setupToken is now required to set a password
POST /api/auth/set-password now requires the setupToken returned by POST /api/auth/verify-code (or the emailed verification link). A request without a valid token is rejected with 401; a token can be used once and expires after 30 minutes.
The browser sign-up flow already sends it. If you automate signup, update your flow to the order below and pass the token from step 2 to step 3:
POST /api/auth/registerwith the emailPOST /api/auth/verify-codewith the emailed code: the response includessetupTokenPOST /api/auth/set-passwordwithemail,passwordandsetupToken
If your request is rejected, request a fresh code and repeat from step 2. The full request shapes are in Authentication and the OpenAPI document.