Change passwords APIedit

Changes the passwords of users in the native realm.


POST _xpack/security/user/_password

POST _xpack/security/user/<username>/_password


You can use the create user API to update everything but a user’s username and password. This API changes a user’s password.

For more information about the native realm, see Realms and Configuring a native realm.

Path Parametersedit

(string) The user whose password you want to change. If you do not specify this parameter, the password is changed for the current user.

Request Bodyedit

password (required)
(string) The new password value.


Every user can change their own password. Users with the manage_security privilege can change passwords of other users.


The following example updates the password for the jacknich user:

POST /_xpack/security/user/jacknich/_password
  "password" : "s3cr3t"

A successful call returns an empty JSON structure.