Verify an email and set the first password
The one-step activation behind a verification email link: verifies the address, sets the password, activates the account, and returns a token pair so the client can go straight to signed-in without a second round trip through login.
The link’s token is single-use. A second attempt with the same token is refused as invalid rather than as expired. A link never reactivates an account an organisation admin has deactivated.
Request
This endpoint expects an object.
token
The token carried by the verification email link.
password
confirm_password
Response
Account activated; tokens issued.
tokens
email
Errors
400
Bad Request Error
403
Forbidden Error