cURL
Auth
Reset password with a one-time token and bump app_perm_ver
Bumps user.roleRevision so any in-flight JWT for this user is invalidated by the gateway on the very next request — defence-in-depth alongside the per-jti denylist.
POST
cURL
Authorizations
Access token JWT. Use as Authorization: Bearer . In the API playground, paste the JWT only.
Body
application/json
Send a password reset email with a one-time linkComplete HR staff first-access setup (single-use token + initial passwo…