AlmondTill/G3N API

On this page

resetConsumerPassword

mutation · in the family Identity and access

What it does

Reset a shopper’s password, as staff — the recovery lane.

STAFF: set a consumer's password credential DIRECTLY: writes a NEW argon2id credential; arms self-service on a staff-created profile; REFUSED on a doomed (de-identified) consumer. Existing sessions stay live — pair with revokeConsumerSessions for a takeover response. Template class; requires the unrestricted capability.

Careful

An account-takeover-sensitive act; it is recorded, and the customer should be verified first.

Who may call it

Capability area: Identity and access — Who can sign in and what each role allows — users, roles and their assignments.

Arguments

NameTypeRequiredNotes
consumerIdID ID!yesNo further notes.
newPasswordString String!yesNo further notes.

Returns

Boolean Boolean! — True or false.

Example request

mutation ExampleResetConsumerPassword($consumerId: ID!, $newPassword: String!) {
  resetConsumerPassword(consumerId: $consumerId, newPassword: $newPassword)
}

Variables:

{
  "consumerId": "01900000-0000-7000-8000-6e8c92ec0000",
  "newPassword": "<new password>"
}

Send it with the envelope naming the version: "extensions": {"at": {"version": {"name":"genesis","number":0}}}.

Example response

{
  "data": {
    "resetConsumerPassword": true
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}

Errors this call can answer