Migration Guide: Password confirmation for VoucherOwner email and password changes
Go-live date: 1 November 2026
From 1 November 2026, requests that changeemailor set a newpasswordwithout a validcurrent_passwordare rejected.
Because of security concerns, a VoucherOwner who changes their own email address or password must confirm their identity with their current password. The change affects the Update VoucherOwner endpoint.
TIP
The parameter is accepted already, so you can start sending it now.
Yes, if the request changes email or sets a new password. Otherwise optional.
email counts as changed when the submitted address differs from the VoucherOwner's current address. Sending the unchanged address does not require current_password.
Ifcurrent_passwordis missing or incorrect, the API responds with HTTP 422 and aninvaliderror on thecurrent_passwordattribute. No changes are saved.
Missing:
{"errors":[{"code":"invalid","detail":"Current password is required to update email or password","source":{"attributes":["current_password"],"pointer":"/current_password"}}]}
Incorrect:
{"errors":[{"code":"invalid","detail":"Current password is incorrect","source":{"attributes":["current_password"],"pointer":"/current_password"}}]}