Password
Password - again
Reset response
By default just 'id', and 'authentication_token' are returned. However by overriding User::get_security_payload() any attributes of the User model can be returned.
Session CSRF token
{ "user": { "id": 42 } }