OUTCOME · Create or advance
What changes
Creates or advances only the email change resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2Identity sessions and federation
/api/v2/me/contact/email-change-requests/confirmPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this when an identity, compliance, relying-party, or trust agent workflow needs to apply the documented email change transition after re-reading the current authoritative state so it can make a purpose-limited identity or assurance decision with current policy and lifecycle state.
OUTCOME · Create or advance
Creates or advances only the email change resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the profile:write scope.EXAMPLEBearer hc_live_…
Idempotency-KeyheaderRequiredASCII string · 1–128Caller-generated key reused for every retry of the same logical mutation.EXAMPLElaunch-treasury-v1-001
Content-TypeheaderRequiredapplication/jsonSigned mutations accept canonical JSON only.EXAMPLEapplication/json
Content-DigestheaderRequiredRFC 9530 SHA-256 digestDigest of the exact transmitted body bytes.EXAMPLEsha-256=:47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=:
Signature-InputheaderRequiredRFC 9421 signature parametersCovers @method, @path, content-digest, content-type, and idempotency-key; includes keyid, nonce, created, and expires.EXAMPLEsig1=("@method" "@path" "content-digest" "content-type" "idempotency-key");created=1786582800;expires=1786583100;nonce="01J…";keyid="machine-prod"
SignatureheaderRequiredEd25519 HTTP Message SignatureSignature made by an active public key registered to the authenticated client.EXAMPLEsig1=:base64-signature:
tokenbodyRequiredone-time hcat_ token15-minute token delivered to the proposed email address.
REQUEST
{
"token": "hcat_…"
}RESPONSES
{
"request_id": null,
"status": "VERIFIED",
"contact_type": "EMAIL",
"delivery_channel": null,
"target_hint": "a***@example.net",
"expires_at": null,
"profile_uuid": "f8317aef81764e1f923037c1b76df8de",
"sessions_revoked": true
}{
"code": "invalid_profile_update",
"message": "The contact value, token, or signed request shape is invalid."
}invalid_profile_update{
"code": "invalid_credentials",
"message": "The bearer credential or HTTP Message Signature is missing, expired, replayed, or invalid."
}invalid_credentials{
"code": "step_up_required",
"message": "The current password failed, the profile scope is absent, fresh purpose-bound authenticator verification is required, or the one-time token is invalid, expired, superseded, or consumed."
}step_up_required{
"code": "contact_change_conflict",
"message": "The verified target contact is already in use."
}contact_change_conflict{
"code": "identity_unavailable",
"message": "Identity or the configured contact-delivery channel is unavailable."
}identity_unavailableOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗