---
title: "Get someone's personal set-password link"
description: "A one-time link that lets this person, and only this person, set their password at the suite's address."
canonical: "https://gtable.app/docs/builder-api/users/password-link"
updated: "2026-10-05"
---

# Get someone's personal set-password link

`POST https://studio.gtable.app/v1/users/{userId}/password-link`

A one-time link that lets this person, and only this person, set their password at the suite's address.

Being in the directory proves nothing, the platform sends no email, so this is how a person without Google gets in: you hand them the link. It works once, for seven days, and making a new one retires the last. Refused for someone who can already sign in. The URL is returned once and never stored in clear.

Requires the `members:write` scope. Operation `users.passwordLink`. Not an MCP tool: a set-password link is a credential for another person and never passes through a model. CLI, once published: `gtable users password-link`.

## Path parameters

| Name     | Type   | Required | Description |
| -------- | ------ | -------- | ----------- |
| `userId` | string | yes      |             |

## Headers

| Name              | Type   | Required | Description                                                                                                                                                                                                                                                        |
| ----------------- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `Idempotency-Key` | string | no       | Any unique string. Sending the same key with the same request again returns the first response (marked `Idempotency-Replayed: true`) instead of running it twice. Reusing it for a different request is refused with 409. Kept for 24 hours. Up to 255 characters. |
