İçeriğe geç

/v1/users/{id}/recovery

POST
/v1/users/{id}/recovery
curl --request POST \
--url https://api.reindeer.example.tr/v1/users/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/recovery \
--header 'Authorization: Bearer <token>'

Scope users:write, fresh step-up. Requests the recovery of a person who lost every passkey (ADR-0011). Nobody in that person’s control chain, the person included, can decide it. Once approved it becomes an invite that names the account in recovers and stays open for limits.recovery_lifetime (24 hours); only the administrator who requested it may issue its code (403 recovery_requester_only otherwise). Redeeming the code adds a new passkey to the same account, removes its other passkeys and sessions, and adds the requester, the code issuers and the approver to the account’s controllers.

id
required
string format: uuid

Approval waiting for a second person

Media typeapplication/json
object
approval
object
id
string
kind
string
Allowed values: identity.create invite.create export.full deletion.accept key.declare-lost
summary
string
requested_by
string
requested_at
string format: date-time
not_before
string format: date-time
expires_at
string format: date-time
state
string
Allowed values: pending approved executing rejected expired executed failed cancelled
controllers

Everyone who controlled the requester when the request was made: the issuers of its codes, the person who requested a machine, and their controllers in turn

Array<string>
cool_off_seconds
integer
decided_by
string
decided_at
string format: date-time
cancelled_by
string
cancelled_at
string format: date-time
result
object

Example

{
"approval": {
"kind": "identity.create",
"state": "pending"
}
}

RFC 9457 problem

Media typeapplication/problem+json
object
status
integer
code
string
title
string
detail
string
type
string

Example generated

{
"status": 1,
"code": "example",
"title": "example",
"detail": "example",
"type": "example"
}

Recover_self for your own account, account_disabled for a disabled one