HyperSaaS
BackendAuthentication

User Endpoints (Djoser)

Registration, activation, password management via djoser REST endpoints.

All djoser endpoints are mounted under /auth/. The configuration is in config/settings/base.py under DJOSER.

Registration

Create User

POST /auth/users/
{
  "email": "user@example.com",
  "password": "secure-password-123",
  "re_password": "secure-password-123"
}

Returns 201 Created and sends an activation email (SEND_ACTIVATION_EMAIL). The account can't sign in until it's activated.

Activate Account

POST /auth/users/activation/
{
  "uid": "MQ",
  "token": "c3g3vj-abc123..."
}

The uid and token come from the activation email's link, which opens the frontend at user-activation/{uid}/{token}.

Resend Activation Email

POST /auth/users/resend_activation/
{
  "email": "user@example.com"
}

Current User

Get Profile

GET /auth/users/me/

Returns the signed-in user's id, name and email, and their workspaces: each with its id, name, slug, status, the user's role, created_at and updated_at.

Update Profile

PUT /auth/users/me/
PATCH /auth/users/me/

Changes name. The email is read-only here; see Email Management.

Delete Account

DELETE /auth/users/me/
{
  "current_password": "your-password"
}

Deleting an account deletes the workspaces it owns, so it's refused (400, with the reasons) until:

  • the account's subscriptions are cancelled, and
  • every workspace it owns that has other members is transferred to someone else, or has no other members left.

Password Management

Change Password

POST /auth/users/set_password/
{
  "new_password": "new-secure-password",
  "re_new_password": "new-secure-password",
  "current_password": "old-password"
}

Request Password Reset

POST /auth/users/reset_password/
{
  "email": "user@example.com"
}

Sends a password reset email whose link opens the frontend at confirm-password-reset/{uid}/{token}. The response is the same whether or not the address has an account.

Confirm Password Reset

POST /auth/users/reset_password_confirm/
{
  "uid": "MQ",
  "token": "c3g3vj-abc123...",
  "new_password": "new-secure-password",
  "re_new_password": "new-secure-password"
}

Email Management

Changing an account's email takes three steps, so the change only happens once both addresses are proven.

1. Request a Change

POST /auth/users/reset_email/
{
  "email": "current@example.com"
}

Emails the current address a link to confirm-username-reset/{uid}/{token}.

2. Choose the New Address

POST /auth/users/reset_email_confirm/
{
  "uid": "MQ",
  "token": "c3g3vj-abc123...",
  "new_email": "new@example.com",
  "re_new_email": "new@example.com"
}

Nothing changes yet. A confirmation link is sent to the new address, opening the frontend at confirm-email-change/{token}. It's valid for 3 days.

3. Confirm at the New Address

POST /auth/users/confirm_email_change/
{
  "token": "eyJ1c2VyIjoxLCJmcm9tIjoi..."
}

Switches the account to the new address and tells the old one. No sign-in needed: the token is the proof.

POST /auth/users/set_email/, which changes the email directly, is restricted to staff.

Djoser Configuration

DJOSER = {
    "USER_CREATE_PASSWORD_RETYPE": True,
    "SEND_ACTIVATION_EMAIL": True,
    "SEND_CONFIRMATION_EMAIL": True,
    "PASSWORD_CHANGED_EMAIL_CONFIRMATION": True,
    "USERNAME_CHANGED_EMAIL_CONFIRMATION": True,
    "ACTIVATION_URL": "user-activation/{uid}/{token}",
    "PASSWORD_RESET_CONFIRM_URL": "confirm-password-reset/{uid}/{token}",
    "USERNAME_RESET_CONFIRM_URL": "confirm-username-reset/{uid}/{token}",
    # Answer the same whether or not the email is registered.
    "PASSWORD_RESET_SHOW_EMAIL_NOT_FOUND": False,
    "USERNAME_RESET_SHOW_EMAIL_NOT_FOUND": False,
    "PERMISSIONS": {
        "set_username": ["rest_framework.permissions.IsAdminUser"],
    },
    "SERIALIZERS": {
        "user": "backend.users.api.serializers.UserSerializer",
        "current_user": "backend.users.api.serializers.UserSerializer",
        "user_delete": "backend.users.api.serializers.UserDeleteSerializer",
    },
}

The /auth/users/ routes are served by AccountViewSet (users/api/account_views.py), a subclass of djoser's view that adds the confirmed email change.

On this page