Request a hosted PIN reset for a person
Returns a CorpX page URL. The person opens it, completes the facial
check and, if it is approved, chooses the new PIN on that page. The
body does not accept the PIN. Requires scope pin.manage, the
pin_hosted_reset feature and an existing PIN — a PIN invalidated by
DELETE still counts. Five requests per person per hour, across
accounts. The per-account alias counts toward the same limit.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
Optional client-generated idempotency token (recommended for safe retries).
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.