Set or change a person's transaction PIN
The PIN belongs to the person (X-Acting-Document) inside the tenant,
and is the same PIN on every account that person operates. Requires
scope pin.manage. The CPF is a header, not a path segment: API
Gateway access logs store the path.
The first enrollment does not send currentPin. Replacing an existing
PIN requires currentPin. When hosted reset is on, a replacement
without currentPin returns 403 pin_change_disabled; a
replacement with the correct currentPin succeeds. After DELETE, a
PUT without currentPin re-enrolls only while hosted reset is off.
Authentication
AuthorizationBearer
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
X-Tenant-Id
Tenant context used for authorization and routing.
X-Acting-Document
CPF of the person, 11 digits.
Idempotency-Key
Optional client-generated idempotency token (recommended for safe retries).
Request
This endpoint expects an object.
pin
currentPin
Required when replacing an existing PIN.
Response
PIN created, replaced or re-enrolled.
document
Masked CPF.
status
Allowed values:
Errors
403
Forbidden Error
422
Unprocessable Entity Error
423
Locked Error