---
title: Set a new password from a reset email
sidebar_label: Set a new password from a reset email
sidebar_position: 8
description: Set a new password with the id and secret from a reset email using POST /v2/auth/reset-password/process.
---

# Set a new password from a reset email

| Method | Path |
| --- | --- |
| `POST` | `/v2/auth/reset-password/process` |

[Authentication](/authentication) · [Account routes](/authentication#account-routes) · [Email templates](/email-templates)

Sets a new password using the `id` and `secret` from a reset email. Use it when your app handles the reset itself, on the page that the emailed link opens. The first step is [Send a password reset email](/authentication/account/reset-password).

:::note
This is an account-level route. It has no `/auth/tenant/` variant and needs no token.
:::

**Auth:** None. The reset request `id` and `secret` are the credential.
**Scope:** The user the reset request was created for.

## Request

### Body

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | `string` | Yes | The reset request id. It is the `id` in the emailed link `<app URL>/setpassword/<id>/<secret>`. |
| `secret` | `string` | Yes | The reset request secret, from the same link. |
| `password` | `string` | Yes | The new password. Ovok applies no length or strength rule, so check it in your app. |

## Behaviour

- A request can be used once. Ovok marks it used before it changes the password. If the password change then fails, the request cannot be retried and the user must ask for a new email.
- A newer reset email replaces the older one: after a second [reset request](/authentication/account/reset-password), only the newest `id` and `secret` work.
- The route applies no time limit of its own to a request.
- Setting the password also marks the user's email address as verified, because the secret came by email.
- The route does not end existing sessions.
- The response is a minimal User with `resourceType`, `id` and `email`.
- The route is rate limited to 5 requests per minute for each caller.

## Example

```bash
curl -X POST 'https://api.sandbox.ovok.com/v2/auth/reset-password/process' \
  -H 'Content-Type: application/json' \
  -d '{
    "id": "4d8f1a63-9b2e-4c70-8e15-a3b6d9c2f047",
    "secret": "<secret from the email>",
    "password": "<new password>"
  }'
```

## Successful response

`201` — The password is changed.

```json
{
  "resourceType": "User",
  "id": "9a4e6c10-3b7d-4f28-8c15-2d0e7b9a6f43",
  "email": "alex@example.com"
}
```

| Field | Type | Description |
| --- | --- | --- |
| `resourceType` | `"User"` | Always `User`. |
| `id` | `string (uuid)` | User id. |
| `email` | `string` | Sign-in email address. |

## Errors

| Status | Meaning |
| --- | --- |
| `404` | No reset request has this `id`. |
| `409` | The reset request was already used, or a newer reset email replaced it. |
| `422` | `id`, `secret` or `password` is missing or not a string, or `secret` does not match the request. |
| `429` | More than 5 requests in a minute from the same caller. |
