Authentication

Password recovery and reset

Forgot-password emails, the reset page, and what a reset changes.

The flow#

  1. The user asks for a link on the hosted forgot-password page (linked from sign-in).
  2. An email with a link to your hosted reset page is sent, valid for 15 minutes.
  3. The reset page checks the link first. An expired or used link shows how to request a new one.
  4. A new password that meets the policy is set, and the user signs in again.

Requesting a reset link#

To start it from your own UI, call AuthClient.forgotPassword(email, environmentId) on the server. The answer is the same whether or not the address has an account, and a new request replaces the previous link. See forgotPassword in the server example.

What a reset does#

  • The link works once. Two submissions at the same moment can't both succeed.
  • The new password, the used link and the revocation of every existing session of that user are saved together. If any of the three fails, none of them is applied.
  • Only a SHA-256 digest of the link's token is stored.
  • The reset changes only that user, in that environment. Accounts with the same address elsewhere are untouched.

Limitations#

At most three requests a minute are accepted per address. A request for an address with no account still answers normally, so the form reveals nothing about who has an account.