Prompt
How do I send email verification links?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
To send email verification links, the usual flow is:
-
User signs up
Create the user account withemail_verified = false. -
Generate a unique verification token/link
Create a secure, time-limited token tied to the user. -
Send an email with the link
The link usually looks like:https://yourapp.com/verify-email?token=ABC123 -
User clicks the link
Your backend checks:- token is valid
- token not expired
- token matches the user
-
Mark email as verified
Update the user record:email_verified = true- clear the token if needed
Typical implementation ideas
Backend
You can use:
- Node.js: Nodemailer + JWT or random token
- Python: Django / Flask + email library
- PHP: Laravel’s built-in verification
- Ruby on Rails: Devise confirmation
- Firebase/Auth0/Clerk: built-in email verification
Example link flow
- Generate token:
a8f3... - Save hashed token in DB with expiration
- Email:
Click here to verify your email:
https://example.com/verify?token=a8f3...
Best practices
- Make tokens single-use
- Expire them in 15–60 minutes or a few hours
- Store tokens hashed, not plain text
- Rate-limit resend requests
- Use HTTPS
- Provide a resend verification email option
If you want a quick code example
I can give you one for:
- Node.js
- Python
- PHP
- Laravel
- Django
- Firebase
If you tell me your stack, I’ll show the exact implementation.