Prompt
How do I send password reset emails from a backend app using an email API?
Latest observation
Sep 22, 2026
MistralWeb search: on
To send password reset emails from a backend app using an email API, follow this standard flow:
- Generate a Secure Token: Create a random, unique token (e.g., using a UUID or crypto library) and store a hashed version of it in your database, along with an expiration time (typically 15–60 minutes).
- Construct the Reset Link: Build a URL (e.g.,
https://yourapp.com/reset-password?token=UNIQUE_TOKEN) that includes the token and points to your password reset page. - Send the Email: Use an email API (like Notify, Mailgun, or SendGrid) to send an email to the user with the reset link. The API call is a simple HTTP POST request with the recipient’s email, subject, and the reset link in the body. Never include the actual password or token in plaintext in the email—only the link.
- Handle the Reset: When the user clicks the link, your backend verifies the token (checks if it exists, is unexpired, and matches the stored hash). If valid, allow the user to set a new password.
- Optional: Webhooks for Bounces: Register a webhook with your email API (e.g., Notify) to automatically receive notifications for bounced or failed emails, so your app can log or act on delivery issues.
Example API Call (Notify):
curl -X POST https://notify.cx/api/email/send \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"to": "user@example.com",
"from": "noreply@yourapp.com",
"subject": "Password Reset Request",
"body": "Click here to reset your password: https://yourapp.com/reset-password?token=UNIQUE_TOKEN"
}'