cURL
Auth
Complete HR staff first-access setup (single-use token + initial passwo…
Does not mint a JWT. After success the user signs in with email + password. Rate-limited per client IP.
POST
cURL
Authorizations
Access token JWT. Use as Authorization: Bearer . In the API playground, paste the JWT only.
Reset password with a one-time token and bump app_perm_verRevoke the current JWT (jti goes onto the Redis denylist)