Skip to main content
PUT
Replace a login's recovery codes
Authentication: Authorization: Bearer <token> with Dashboard session, Pomerado MCP OAuth token, API key. Permission: logins:manage. Effect: Write: creates or changes something in your account. Errors: invalid_request (400), unauthorized (401), reauthentication_required (401), forbidden (403), not_found (404), site_login_exists (409), login_identity_conflict (409), legacy_duplicate_saved_logins (409), saved_login_unsettled (409), login_in_use (409), login_save_in_progress (409), request_too_large (413), invalid_credential (422), internal_error (500), acceptance_unknown (503), temporarily_unavailable (503). Every error has the same envelope.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id
string
required

a saved login ID: login_ and 32 lowercase hex digits

Example:

"login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

Body

application/json
codes
string[]
required

an array of at most 20 item(s)

Required array length: 1 - 20 elements

a string at most 64 character(s) long

Required string length: 4 - 64

Response

The login

id
string
required

a saved login ID: login_ and 32 lowercase hex digits

Example:

"login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190"

label
string | null
required
site
object
required
username_masked
string
required
identifier_type
enum<string>
required
Available options:
username,
email,
phone,
account_number
sign_in
enum<string>
required
Available options:
password,
code
saved_fields
enum<string>[] | null
required

What it holds besides its username and password; null when not recorded

Available options:
email,
phone,
account_number,
date_of_birth,
zip,
recovery_codes,
preferred_method
two_factor
object
required
status
enum<string>
required
Available options:
unverified,
verified,
needs_attention
needs_attention
object | null
required
locked
boolean
required
created_at
string
required

When it was saved, ISO 8601 UTC

updated_at
string
required

When it last changed, ISO 8601 UTC

verified_at
string | null
required

Its first verified sign-in, ISO 8601 UTC; null before one