Request a hosted PIN reset

Returns a CorpX page URL. The operator opens it, completes the facial check for the CPF on the request and, if the check is approved, chooses the new PIN on that same page. The integrator never sees or chooses the PIN. The body does not accept it. Requires scope `pin.manage` and an existing PIN for that operator. With no PIN, the response is **409** `pin_reset_not_enrolled` and the first enrollment stays on `PUT .../security/pin`. When hosted reset is not enabled for the tenant, the response is **403** `feature_disabled`. Optional `displayMessage` is one line of plain text, at most 240 characters, without HTML, Markdown or links. The page shows that text as-is. The link expires in 30 minutes. Five requests per operator per hour; a new request expires earlier open links for the same operator.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

accountIdstringRequired
Account identifier.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
Idempotency-KeystringOptional

Optional client-generated idempotency token (recommended for safe retries).

Request

This endpoint expects an object.
actingDocumentstringRequired
CPF of the operator whose PIN will be reset.
displayMessagestringOptional<=240 characters
Optional plain text shown on the CorpX page.

Response

Link for the operator. The token is in the URL fragment.
resetIdstringOptional
resetUrlstringOptional
Open this URL in the operator's browser. The credential is the fragment, not a query parameter.
expiresAtdatetimeOptional

Errors

400
Bad Request Error
403
Forbidden Error
409
Conflict Error
429
Too Many Requests Error