Prompt
How do I send password reset emails from my app?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
To send password reset emails from your app, the usual flow is:
-
User requests a reset
- They enter their email address on a “Forgot password?” page.
-
Generate a secure reset token
- Create a random, hard-to-guess token.
- Store only a hashed version of the token in your database.
- Save an expiration time (for example, 15–60 minutes).
-
Email the user a reset link
- The link should point to your app, something like:
https://yourapp.com/reset-password?token=... - Include the raw token in the URL.
- The link should point to your app, something like:
-
User opens the link and sets a new password
- Verify the token exists, matches the stored hash, and is not expired.
- Let them submit a new password.
- Save the new password using a strong hash like bcrypt, Argon2, or scrypt.
-
Invalidate the token
- Delete the reset token after use.
- Also invalidate any existing sessions if appropriate.
Important security practices
- Never email the password itself
- Do not store reset tokens in plain text
- Use HTTPS
- Make tokens single-use and short-lived
- Avoid revealing whether an email exists
- Say something like: “If an account exists, we sent a reset link.”
- Rate-limit reset requests to reduce abuse
- Add email-sending logging and monitoring
Typical implementation pieces
- Backend endpoint:
POST /forgot-password - Backend endpoint:
POST /reset-password - Database table/collection for reset tokens
- Email service like:
- SendGrid
- Mailgun
- Amazon SES
- Postmark
- Nodemailer + SMTP
Example flow
Forgot password request
POST /forgot-password
{ "email": "user@example.com" }
Email contains
Click to reset your password:
https://yourapp.com/reset-password?token=abc123
Reset submission
POST /reset-password
{
"token": "abc123",
"newPassword": "newStrongPassword123!"
}
If you want, I can show you a complete example in Node.js, Python, PHP, or Java.