Update authentication settings
/settings/authenticationUpdates the authentication settings. Only the fields included in the request are changed: setting a field to null clears its configured value and restores the default, and omitted fields are left unchanged. Images are referenced by the ID of a file that belongs to the account.
Secrets such as recaptcha.secret and google_login.client_secret are write-only. Changes take effect at the next login; active sessions are not terminated.
To avoid overwriting a newer version, send the ETag returned by the retrieve operation in the If-Match header. The header is optional; when it is omitted, the update is applied to the current revision.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Header Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/settings/authentication" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "access_screens": { "accent_color": "string", "background": { "image": { "file_id": "string", "url": "string" }, "position": "string", "size": "string" }, "form_position": "string", "logo": { "file_id": "string", "url": "string" }, "logo_align": "string", "model": "classico", "phrase": "string", "theme": "string" }, "admin_two_factor_available": true, "defaults": {}, "effects": { "sessions": "next_login" }, "google_login": { "client_id": "string", "configured": true, "enabled": true }, "max_devices": 1, "object": "settings", "password": { "configured": true, "field": "email", "rules": { "digits": 0, "letters": 0, "lowercase": 0, "min_length": 0, "special_chars": 0, "uppercase": 0 }, "strong": true }, "propagation": {}, "recaptcha": { "configured": true, "enabled": true, "site_key": "string" }, "replica": {}, "revision": "string" }}Retrieve authentication settings GET
Returns the authentication settings of the account: password rules, reCAPTCHA, two-factor authentication for administrators, Google sign-in, the device limit, and the layout of the access screens. Secrets are never returned; the `configured` fields indicate whether they have been set. The response includes an `ETag` representing the current revision. Send this value in the `If-Match` header when updating these settings to avoid overwriting a newer version.
Retrieve registration settings GET
Returns the registration settings of the account: public sign-up, domain restrictions, whether a document is required, and the highlight applied to users with free access. The response includes an `ETag` representing the current revision. Send this value in the `If-Match` header when updating these settings to avoid overwriting a newer version.