Contractors

contractorOps.encryption.resetFingerprintKey

Only while the organization's fingerprint key can't be read any more (the encryption key it was sealed with is lost), replace it with a new one, with a reason, so tax numbers and payment details can be saved and paid out again. Fingerprints are worked out again for every tax number and payment email that can still be read; ones that can't be read lose theirs and are flagged until they're entered again, and saved Wise recipients are created again on their next payout. Refused while the fingerprint key can still be read. Audited with counts and the reason only. Only an administrator in the dashboard can; not available to API keys or MCP clients.

POST/api/v1/accounting/contractorOps.encryption.resetFingerprintKey

Permissions

accounting:readaccounting:writeaccounting:admin

Who can call it

admin

Retries

Idempotency key required

MCP

Not offered over MCP: Destructive key management.

Can't be undone

It deletes, voids, revokes or discards something. Confirm with a person first.

Fields

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

  • reasonstringRequired

    A short note saying why, kept in the record's history.

    5–500 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.encryption.resetFingerprintKey \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "reason": "Synthetic example from the docs"
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/contractorOps.encryption.resetFingerprintKey
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.encryption.resetFingerprintKey \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "reason": "Synthetic example from the docs"
}'

More in Contractors.