Changes the password for the currently authenticated user.
Calls POST /v1/user/auth/password (CognitoAuthorizer Bearer token).
The user's current password.
The new password to set.
A promise that resolves to a ChangePasswordResponse on success.
Confirms a user's sign-up using the verification code sent by Cognito.
Calls POST /v1/user/auth/signup/verify.
The username (typically the user's email or phone).
The verification code received by the user.
The API response.
Initiates the password recovery process for a user.
Calls POST /v1/user/auth/password-recovery.
The username (email or phone number) for password recovery.
The server response with an optional message field — the only
field the backend returns (verified against the backend source).
Returns the SDK config this auth instance was constructed with. Prefer this over ESPRMNeoBase.getConfig in auth method implementations.
Retrieves the currently logged-in user.
Reads tokens from storage. If the access token is expired, refreshes the session using the refresh token, then reloads. Returns null when no tokens are stored.
An ESPRMNeoUser if a session is active, or null when no tokens are stored.
Logs in a user with username and password.
Calls POST /v1/user/auth/token.
The username (email or phone number) for authentication.
The user's password.
A promise that resolves to an ESPRMNeoUser instance on successful login.
Sends a verification code to the user's email during the sign-up process.
Calls POST /v1/user/auth/signup.
The email address of the user signing up
The password for the new account
OptionaluserAttributes: Record<string, string>Optional additional user attributes
A promise that resolves with the API response when the verification code is sent successfully
Sets a new password for a user during password recovery flow.
Calls POST /v1/user/auth/password-recovery/confirmation.
The username (email or phone number) for password recovery.
The new password to set.
The verification code received by the user.
A promise that resolves to a SetNewPasswordResponse on success.
StaticgetGets refreshed tokens using a refresh token without persisting them.
Calls POST /v1/user/auth/token/refresh (unauthenticated; the backend
validates refresh_token in the body only).
The backend rotates the refresh token on every redemption: the presented token is spent and the response carries its replacement. Presenting a spent token again is treated as reuse and kills the login, so the rotated token from the response is returned here (and must be persisted by the caller). Falls back to the presented token only when the backend does not return one.
The
ESPRMNeoAuthclass provides authentication functionality via the RainMaker User Auth API. Key features include: