This article describes how to enable the FortiAuthenticator REST API and update local user accounts via the API.
FortiAuthenticator v6.5.
By default, the REST API services are disabled and need to be enabled and configured to receive and process API requests.
To enable the REST API Server, adjust the admin access at the interface level and create a new admin user or modify an existing one, which allows an administrator to access the web services via a REST API, as described below:
Create a user under Authentication -> User Management -> Local Users -> Create New.
Note: After creating the user, make sure to configure the email field to receive the API token. Refer to the related articles for instructions on setting up the SMTP server.
To enable API services on the new account, toggle the Web Service Access button and select Save. Password confirmation will be requested.
The API access key will be shown as below. Save the access key or request to send the API key over email.
Note: The API can only be enabled for local FortiAuthenticator users. If the API token is lost, it’s necessary to disable and enable Web Service Access again to generate a new API token.
With the API access key in hand, a test can be performed to ensure the API server is listening and working. Issue the following commands:
curl -k -X GET -u "api-admin:Zx0PGUsEnSIw5hwn7BVTNlQzcDlWQXwEmkuYN6Lo" https://192.168.31.72/api/v1/systeminfo/
Now that the REST API is enabled, the user database can be queried and the user updated to enforce a password change, as shown below:
curl -k -X GET -u "api-admin:Zx0PGUsEnSIw5hwn7BVTNlQzcDlWQXwEmkuYN6Lo" https://192.168.31.72/api/v1/localusers/?username__exact=johndoe
Note: Administrator users are not returned in API queries.
After obtaining the user ID, an API PATCH command can be sent to modify the field 'change_password', to enable the option 'Force password change on next logon'.
curl -k -v -u "api-admin:Zx0PGUsEnSIw5hwn7BVTNlQzcDlWQXwEmkuYN6Lo" -X PATCH -d "{\"change_password\": true}" -H "Content-Type: application/json" https://192.168.31.72/api/v1/localusers/18/
The field 'change_password' is now set to true, and the GUI will reflect this change accordingly.
In the related articles, find detailed information and supported methods for the FortiAuthenticator REST API.
Related documents:
Technical Tip: FortiAuthenticator self-service portal
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.