Skip to content

Create an App Password

POST
/api/v1/auth/app-passwords
curl --request POST \
--url https://example.com/api/v1/auth/app-passwords \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "expires_at": 1, "home_prefix": "example", "name": "example", "plugin_scope": { "access": [ "read" ], "plugin": "example", "resource_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0" }, "scopes": [ { "access": "read", "protocol": "caldav" } ] }'

Create an App Password with protocol scopes, an optional Home folder or resource limit, and an expiry. It needs an account session and a fresh assertion. The response shows the password only once. Route: /api/v1/auth/app-passwords. Inputs: . A recent account assertion is required. Do not automatically replay this operation after an uncertain result.

Media typeapplication/json
object
expires_at
integer | null format: int64
home_prefix
string | null
name
required
string
plugin_scope
One of:

Optional authority for one Plugin, with an optional stable resource ID.

object
access
required
Array<string>
Allowed values: read write
plugin
required
string
resource_id
string | null format: uuid
scopes
Array<object>
object
access
required
string
Allowed values: read write upload_only full
protocol
required
string
Allowed values: caldav notes mail webdav api mcp
Media typeapplication/json
object
created_at
required
integer format: int64
expires_at
integer | null format: int64
home_prefix
string | null
id
required
string format: uuid
name
required
string
password
required
string
plugin_scope
One of:

Optional authority for one Plugin, with an optional stable resource ID.

object
access
required
Array<string>
Allowed values: read write
plugin
required
string
resource_id
string | null format: uuid
scopes
required
Array<object>
object
access
required
string
Allowed values: read write upload_only full
protocol
required
string
Allowed values: caldav notes mail webdav api mcp
username
required

Immutable Basic username, so renaming the user does not break DAV.

string
Example
{
"plugin_scope": {
"access": [
"read"
]
},
"scopes": [
{
"access": "read",
"protocol": "caldav"
}
]
}
Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}
Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}
Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}
Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}