Skip to main content

Set a new password from a reset email

MethodPath
POST/v2/auth/reset-password/process

Authentication · Account routes · Email templates

Sets a new password using the id and secret from a reset email. Use it when your app handles the reset itself, on the page that the emailed link opens. The first step is Send a password reset email.

note

This is an account-level route. It has no /auth/tenant/ variant and needs no token.

Auth: None. The reset request id and secret are the credential. Scope: The user the reset request was created for.

Request​

Body​

NameTypeRequiredDescription
idstringYesThe reset request id. It is the id in the emailed link <app URL>/setpassword/<id>/<secret>.
secretstringYesThe reset request secret, from the same link.
passwordstringYesThe new password. Ovok applies no length or strength rule, so check it in your app.

Behaviour​

  • A request can be used once. Ovok marks it used before it changes the password. If the password change then fails, the request cannot be retried and the user must ask for a new email.
  • A newer reset email replaces the older one: after a second reset request, only the newest id and secret work.
  • The route applies no time limit of its own to a request.
  • Setting the password also marks the user's email address as verified, because the secret came by email.
  • The route does not end existing sessions.
  • The response is a minimal User with resourceType, id and email.
  • The route is rate limited to 5 requests per minute for each caller.

Example​

curl -X POST 'https://api.sandbox.ovok.com/v2/auth/reset-password/process' \
-H 'Content-Type: application/json' \
-d '{
"id": "4d8f1a63-9b2e-4c70-8e15-a3b6d9c2f047",
"secret": "<secret from the email>",
"password": "<new password>"
}'

Successful response​

201 — The password is changed.

{
"resourceType": "User",
"id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
"email": "alex@example.com"
}
FieldTypeDescription
resourceType"User"Always User.
idstring (uuid)User id.
emailstringSign-in email address.

Errors​

StatusMeaning
404No reset request has this id.
409The reset request was already used, or a newer reset email replaced it.
422id, secret or password is missing or not a string, or secret does not match the request.
429More than 5 requests in a minute from the same caller.