The password reset endpoint was fully blocked under OIDC mode. Now M2M callers (identified by oidc: principal prefix) can reset local user passwords, enabling the SaaS platform to manage the server's built-in admin credentials. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>