contractorOps.encryption.resetFingerprintKey
Only while the organization's fingerprint key can't be read any more (the encryption key it was sealed with is lost), replace it with a new one, with a reason, so tax numbers and payment details can be saved and paid out again. Fingerprints are worked out again for every tax number and payment email that can still be read; ones that can't be read lose theirs and are flagged until they're entered again, and saved Wise recipients are created again on their next payout. Refused while the fingerprint key can still be read. Audited with counts and the reason only. Only an administrator in the dashboard can; not available to API keys or MCP clients.
/api/v1/accounting/contractorOps.encryption.resetFingerprintKeyPermissions
Who can call it
Retries
MCP
Can't be undone
Fields
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–200 characters
reasonstringRequiredA short note saying why, kept in the record's history.
5–500 characters
Example
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.encryption.resetFingerprintKey \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"reason": "Synthetic example from the docs"
}'{
"data": { … }
}Try it
Try it
Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.encryption.resetFingerprintKey \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"reason": "Synthetic example from the docs"
}'More in Contractors.