Change the password on a customer's login. Every outstanding reset link stops working at the same moment. Send current_password when your form insists on it — it is checked first (401 when wrong); your site has already signed the customer in, so that is your choice, not the API's.