Z Zise Developers 简体中文

Change the account email: obtain a hosted-screen link

POST /v1/members/{id}/email-sessions scope: members:write
Merchant account Requires x-idempotency-key

Give hosted_url to the end user. They enter the new address on our page, and we send one verification code to each of the old and new addresses. Both codes must be correct.

── Why this is not a PATCH field ── Email is this member's only step-up authentication factor with us. They have no platform password (the account has a random placeholder), passkey, or trusted device.

An endpoint allowing direct email changes would let you replace any member's factor with your own mailbox, then complete step-up authentication as that member to access card details or add withdrawal addresses. That is a complete account-takeover path, so the end user must perform this action within our domain.

Each code proves a different fact:

  • The new-address code proves ownership of the new mailbox, preventing binding to a mistyped address and permanently losing contact.
  • The current-address code proves ownership of the existing account.

⚠ A successful change revokes all of the member's platform sessions, trusted devices, and passkeys. It does not directly affect you, since your members do not normally use our sessions, but refresh any email address you have cached locally.

⚠ If the new address is already used by someone else on the platform, the hosted page informs the user. This endpoint does not check availability; doing so during ticket issuance would give you an email-probing API.

The link is single-use, bound to the member, and valid for 24 hours.

Path Parameters

FieldTypeRequiredDescription
id string Required Member identifier: either our mem_<uuid> or your external_member_id. There is no fallback; an external identifier beginning with mem_ is parsed as our ID.
FieldTypeRequiredDescription
x-idempotency-key string Required

Response

201Ticket issued
{
  "id": "kyc_2e7f90b1c4a34d58ae3b6f2019c7d845",
  "hosted_url": "https://api.zinfra.vip/hosted/email/kyc_2e7f90b1c4a34d58ae3b6f2019c7d845",
  "expires_at": 1786000000
}
400member_not_found: member does not exist or does not belong to you. idempotency_key_required.
Request
curl -X POST 'https://api.zinfra.vip/v1/members/{id}/email-sessions' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-idempotency-key: $IDEMPOTENCY_KEY'
const res = await fetch("https://api.zinfra.vip/v1/members/{id}/email-sessions", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-idempotency-key": "$IDEMPOTENCY_KEY",
  },
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/members/{id}/email-sessions",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-idempotency-key": "$IDEMPOTENCY_KEY",
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/members/{id}/email-sessions",
    nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/members/{id}/email-sessions"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-idempotency-key", "$IDEMPOTENCY_KEY")
    .method("POST", HttpRequest.BodyPublishers.noBody())
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/members/{id}/email-sessions');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-idempotency-key: $IDEMPOTENCY_KEY',
  ],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
201
{
  "id": "kyc_2e7f90b1c4a34d58ae3b6f2019c7d845",
  "hosted_url": "https://api.zinfra.vip/hosted/email/kyc_2e7f90b1c4a34d58ae3b6f2019c7d845",
  "expires_at": 1786000000
}