Prompt
password reset email API python
Latest observation
Oct 4, 2026
OpenAI APIWeb search: off
Here’s a simple Python example for a password reset email API using FastAPI and SMTP.
1) Install dependencies
pip install fastapi uvicorn python-dotenv
2) Example API
from fastapi import FastAPI, HTTPException
from pydantic import BaseModel, EmailStr
import smtplib
from email.mime.text import MIMEText
from dotenv import load_dotenv
import os
import secrets
load_dotenv()
app = FastAPI()
SMTP_HOST = os.getenv("SMTP_HOST")
SMTP_PORT = int(os.getenv("SMTP_PORT", 587))
SMTP_USER = os.getenv("SMTP_USER")
SMTP_PASSWORD = os.getenv("SMTP_PASSWORD")
FROM_EMAIL = os.getenv("FROM_EMAIL", SMTP_USER)
class ResetRequest(BaseModel):
email: EmailStr
def send_reset_email(to_email: str, reset_link: str):
subject = "Password Reset Request"
body = f"""
Hi,
We received a request to reset your password.
Click the link below to reset it:
{reset_link}
If you did not request this, ignore this email.
"""
msg = MIMEText(body)
msg["Subject"] = subject
msg["From"] = FROM_EMAIL
msg["To"] = to_email
with smtplib.SMTP(SMTP_HOST, SMTP_PORT) as server:
server.starttls()
server.login(SMTP_USER, SMTP_PASSWORD)
server.send_message(msg)
@app.post("/password-reset")
def password_reset(request: ResetRequest):
# In a real app, verify user exists in DB
token = secrets.token_urlsafe(32)
reset_link = f"https://your-frontend.com/reset-password?token={token}"
try:
send_reset_email(request.email, reset_link)
return {"message": "Password reset email sent"}
except Exception as e:
raise HTTPException(status_code=500, detail=str(e))
3) .env file
SMTP_HOST=smtp.gmail.com
SMTP_PORT=587
SMTP_USER=your_email@gmail.com
SMTP_PASSWORD=your_app_password
FROM_EMAIL=your_email@gmail.com
4) Run the server
uvicorn main:app --reload
5) Test request
curl -X POST "http://127.0.0.1:8000/password-reset" \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com"}'
Important notes
- Use a real token stored in your database with an expiration time.
- Don’t expose whether the email exists; always return a generic response.
- Use HTTPS for the reset link.
- Prefer email providers like SendGrid, Mailgun, or AWS SES in production.
If you want, I can also give you:
- a Flask version,
- a version using SendGrid, or
- the full reset-password flow with token verification and database storage.