# contractorOps.encryption.resetFingerprintKey

Only while the organization's fingerprint key can't be read any more (the encryption key it was sealed with is lost), replace it with a new one, with a reason, so tax numbers and payment details can be saved and paid out again. Fingerprints are worked out again for every tax number and payment email that can still be read; ones that can't be read lose theirs and are flagged until they're entered again, and saved Wise recipients are created again on their next payout. Refused while the fingerprint key can still be read. Audited with counts and the reason only. Only an administrator in the dashboard can; not available to API keys or MCP clients.

`POST /api/v1/accounting/contractorOps.encryption.resetFingerprintKey`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Destructive: confirm with a person first

Not available over MCP: Destructive key management.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |
| `reason` | string | Yes | A short note saying why, kept in the record's history. 5–500 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.encryption.resetFingerprintKey \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "reason": "Synthetic example from the docs"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractorOps.encryption.resetFingerprintKey
