Skip to navigation

Request a hosted PIN reset for a person

Returns a CorpX page URL. The person opens it, completes the facial check and, if it is approved, chooses the new PIN on that page. The body does not accept the PIN. Requires scope pin.manage, the pin_hosted_reset feature and an existing PIN — a PIN invalidated by DELETE still counts. Five requests per person per hour, across accounts. The per-account alias counts toward the same limit.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
X-Acting-DocumentstringRequired
CPF of the person, 11 digits.
Idempotency-KeystringOptional

Optional client-generated idempotency token (recommended for safe retries).

X-Request-TimestampstringRequired

Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).

X-Content-SHA256stringRequired

Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.

X-Request-SignaturestringRequired

Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.

Request

This endpoint expects an object.
displayMessagestringOptional<=240 characters

Response

Link for the person. The token is in the URL fragment.
resetIdstringOptional
resetUrlstringOptional
expiresAtdatetimeOptional

Errors

403
Forbidden Error
409
Conflict Error
429
Too Many Requests Error