Settings
User self-service: change email/password, account deletion
📄️ Change user email
Change user email
📄️ Send email confirmation
Send email confirmation
📄️ Change password
Change password
📄️ Change receive emails preference
Change receive emails preference
📄️ Request account deletion
Initiates user-initiated account deletion. Verifies the supplied password (skipped for OAuth-only accounts) and emails a confirmation link. Rate-limited per `auth.account_delete.timeout`. JWT-gated.
📄️ Validate a deletion confirmation hash
Public. Reports whether the emailed deletion hash is still live (not expired, account not already deleted). Used by the confirmation page to decide whether to show the confirm action or an expired-link message.
📄️ Confirm account deletion
Public. Finalizes a user-initiated deletion via the emailed hash: executes the soft-delete (mask email, neutralize identities, stamp `deleted_at`). Idempotent-safe: an invalid/expired hash returns a soft error in the body.