You can restrict the returned data of a GET by specifying the header "Fields", i.e. a comma-separated list of the class fields to be returned (the core will be always returned). If this header is not present, the whole entity will be returned as usual. Currently available only for locations.
Use support/recovery/password in order to set a new password with the given OTP. Cannot be accessed by authenticated users.