> ## Documentation Index
> Fetch the complete documentation index at: https://developers.kardinal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Request a password token



## OpenAPI

````yaml /openapi.yaml post /auth/password/requestToken
openapi: 3.0.3
info:
  title: Kardinal ARO API
  version: 2.55.0
  description: This document specifies the REST API of Kardinal ARO v2.
  contact:
    url: https://kardinal.ai/
    email: contact@kardinal.ai
servers:
  - url: /api/v2
security:
  - access_token: []
tags:
  - name: Authenticate
    description: How to authenticate, and manage the access and refresh tokens.
  - name: Plan
    description: How to create, retrieve, update and delete plans.
  - name: Resource
    description: How to create, retrieve, update and delete resources in a plan.
  - name: Order
    description: How to create, retrieve, update and delete orders in a plan.
  - name: SimplePlan
    description: How to create a plan through the use of a simple plan.
paths:
  /auth/password/requestToken:
    post:
      tags:
        - Authenticate
      summary: Request a password token
      operationId: postRequestPasswordToken
      parameters:
        - $ref: '#/components/parameters/originHeader'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UsernameRequest'
      responses:
        '204':
          description: >
            The request has been taken into account.

            If the provided username is a valid email address which corresponds
            to an active user, a password token will be generated and sent by
            mail.

            If no active user is found, the error is silently discarded and a
            204 code is returned anyway.
        '400':
          $ref: '#/components/responses/BadRequest'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security: []
components:
  parameters:
    originHeader:
      name: originHeader
      description: |
        The origin of the request.
        When an email needs to be sent, the "Origin" header value is used (after
        validation) to correctly generate the hyperlinks inside the email body.
      in: header
      schema:
        type: string
        format: uri
  schemas:
    UsernameRequest:
      type: object
      description: An object containing a username.
      properties:
        username:
          $ref: '#/components/schemas/Username'
    Username:
      type: string
      description: >-
        The username is used for login, it is unique for each user, it can be
        either an email (for clients) or a regular username (for Kardinal's
        internal users).
      example: martin.dupont@kardinal.ai
      oneOf:
        - $ref: '#/components/schemas/RegexNotEmpty'
        - $ref: '#/components/schemas/Email'
    EnvelopedErrors:
      type: object
      properties:
        errors:
          type: array
          items:
            $ref: '#/components/schemas/Error'
      description: '[TO_VALIDATE] Description pending review by a Kardinal engineer.'
    RegexNotEmpty:
      type: string
      description: Not empty string.
      pattern: .+
    Email:
      type: string
      description: A valid email address.
      format: email
      example: martin.dupont@kardinal.ai
    Error:
      type: object
      readOnly: true
      properties:
        code:
          type: string
          description: '[TO_VALIDATE] Description pending review by a Kardinal engineer.'
        message:
          type: string
          description: '[TO_VALIDATE] Description pending review by a Kardinal engineer.'
        properties:
          $ref: '#/components/schemas/ErrorProperties'
      required:
        - message
        - code
      description: '[TO_VALIDATE] Description pending review by a Kardinal engineer.'
    ErrorProperties:
      type: object
      additionalProperties:
        type: string
      description: '[TO_VALIDATE] Description pending review by a Kardinal engineer.'
  responses:
    BadRequest:
      description: >-
        The server could not understand the request due to invalid content (bad
        syntax, bad format, bad values, etc).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/EnvelopedErrors'
    InternalServerError:
      description: An internal server error has occurred.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/EnvelopedErrors'
  securitySchemes:
    access_token:
      type: http
      scheme: bearer
      bearerFormat: JWT

````