/api/v1/auth/password
Public, like GET /api/v1/auth/oidc: the login page asks before anyone is signed in.
curl -X GET "https://example.com/api/v1/auth/password"{ "$schema": "https://example.com/api/v1/schemas/PasswordResetInfo.json", "available": true}/api/v1/auth/oidc/start POST
A form post (application/x-www-form-urlencoded) the browser follows: intent is login, link (connect the signed-in account) or setup (finish an account through its setup link, passed as setup); next is the SPA path to return to. Answers 303 to the provider, or back to the SPA with ?oidc=failed.
/api/v1/auth/password/forgot POST
Public. Always 204, whether or not an account matches, and the mail goes out in the background, so neither the answer nor its timing tells whether an account exists. A login with @ is an address and reaches every account whose confirmed address it is; otherwise it is a username with a confirmed address. An account without a password that signs in through the identity provider gets a hint instead. The owner is never reset by mail; at most one mail per account per 5 minutes.