1. Docs
  2. API Reference
  3. Admin-trigger a password reset email

Admin-trigger a password reset email

POST/portal/v1/accounts/{accountSlug}/identities/{id}/reset-password

Triggers an admin-initiated password reset for one identity: mints a hashed, time-limited reset token and emails the identity a link into the end-user reset flow. Account-scoped; returns 404 when the identity is not found and is rejected for an already-erased identity. Writes an identity.password_reset_triggered audit row and returns a confirmation message.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability identities.manageIdentities

Manage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Path Parameters

idstring Required

Responses

application/json

  • dataMessageResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Returned object

Request
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities/value/reset-password" \
  -H "Authorization: Bearer $CANOPY_TOKEN"
Response
{
  "data": {
    "message": "string"
  }
}
Related endpoints
GETList identities in Account
POSTCreate an Account identity
POSTBulk-create Account identities
GETGet directory counts for the Account
GETGet an Account identity
PATCHUpdate an Account identity profile
PATCHSet Account-wide is_active flag
POSTErase an identity (GDPR/CCPA right to be forgotten)
POSTRe-send email verification
POSTRevoke all active sessions for an identity
GETList audit events for an Account identity
POSTAdd an identity to an Environment (create EnvironmentMembership)
POSTBulk-attach EnvironmentMemberships for the Add-from-directory picker
DELETERemove an identity from an Environment (revoke EnvironmentMembership)
Was this page helpful?

Tell us how we can improve this guide.