[{"data":1,"prerenderedAt":447},["ShallowReactive",2],{"navigation":3,"\u002Fguides\u002Freset-password":203,"\u002Fguides\u002Freset-password-surround":442},[4,33,96,114,177],{"title":5,"path":6,"stem":7,"children":8,"icon":32},"Get started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Install AuthEndpoints","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F3.quick-start","i-lucide-play",{"title":23,"path":24,"stem":25,"icon":26},"Choose a sign-in stack","\u002Fgetting-started\u002Fchoose-a-sign-in-stack","1.getting-started\u002F4.choose-a-sign-in-stack","i-lucide-signpost",{"title":28,"path":29,"stem":30,"icon":31},"Use the AuthEndpoints skill with coding agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F5.ai-agents","i-lucide-bot","i-lucide-rocket",{"title":34,"path":35,"stem":36,"children":37,"icon":95},"Guides","\u002Fguides","2.guides\u002F01.index",[38,40,45,50,55,60,65,70,75,80,85,90],{"title":34,"path":35,"stem":36,"icon":39},"i-lucide-list-checks",{"title":41,"path":42,"stem":43,"icon":44},"Register users","\u002Fguides\u002Fregistration","2.guides\u002F02.registration","i-lucide-user-plus",{"title":46,"path":47,"stem":48,"icon":49},"Sign users in","\u002Fguides\u002Fsign-in","2.guides\u002F03.sign-in","i-lucide-log-in",{"title":51,"path":52,"stem":53,"icon":54},"Sign users out","\u002Fguides\u002Fsign-out","2.guides\u002F04.sign-out","i-lucide-log-out",{"title":56,"path":57,"stem":58,"icon":59},"Turn on two-factor authentication","\u002Fguides\u002Ftwo-factor","2.guides\u002F05.two-factor","i-lucide-smartphone",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fguides\u002Freset-password","2.guides\u002F06.reset-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Change a user's email or password","\u002Fguides\u002Fmanage-account","2.guides\u002F07.manage-account","i-lucide-user-cog",{"title":71,"path":72,"stem":73,"icon":74},"Add, rename, and remove passkeys","\u002Fguides\u002Fmanage-passkeys","2.guides\u002F08.manage-passkeys","i-lucide-scan-face",{"title":76,"path":77,"stem":78,"icon":79},"Link and unlink GitHub or Google accounts","\u002Fguides\u002Flink-external-accounts","2.guides\u002F09.link-external-accounts","i-lucide-link",{"title":81,"path":82,"stem":83,"icon":84},"Require step-up before sensitive actions","\u002Fguides\u002Fstep-up","2.guides\u002F10.step-up","i-lucide-shield-check",{"title":86,"path":87,"stem":88,"icon":89},"Call the API from a browser","\u002Fguides\u002Fbrowser-clients","2.guides\u002F11.browser-clients","i-lucide-globe",{"title":91,"path":92,"stem":93,"icon":94},"Prepare for production","\u002Fguides\u002Fproduction","2.guides\u002F12.production","i-lucide-factory","i-lucide-waypoints",{"title":97,"path":98,"stem":99,"children":100,"icon":113},"Composable endpoints","\u002Fcomposables","3.composables\u002F1.index",[101,104,108],{"title":102,"path":98,"stem":99,"icon":103},"How composition works","i-lucide-layout-grid",{"title":105,"path":106,"stem":107,"icon":39},"Composition requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements",{"title":109,"path":110,"stem":111,"icon":112},"Compose a custom auth stack","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":115,"icon":116,"path":117,"stem":118,"children":119,"page":176},"Reference","i-lucide-book-open","\u002Fmodules","4.modules",[120,125,129,134,139,144,148,153,157,162,166,171],{"title":121,"path":122,"stem":123,"icon":124},"Endpoint reference","\u002Fmodules\u002Fendpoints","4.modules\u002F01.endpoints","i-lucide-route",{"title":126,"path":127,"stem":128,"icon":69},"Identity management module","\u002Fmodules\u002Fidentity-management","4.modules\u002F02.identity-management",{"title":130,"path":131,"stem":132,"icon":133},"Cookie sign-in module","\u002Fmodules\u002Fcookie-auth","4.modules\u002F03.cookie-auth","i-lucide-cookie",{"title":135,"path":136,"stem":137,"icon":138},"Identity bearer sign-in module","\u002Fmodules\u002Fbearer-auth","4.modules\u002F04.bearer-auth","i-lucide-key",{"title":140,"path":141,"stem":142,"icon":143},"JWT module","\u002Fmodules\u002Fjwt","4.modules\u002F05.jwt","i-lucide-fingerprint",{"title":145,"path":146,"stem":147,"icon":74},"Passkeys module","\u002Fmodules\u002Fpasskeys","4.modules\u002F06.passkeys",{"title":149,"path":150,"stem":151,"icon":152},"ReAuth module","\u002Fmodules\u002Freauth","4.modules\u002F07.reauth","i-lucide-shield-alert",{"title":154,"path":155,"stem":156,"icon":49},"External OAuth packages","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F08.external-oauth",{"title":158,"path":159,"stem":160,"icon":161},"Configuration options","\u002Fmodules\u002Fconfiguration","4.modules\u002F09.configuration","i-lucide-settings",{"title":163,"path":164,"stem":165,"icon":84},"Antiforgery (CSRF) rules","\u002Fmodules\u002Fcsrf","4.modules\u002F10.csrf",{"title":167,"path":168,"stem":169,"icon":170},"Responses and errors","\u002Fmodules\u002Ferrors","4.modules\u002F11.errors","i-lucide-circle-alert",{"title":172,"path":173,"stem":174,"icon":175},"Rate-limit policies","\u002Fmodules\u002Frate-limits","4.modules\u002F12.rate-limits","i-lucide-gauge",false,{"title":178,"icon":179,"path":180,"stem":181,"children":182,"page":176},"Concepts","i-lucide-lightbulb","\u002Fconcepts","5.concepts",[183,188,193,198],{"title":184,"path":185,"stem":186,"icon":187},"AuthEndpoints compared with other options","\u002Fconcepts\u002Fcompare","5.concepts\u002F1.compare","i-lucide-git-compare",{"title":189,"path":190,"stem":191,"icon":192},"Stock Identity endpoints vs AuthEndpoints","\u002Fconcepts\u002Fstock-identity-vs-authendpoints","5.concepts\u002F2.stock-identity-vs-authendpoints","i-lucide-columns-2",{"title":194,"path":195,"stem":196,"icon":197},"Security model","\u002Fconcepts\u002Fsecurity-model","5.concepts\u002F3.security-model","i-lucide-shield",{"title":199,"path":200,"stem":201,"icon":202},"FAQ","\u002Fconcepts\u002Ffaq","5.concepts\u002F4.faq","i-lucide-circle-help",{"id":204,"title":61,"body":205,"description":435,"extension":436,"links":437,"meta":438,"navigation":439,"path":62,"seo":440,"stem":63,"__hash__":441},"docs\u002F2.guides\u002F06.reset-password.md",{"type":206,"value":207,"toc":421},"minimark",[208,217,239,244,249,253,334,340,345,363,366,370,386,400,404],[209,210,211,212,216],"p",{},"Use these steps when a user forgot their password. The routes are on the management group (facade default ",[213,214,215],"code",{},"\u002Fidentity","). They need no CSRF token and no session.",[209,218,219,222,223,226,227,230,231,234,235,238],{},[213,220,221],{},"POST \u002Fidentity\u002FforgotPassword"," always returns ",[213,224,225],{},"200",". AuthEndpoints sends mail only when the account exists and its email is confirmed. It calls ",[213,228,229],{},"IEmailSender\u003CTUser>.SendPasswordResetCodeAsync"," with an HTML-encoded Base64Url reset code. You build the reset screen and the mail template. The reset body is Identity's ",[213,232,233],{},"ResetPasswordRequest",": ",[213,236,237],{},"{ \"email\", \"resetCode\", \"newPassword\" }",".",[240,241,243],"h2",{"id":242},"video","Video",[245,246],"youtube-embed",{"id":247,"title":248},"_3wSxAQ9588","Forgot password and reset password",[240,250,252],{"id":251},"steps","Steps",[254,255,256,265,273,283,298,304,312,321],"ol",{},[257,258,259,260,264],"li",{},"Collect the account email on a ",[261,262,263],"strong",{},"Forgot password"," screen.",[257,266,267,269,270,238],{},[213,268,221],{}," with body ",[213,271,272],{},"{ \"email\" }",[257,274,275,276,278,279,282],{},"On ",[213,277,225],{},", show ",[261,280,281],{},"Check your email"," (same copy for known and unknown addresses). Then use one of the host patterns below for the reset screen.",[257,284,285,286,289,290,293,294,297],{},"Build the reset mail in your ",[213,287,288],{},"IEmailSender\u003CTUser>"," implementation. AuthEndpoints passes ",[213,291,292],{},"HtmlEncoder.Default.Encode(base64UrlCode)"," into ",[213,295,296],{},"SendPasswordResetCodeAsync",". Decode HTML entities before the user copies the code or before you put it in a link query. If you embed the code in HTML again, re-encode for markup.",[257,299,300,301,264],{},"Collect email, reset code, and new password on a ",[261,302,303],{},"Reset password",[257,305,306,269,309,311],{},[213,307,308],{},"POST \u002Fidentity\u002FresetPassword",[213,310,237],{},". Submit the Base64Url value (not the Identity raw token).",[257,313,275,314,316,317,238],{},[213,315,225],{},", sign in with the new password. See ",[318,319,46],"a",{"href":320},"\u002Fguides\u002Fsign-in\u002F",[257,322,275,323,326,327,330,331,238],{},[213,324,325],{},"400"," validation problem ",[213,328,329],{},"InvalidToken",", show a generic error. AuthEndpoints returns that code for a bad code, an unknown email, and an unconfirmed email alike. Password-rule failures return their own codes, such as ",[213,332,333],{},"PasswordTooShort",[240,335,337,338],{"id":336},"host-patterns-after-forgot-200","Host patterns after forgot ",[213,339,225],{},[341,342,344],"h3",{"id":343},"same-session-auto-nav-safer-default","Same-session auto-nav (safer default)",[209,346,347,348,350,351,354,355,358,359,362],{},"After forgot returns ",[213,349,225],{},", navigate the SPA to the reset page with ",[261,352,353],{},"email only"," prefilled (query string or ",[213,356,357],{},"sessionStorage","). The user pastes ",[213,360,361],{},"resetCode"," from the mail.",[209,364,365],{},"No reset token in the URL. Fits the same browser that started forgot.",[341,367,369],{"id":368},"email-deep-link-cross-device","Email deep link (cross-device)",[209,371,372,373,375,376,379,380,382,383,385],{},"In ",[213,374,296],{},", include a host-owned link to your reset page with ",[213,377,378],{},"email"," and ",[213,381,361],{}," (or ",[213,384,213],{},") query params. Still show the code in the mail as a paste fallback.",[209,387,388,389,391,392,395,396,399],{},"Stock forgot uses ",[213,390,296],{},", not ",[213,393,394],{},"SendPasswordResetLinkAsync",". A clickable link is entirely your mail template (or a custom pipeline you build). Query tokens can leak through history, ",[213,397,398],{},"Referer",", and logs. Prefer same-session auto-nav when the user resets on the same device.",[240,401,403],{"id":402},"related","Related",[405,406,407,411,416],"ul",{},[257,408,409],{},[318,410,46],{"href":320},[257,412,413],{},[318,414,41],{"href":415},"\u002Fguides\u002Fregistration\u002F",[257,417,418],{},[318,419,126],{"href":420},"\u002Fmodules\u002Fidentity-management\u002F",{"title":422,"searchDepth":423,"depth":424,"links":425},"",1,2,[426,427,428,434],{"id":242,"depth":424,"text":243},{"id":251,"depth":424,"text":252},{"id":336,"depth":424,"text":429,"children":430},"Host patterns after forgot 200",[431,433],{"id":343,"depth":432,"text":344},3,{"id":368,"depth":432,"text":369},{"id":402,"depth":424,"text":403},"Request a reset mail, set a new password, then sign in.","md",null,{},{"icon":64},{"title":61,"description":435},"sDd6PeT15aiH91hEIHI7J-90XMyMst9LTB0pQaKWioU",[443,445],{"title":56,"path":57,"stem":58,"description":444,"icon":59,"children":-1},"Turn authenticator two-factor authentication on and off, and issue recovery codes.",{"title":66,"path":67,"stem":68,"description":446,"icon":69,"children":-1},"Read account info, change the password, and change the email after the user confirms the new address.",1791123626752]