Skip to navigation

Verify an email and set the first password

The one-step activation behind a verification email link: verifies the address, sets the password, activates the account, and returns a token pair so the client can go straight to signed-in without a second round trip through login.

The link’s token is single-use. A second attempt with the same token is refused as invalid rather than as expired. A link never reactivates an account an organisation admin has deactivated.

Request

This endpoint expects an object.
tokenstringRequired
The token carried by the verification email link.
passwordstringRequiredformat: "password"6-68 characters
confirm_passwordstringRequiredformat: "password"

Response

Account activated; tokens issued.

tokensobjectOptional
emailstringOptionalformat: "email"

Errors

400
Bad Request Error
403
Forbidden Error