Authentication
Password recovery and reset
Forgot-password emails, the reset page, and what a reset changes.
The flow#
- The user asks for a link on the hosted forgot-password page (linked from sign-in).
- An email with a link to your hosted reset page is sent, valid for 15 minutes.
- The reset page checks the link first. An expired or used link shows how to request a new one.
- A new password that meets the policy is set, and the user signs in again.
Requesting a reset link#
To start it from your own UI, call AuthClient.forgotPassword(email, environmentId) on the server. The answer is the same whether or not the address has an account, and a new request replaces the previous link. See forgotPassword in the server example.
What a reset does#
- The link works once. Two submissions at the same moment can't both succeed.
- The new password, the used link and the revocation of every existing session of that user are saved together. If any of the three fails, none of them is applied.
- Only a SHA-256 digest of the link's token is stored.
- The reset changes only that user, in that environment. Accounts with the same address elsewhere are untouched.
Limitations#
At most three requests a minute are accepted per address. A request for an address with no account still answers normally, so the form reveals nothing about who has an account.