Prompt
I'm building a Next.js app and need password reset and verification emails.
Latest observation
Sep 24, 2026
OpenAI APIWeb search: off
A solid setup for Next.js is:
-
Use a transactional email provider
- Recommended: Resend, SendGrid, Postmark, or Amazon SES
- These are much better than sending directly from your app server
-
Generate short-lived secure tokens
- For password reset and email verification, create a random token
- Store only a hashed version in your DB
- Set an expiration time, like 15–60 minutes
-
Send links, not passwords
- Password reset email should include a link like:
https://yourapp.com/reset-password?token=...
- Verification email should include:
https://yourapp.com/verify-email?token=...
- Password reset email should include a link like:
-
Create API routes or server actions
- One endpoint to request reset/verification email
- One endpoint to confirm token and complete the action
-
Protect against abuse
- Rate-limit requests
- Don’t reveal whether an email exists
- Make tokens single-use
-
Build the email content
- Keep it simple
- Include a clear CTA button
- Add expiration info and fallback text link
If you want, I can give you:
- a Next.js App Router example
- a Resend + React Email template
- or a complete password reset + email verification flow with database schema.