Skip to main content
POST
Reset Password
Resets a user’s password using the token sent to their email via the forgot password endpoint. This completes the password recovery process.

Authentication

No authentication required.

Request Body

string
required
Password reset token sent to the user’s email address. This token is typically included in the password reset link.
string
required
New password for the account. Should meet security requirements (minimum 8 characters recommended).

Response

string
Success message confirming the password has been reset.

Example Request

Example Response

Error Responses

string
Error type identifier.
string
Human-readable error message.

Common Errors

400 Bad Request
400 Bad Request
400 Bad Request

Notes

  • Password reset tokens typically expire after 1 hour
  • Once a token is used successfully, it becomes invalid
  • After resetting the password, users should log in with their new credentials
  • For security, all active sessions are terminated when the password is reset
  • The new password cannot be the same as the old password