request falls back to rule 2 or later, which may not be the account you
    intended.


    Responses when the header is present but invalid:


    | Situation | Status |

    | --- | --- |

    | Account does not exist | `404 Not Found` |

    | Account exists but the user cannot access it | `403 Forbidden` |


    ### IDs


    Object IDs in the API are always **prefix IDs** — an opaque string with a

    type-specific prefix:


    | Type | Prefix | Example |

    | --- | --- | --- |

    | Account | `acct_` | `acct_Ex4mpLeAcc0unt1d567890` |

    | Fixture | `fxt_` | `fxt_Ex4mpLeF1xtur31d34567890` |

    | Game | `game_` | `game_Ex4mpLeG4m31d4567890abc` |

    | Event | `evnt_` | `evnt_Ex4mpLe3v3nt1d4567890ab` |

    | Team | `team_` | `team_Ex4mpLeTe4m1d4567890abc` |

    | Player | `pl_` | `pl_Ex4mpLePL4y3r1d4567890abc` |

    | Player game involvement | `pgi_` | `pgi_Ex4mpLePG1nv0Lv3m3nt4aa` |


    Never pass raw integer IDs — the API only accepts prefix IDs for public
    lookups.


    ### Pagination


    List endpoints use [Pagy](https://ddnexus.github.io/pagy/) with
    JSON:API-style

    links. Pass `page` and `per_page` as query parameters (or use the URLs in
    the

    `links` object of the response):


    ```json

    {
      "links": {
        "first": "/api/v1/games/.../events?page[page]=1",
        "last":  "/api/v1/games/.../events?page[page]=9",
        "prev":  null,
        "next":  "/api/v1/games/.../events?page[page]=2"
      },
      "data": [ /* ... */ ]
    }

    ```


    ### Errors


    Errors are returned with an appropriate HTTP status and (usually) a JSON
    body of

    the form `{"error": "..."}`. Unauthenticated responses (`401`) currently
    return

    an empty body with `content-type: text/html` — treat any `401` as "token
    missing

    or invalid" regardless of body.


    ### Versioning & stability


    The `/api/v1/` prefix denotes a stable version of the API. Fields may be
    **added**

    without notice; fields will not be **removed** or change meaning without a
    new

    major version. Any field whose object includes `"deprecated": true` is
    scheduled

    for removal — migrate off it.
  contact:
    name: Framesports support
    email: support@framesports.ai
servers:
  - url: https://app.framesports.ai
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange credentials for an API token, or invalidate the current session.
  - name: Accounts
    description: The accounts the authenticated user can access.
  - name: Me
    description: The authenticated user.
  - name: Fixtures
    description: |
      A fixture is a single rugby match with two sides. Each side carries the
      team that played, the roster that took the field, and the full set of
      team-level stats. This is the endpoint to use for broadcast graphics,
      season roll-ups, or anything else that wants "the match" as a single
      object.
  - name: Games
    description: |
      **Deprecated — prefer `Fixtures`.** A game represents one side of a
      fixture (the billing account's own side). The `/api/v1/games` endpoints
      are kept for backwards compatibility; new integrations should consume
      `/api/v1/fixtures` instead, which returns both sides and all stats in
      one payload.
  - name: Events
    description: |
      Tagged plays within a fixture (tackles, carries, tries, etc.). Prefer
      `GET /api/v1/fixtures/{fixture_id}/events`, which spans both sides of
      the match and resolves each event's team + player into prefix IDs. The
      `/api/v1/games/{game_id}/events` endpoint is kept for backwards
      compatibility — it returns only one side and leaves you to map
      `"Home"` / `"Opp"` + jersey numbers yourself.
paths:
  /api/v1/password:
    patch:
      tags:
        - Authentication
      summary: Change the current user's password
      description: Requires the user's current password for verification.
      operationId: updatePassword
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - user
              properties:
                user:
                  type: object
                  required:
                    - current_password
                    - password
                    - password_confirmation
                  properties:
                    current_password:
                      type: string
                      format: password
                    password:
                      type: string
                      format: password
                    password_confirmation:
                      type: string
                      format: password
      responses:
        '200':
          description: Password changed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
        '401':
          $ref: '#/components/responses/Unauthorized'
        '422':
          description: >-
            Validation failed (e.g. current password wrong, new password too
            short).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  responses:
    Unauthorized:
      description: Token missing or invalid.
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque
      description: |
        Create a token on **Settings → API tokens** in Framesports. It is shown
        once, when you create it.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.