Set a new password from a reset email
| Method | Path |
|---|---|
POST | /v2/auth/reset-password/process |
Authentication · Account routes · Email templates
Sets a new password using the id and secret from a reset email. Use it when your app handles the reset itself, on the page that the emailed link opens. The first step is Send a password reset email.
note
This is an account-level route. It has no /auth/tenant/ variant and needs no token.
Auth: None. The reset request id and secret are the credential.
Scope: The user the reset request was created for.
Request
Body
| Name | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The reset request id. It is the id in the emailed link <app URL>/setpassword/<id>/<secret>. |
secret | string | Yes | The reset request secret, from the same link. |
password | string | Yes | The new password. Ovok applies no length or strength rule, so check it in your app. |
Behaviour
- A request can be used once. Ovok marks it used before it changes the password. If the password change then fails, the request cannot be retried and the user must ask for a new email.
- A newer reset email replaces the older one: after a second reset request, only the newest
idandsecretwork. - The route applies no time limit of its own to a request.
- Setting the password also marks the user's email address as verified, because the secret came by email.
- The route does not end existing sessions.
- The response is a minimal User with
resourceType,idandemail. - The route is rate limited to 5 requests per minute for each caller.
Example
curl -X POST 'https://api.sandbox.ovok.com/v2/auth/reset-password/process' \
-H 'Content-Type: application/json' \
-d '{
"id": "4d8f1a63-9b2e-4c70-8e15-a3b6d9c2f047",
"secret": "<secret from the email>",
"password": "<new password>"
}'
Successful response
201 — The password is changed.
{
"resourceType": "User",
"id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"email": "alex@example.com"
}
| Field | Type | Description |
|---|---|---|
resourceType | "User" | Always User. |
id | string (uuid) | User id. |
email | string | Sign-in email address. |
Errors
| Status | Meaning |
|---|---|
404 | No reset request has this id. |
409 | The reset request was already used, or a newer reset email replaced it. |
422 | id, secret or password is missing or not a string, or secret does not match the request. |
429 | More than 5 requests in a minute from the same caller. |