CorebanqCorebanq Developer Docs
Usersv1Registration

Activate internal user account

AUTHENTICATED BY X-API-Key, not by a bearer token. auth.APIKeyMiddleware REPLACES the usual chain on this route, so there is no user context, no RBAC check and no licence check — and the refusals are common.api_key_required / common.invalid_api_key rather than common.unauthorized / common.rbac_no_rec_access. An OPTIONS request skips the key check entirely. Activate invited internal user account and set password (public endpoint, API key only). Same transactional semantics and compliance fields as /v1/users/activate. Returns 422 with users_m.email_credential_not_found when the expected email credential row is missing after token validation.

POST
/v1/users/activate-internal

Authorization

apiKeyAuth
X-API-Key<token>

Service API key for the eight pre-authentication user routes. auth.APIKeyMiddleware REPLACES the bearer chain on those routes rather than wrapping it: there is no user context, no RBAC check and no licence check on them.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v1/users/activate-internal" \  -H "Content-Type: application/json" \  -d '{    "token": "string",    "password": "stringstring",    "terms_accepted": true,    "privacy_policy_accepted": true  }'
{
  "message": "string",
  "redirect_url": "http://example.com"
}
{
  "status": 400,
  "message": "Invalid user input",
  "code": "users_m.invalid_user_input",
  "class": "validation"
}
{
  "status": 401,
  "message": "common.api_key_required",
  "code": "common.api_key_required",
  "class": "business"
}
{
  "status": 403,
  "message": "common.invalid_api_key",
  "code": "common.invalid_api_key",
  "class": "business"
}

{
  "status": 409,
  "message": "Credential already exists",
  "code": "users_m.duplicate_credential",
  "class": "business"
}

{
  "status": 422,
  "message": "No email credential found for this user",
  "code": "users_m.email_credential_not_found",
  "class": "validation"
}

{
  "status": 429,
  "message": "Too many activation attempts. Please try again in 842 seconds",
  "code": "users_m.activation_rate_limit_exceeded",
  "class": "temporary",
  "retryable": true
}

{
  "status": 500,
  "message": "Internal server error",
  "code": "common.server_error",
  "class": "business"
}

{
  "overall_status": "unhealthy",
  "message": "Service is shutting down",
  "timestamp": "2026-08-27T15:04:05Z"
}