Change password using current password
Requires matching confirmation and the current password. Atomically invalidates all refresh sessions, outstanding email challenges and access JWTs across every membership. Login again after success.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
confirmPassword*stringpassword12 <= length <= 72currentPassword*stringpassword0 <= length <= 72newPassword*stringpassword12 <= length <= 72Password changed; login again
curl -X POST 'https://api.monetaryai.uz/api/v1/me/security/password' \ -H 'Content-Type: application/json' \ -d '{ "confirmPassword": "pa$$word_qwe", "currentPassword": "pa$$word", "newPassword": "pa$$word_qwe"}'Confirm email 2FA enrollment POST
Requires current password and acknowledged ENABLE code. Invalidates every session and access token for the global identity; login again with password and email code. Wrong, expired, unacknowledged, foreign or reused challenges return 401.
Get inventory, depreciation and tax settings GET
Before first save returns FIFO, STRAIGHT_LINE, null taxRegime/vatRate and version 0. VAT is not guessed from a screenshot or statutory rules. This UI configuration is separate from immutable effective-dated policy/tax records and is not automatically consumed by posting/tax engines. Company permission: `getCompanyAccountingSettings`. Defaults: ADMIN, ACCOUNTANT, VIEWER. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.