
yc954 (yc954) asked a question.
I am trying to reset a password using the /api/v1/authn/credentials/reset_password API. However, I am receiving an error stating: 'This operation is not allowed in the current authentication state.'
My user's status is PASSWORD_EXPIRED.
In which cases will this API return such a response? Are there specific authentication states where this operation is restricted?

Hi @yc954 (yc954) , Thank you for reaching out to the Okta Community!
You might want to check with our colleagues via devforum.okta.com on this, as far as I can see here, this flow is not supported.
There also an older post mentioning MFA requirement coming into play as well.
If you want to set a specific password for the user, you should be able to use the "Set Password" call. Example:
Regards.
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Level up your Identity security superpowers with Okta Learning.
Join the Online Discussion for Ask me Anything on March 25, 2025: Identity Threat Protection with Okta AI