# Replace an account's password

URL: https://docs.fxapis.com/api-reference/accounts/replace-an-accounts-password

> Replace an account's password. Gives a connected account a new trading password — after the member changed it at the broker, or when the account is in…

`POST https://api.fxapis.com/v1/accounts/{id}/password`

Gives a connected account a new trading password — after the member changed it at the broker, or when the account is in `invalid_credentials` because the one it had was wrong. Send `server` as well to correct the server name.

The account is taken offline first (refused with `409` while an order is in flight), the new password is encrypted and stored, and only then is the old one erased — a failure leaves the old credential in place. The account lands in `created` and comes online on the next order or when you bring it online; bring it online straight away to check the new password while the member is still there. The password is never returned or logged.

Authentication: `Authorization: Bearer <API key>`.

#### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `id` | path | string (uuid) | yes |  |

#### Request body (application/json, required)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `password` | string | yes | The account's **trading** password, not the investor password. Example: `"the-members-new-trading-password"` |
| `server` | string | no | Optional: a corrected server name, exactly as MetaTrader shows it. Example: `"VantageMarkets-Live"` |

#### Responses

- `200`
- `400`
- `401`
- `404`
- `409`
- `503`

Failures return `{ "error": { "code", "message" } }`; every code is listed at https://docs.fxapis.com/errors.

#### 200 response fields

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `data` | object | no |  |
| `data.id` | string (uuid) | no |  |
| `data.label` | null \| string | no | Yours, for telling accounts apart. |
| `data.login` | string | no | The MT5 account number. |
| `data.server` | string | no | The broker server name, exactly as MetaTrader shows it. |
| `data.mode` | "always_on" \| "warm_on_demand" \| "cold" | no |  |
| `data.state` | "created" \| "provisioning" \| "standby" \| "starting" \| "connecting" \| "synchronizing" \| "ready" \| "executing" \| "cooling" \| "offline" \| "degraded" \| "reconnecting" \| "invalid_credentials" \| "trading_disabled" \| "needs_2fa" \| "needs_certificate" \| "error" | no | Online: `ready` (can trade) and `executing` (an order is in flight). Connecting: `provisioning`, `starting`, `connecting`, `synchronizing`, `reconnecting` — poll until `ready`. Offline: `created`, `standby`, `cooling` (going offline) and `offline` (after a disconnect, send the account's credentials again to reconnect). `degraded`: online but misbehaving — restart the connection. Need a human: `invalid_credentials`, `needs_2fa`, `needs_certificate`, `trading_disabled`. `error`: see `stateDetail`. |
| `data.stateDetail` | null \| string | no | Why it is in that state, when there is more to say. |
| `data.stateChangedAt` | string (date-time) | no |  |
| `data.currency` | null \| string | no |  |
| `data.leverage` | null \| integer | no |  |
| `data.marginMode` | null \| string | no |  |
| `data.tradeAllowed` | null \| boolean | no |  |
| `data.brokerName` | null \| string | no |  |
| `data.tradingDisabled` | boolean | no | Set by us or by the broker. No order is accepted while true. |
| `data.createdAt` | string (date-time) | no |  |