Skip to content

“This wasn’t me” on the current-inbox confirmation page. GET peeks. POST invalidates both halves that are still active; login email is unchanged. Not confirming already leaves the email unchanged.

Preview email-change cancellation​

GET
/auth/email-change/cancel

GET does not consume the token. The current-inbox confirmation page posts here for “this wasn’t me”. Legacy cancel links still render a cancel page.

Parameters​

Query Parameters

token*
Type
string
Required

Responses​

HTML cancel page or error page

Playground​

Server
Variables
Key
Value

Samples​

Powered by VitePress OpenAPI

Cancel pending email change​

POST
/auth/email-change/cancel

Invalidates both still-active halves of the pair (current inbox token, or a legacy cancel token). Login email is unchanged.

Request Body​

JSON
{
  
"token": "string"
}

Responses​

Request cancelled (JSON or HTML)

Playground​

Server
Body

Samples​

Powered by VitePress OpenAPI