Email a password reset link (ACCT-3)
Sends a link (valid 1h, single use) if the email has an account. Same answer either way. No authentication needed.
Sends a link (valid 1h, single use) if the email has an account. Same answer either way.
No authentication needed.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/password/forgot" \ -H "Content-Type: application/json" \ -d '{ "email": "string" }'{ "message": "Check your email to finish signing up."}Sign in with email + password (ACCT-1) POST
401 `bad_credentials` ("Email or password is incorrect.") for any wrong email or password; 403 `email_unverified` when the email still needs verifying; 403 `not_invited`. No authentication needed.
Set a new password from a reset link (ACCT-3) POST
Also marks the email verified (the link proves it) and signs out every session of the account. It doesn't sign in; sign in with the new password. No authentication needed.