Advocacy API
Changes to Sensitive Data
Confirm the user's identity before changing their email, password or authentication factors.
To make changes to sensitive information such as a user's email, password or authentication factors, you must
provide an id_token as a query parameter in addition to the access token described in
Authentication. The id_token is bound to the access token it was issued for and is only
valid for 15 minutes.
To get an id_token, send the user's current password to POST /oauth/id_token with their access token:
POST /oauth/id_token HTTP/1.1
Accept: application/json
Content-Type: application/x-www-form-urlencoded
Authorization: Bearer <ACCESS_TOKEN>
password=<PASSWORD>{
"id_token": "<ID_TOKEN>",
"expires_in": 900
}Should your id_token expire, request a new one the same way. Then pass it along with the change:
PATCH /v2/me?id_token=<ID_TOKEN> HTTP/1.1
Accept: application/vnd.api+json
Content-Type: application/vnd.api+json
Authorization: Bearer <ACCESS_TOKEN>
{
"data": {
"id": "1",
"type": "user",
"attributes": {
"email": "jane.doe@example.com"
}
}
}