Person-scoped password reset. Omit the body or send an empty object to request a reset link, send token with newPassword to complete an emailed reset, or send newPassword without token for an authenticated self-service password change. Reset-link requests and self-service changes require the path personId to match a session-backed Person bearer; API keys are not accepted. Ordinary self-service changes also require a recent MFA step-up for HighRiskWriteAction; otherwise the operation returns 403 StepUpMfaRequired. A session created by redeeming an invite may set its first password without that step-up only during the bounded invite-redemption window enforced by the authentication service. Successful token completion accepts only a one-time password-reset-purpose session issued by the emailed link. Its JWT has a reset-only audience and cannot be used as an API bearer; an ordinary Person session token is also rejected. Successful password changes revoke all Person sessions in the authentication service. Passwords belong to the Person and must be 8-512 characters, contain at least one ASCII letter and one digit, and contain no whitespace. Invalid passwords return
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
204Password reset successful