Audience: Application developers
Editorial status: Published — Source Validated
Product: FeraAuth
Classification: public
POST /api/v1/auth/reset
Overview
Implements controller.reset in routes/api/v1/auth/routes.js:92. This public identity boundary applies the documented field validation, safe credential responses, source-IP checks, rate limits, and delivery behavior without requiring an existing session.
Deprecated compatibility paths
POST /api/auth/reset
Use the versioned canonical path for new integrations.
Authentication and access
This operation does not require ordinary bearer authentication.
| Control | Contract |
|---|---|
| Authentication | public |
| Authorization | No prior grant is required; the handler applies credential, token, challenge, rate-limit, or safe-disclosure checks. |
| Licensing | FeraAuth does not evaluate product licenses; consuming products establish access by provisioning FeraAuth instance assignments and permissions. |
| Instance Context | The authenticated token, instance header/body value, or route value selects the application instance used for session and permission evaluation. |
| Ownership | Instance-scoped grants control access; a caller cannot cross into an unrelated instance merely by supplying another resource identifier. |
Parameters
No operation parameters.
Request body
JSON identity command consumed by the source-traced handler.
application/json
Schema: AuthMutation
{
"email": "developer@example.com",
"instance": "715c9ebb-0470-11f1-a928-0ed2cd1b87df",
"uuid": "715c9ebb-0470-11f1-a928-0ed2cd1b87df",
"name": "CAN.LOGIN"
}
Example request
cURL
curl --request POST \ \
--url 'https://auth.feradel.com/api/v1/auth/reset' \
--header 'content-type: application/json' \
--data '{"email":"developer@example.com","instance":"715c9ebb-0470-11f1-a928-0ed2cd1b87df","uuid":"715c9ebb-0470-11f1-a928-0ed2cd1b87df","name":"CAN.LOGIN"}'
Responses
200 The source-traced FeraAuth handler completed and returned its identity, permission, session, or administration representation.
Content type: application/json; schema: AuthSuccess
{
"success": true,
"uuid": "715c9ebb-0470-11f1-a928-0ed2cd1b87df",
"items": [],
"fatal": false,
"status": 200
}
400 Validation, credentials, instance context, or command fields are invalid.
Content type: application/json; schema: AuthError
{
"success": false,
"error": {
"status": 400,
"message": "Invalid credentials"
}
}
500 An unexpected persistence, delivery, or internal identity failure occurred.
Content type: application/json; schema: AuthError
{
"success": false,
"error": {
"status": 500,
"message": "Unable to complete request"
}
}
502 The configured FeraEmail or SMS provider did not accept delivery.
Content type: application/json; schema: AuthError
{
"success": false,
"error": {
"status": 502,
"message": "Unable to complete request"
}
}
Status and retry matrix
| Status | Condition | Retryable | Developer action |
|---|---|---|---|
200 |
The source-traced FeraAuth handler completed and returned its identity, permission, session, or administration representation. | No | Continue with the returned identity representation. |
400 |
Validation, credentials, instance context, or command fields are invalid. | No | Correct the documented credential, permission, state, or dependency condition before retrying. |
500 |
An unexpected persistence, delivery, or internal identity failure occurred. | Yes | Correct the documented credential, permission, state, or dependency condition before retrying. |
502 |
The configured FeraEmail or SMS provider did not accept delivery. | Yes | Correct the documented credential, permission, state, or dependency condition before retrying. |
Related operations and events
- Operation
auth_post_authChallengePre - Operation
auth_post_authChallengeSend - Operation
auth_post_authChallengeVerify - Operation
auth_get_authVerifySession - Operation
auth_post_authCaldavVerify - Operation
auth_post_authVerifyToken - Operation
auth_post_authLocal - Operation
auth_post_auth
Source trace
Repository: feradelinc/feradel.auth.api
Branch: agent/auth-security-hardening
Commit: 8e09b7213fdbc5e0e1552d5271dbeee768e9dd88
Route: routes/api/v1/auth/routes.js
Handler: controller.reset
Contract: OpenAPI 3.1, source-traced and publication-validated.