Skip to main content

Email signup: verify-code now returns a setupToken

POST /api/auth/verify-code (and the emailed verification link) now returns a single-use setupToken, valid for 30 minutes. It proves that the person setting the password owns the email address.

Pass it to POST /api/auth/set-password together with the email and password:

{ "email": "you@example.com", "password": "<choose one>", "setupToken": "<from verify-code>" }

What you need to do. If you script or automate signup (agents, CLI-style flows), send the token from the verify step. Today a request without it still succeeds, so nothing breaks yet. We will require it after a notice period, and we will announce the date here.

Accounts that sign in with Google or through the Gluo portal cannot have a password set through this endpoint.

See Authentication and the AI agent quickstart for the updated flow. The OpenAPI document and Postman collection already include the new field.