Home
Advocacy API

Changes to Sensitive Data

Confirm the user's identity before changing their email, password or authentication factors.

To make changes to sensitive information such as a user's email, password or authentication factors, you must provide an id_token as a query parameter in addition to the access token described in Authentication. The id_token is bound to the access token it was issued for and is only valid for 15 minutes.

To get an id_token, send the user's current password to POST /oauth/id_token with their access token:

POST /oauth/id_token HTTP/1.1
Accept: application/json
Content-Type: application/x-www-form-urlencoded
Authorization: Bearer <ACCESS_TOKEN>

password=<PASSWORD>
{
  "id_token": "<ID_TOKEN>",
  "expires_in": 900
}

Should your id_token expire, request a new one the same way. Then pass it along with the change:

PATCH /v2/me?id_token=<ID_TOKEN> HTTP/1.1
Accept: application/vnd.api+json
Content-Type: application/vnd.api+json
Authorization: Bearer <ACCESS_TOKEN>

{
  "data": {
    "id": "1",
    "type": "user",
    "attributes": {
      "email": "jane.doe@example.com"
    }
  }
}