GET peeks (email scanners do not apply the change). Each inbox has its own link to this route. POST consumes only that half. users.email is written when the other half is already confirmed. The first click returns a page asking to confirm the other inbox.
Preview email-change confirmation
GET does not consume the token (safe for email scanners). Renders the confirm page for the new inbox, or the current-inbox page with confirm and reject. POST consumes only that half.
Parameters
Query Parameters
Optional post-confirm redirect. Must be a relative path or an allowed origin.
Responses
HTML confirmation page or error page
Confirm email change
Consumes one half of the email-change pair (new inbox or current inbox). Writes users.email only when the other half is already consumed. The first click does not change the login email.
Request Body
Responses
Half confirmed. JSON/HTML says the other inbox is still required, or that users.email was updated. Redirect with email_changed=true only when the change is applied.