Skip to main content
Version: 1.28 (Current)

Send User Reset Password Email

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, HTML

Sends a user an email with a link to reset their password. The action creates a new reset token for the user, builds a link to your reset password page, and sends the email from the site's mail server.

This page also explains the whole reset password flow. See How the reset password flow works.

Typical Use Cases​

  • A "Forgot password" form where the user enters their email address
  • A Listing button that lets an administrator send a reset link to a selected user
  • A workflow that sends a reset link to users created by an import

Don't use it to​

Action NameDescription
Validate User Reset PasswordChecks the reset link when the reset page opens.
User Reset PasswordSets the new password using the token from the link.
User/Password ValidationChecks a username and password without logging the user in.
Unlock UserUnlocks an account locked by too many failed logins.
User LoginLogs the user in.
User RegistrationCreates a new user.
Send EmailSends a general email.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
Identifier FieldThe user to send the email to. It can be a user ID, a username or an email address, for example [Email] or [QueryString:UserId]. A whole number is treated as a user ID. Otherwise the action looks for a user with that email, then for a user with that username. In forms and listings, you pick a field or write an expression.Yesempty stringYes
Use ConfiguredUses the Password Reset Page set in the application's Settings instead of the page below.NofalseNo
Password Reset PageThe page the link in the email opens. Pick a page, or use an expression with a page ID or a relative page path, for example /reset-password. Shown only when Use Configured is off.Yesempty stringYes, unless Use Configured is on
Sender EmailThe address the email is sent from. Leave it empty to use the site's email address, with the site administrator's display name as the sender name.Yesempty stringNo
Template SourceDefault uses the site's built-in password reminder email. Custom uses the subject and body below.YesDefaultNo
Template SubjectThe email subject. Shown only when Template Source is Custom. [User:*] tokens refer to the user receiving the email, and [Portal:*] tokens to the current site.Yesempty stringNo
Template BodyThe email body. Shown only when Template Source is Custom. Put [PasswordResetUri] where the reset link should go. [User:*] tokens refer to the user receiving the email.Yesempty stringNo
HTML email bodySends the body as HTML. Turn it on if your template contains HTML tags.NofalseNo

Output Parameters Reference​

This action doesn't create any tokens. [PasswordResetUri] exists only inside the email subject and body.

How the reset password flow works​

Resetting a password takes three actions on two pages.

On a "Forgot password" form, Send User Reset Password Email finds the user and asks the platform for a new reset token. The token is a random GUID. It's saved on the user with an expiry time. The site's reset link timeout setting decides how long the token lasts.

Each time the action runs, it creates a new token, so an older link for the same user stops working.

The link in the email looks like this:

https://<your site>/<reset page>?resetToken=<token>&userId=<user ID>

It points to the page in Password Reset Page, or to the page set in the application's Settings when Use Configured is on. That page must contain a form with the actions below.

When the reset page opens, Validate User Reset Password reads userId and resetToken from the URL. If the token doesn't match the user, or it's expired, it shows Invalid password reset token. and stops. Put it in the form's On Init actions, so the user doesn't fill in a form that can't work.

3. Set the new password​

The user enters their username, a new password and the password again. On submit, User Reset Password:

  1. Checks that both passwords match.
  2. Checks the new password against the site's password rules, such as the minimum length.
  3. Reads resetToken from the URL again and changes the password, if the token belongs to that username and hasn't expired.

If any step fails, the action shows an error and stops. After the password changes, the token is cleared, so the link can't be used again.

None of the three actions create tokens. Use the actions that follow them, for example a Display Message, to tell the user what happened.

The email​

With Template Source set to Default, the action uses the site's built-in password reminder subject and body. Links in that template that point to the site's own reset page are replaced with the link to your reset page.

With Custom, add [PasswordResetUri] to the body. It's replaced with the full link. If you leave it out, the email has no link.

Tokens in the subject and body are replaced as if the receiving user were the current user. So [User:DisplayName] is the name of the user who gets the email, not the user who submitted the form. Form tokens, such as [Email], still work.

The email is sent with high priority, using the site's SMTP settings.

Considerations​

  • It shows whether an account exists. If no user matches the identifier, or the user has no email address, the action fails. End users see Failed to send the reset password email., and administrators see Could not find user: <identifier>. A different result for known and unknown addresses lets someone test which emails have accounts. To avoid this, run the action inside Execute Actions, and show the same message in both cases, for example "If an account exists for this address, we've sent a reset link."
  • Anyone who can submit the form can send the email. The action doesn't check who is running it. Each run sends another email and replaces the user's earlier token. Consider a CAPTCHA on a public "Forgot password" form. Only point Identifier Field at a value the user is allowed to choose, such as their own email address.
  • Choose a reset page. If Use Configured is off and Password Reset Page is empty, or the page isn't found, the action fails. A relative path matches the first page whose URL ends with it, so use a full path or a page ID.
  • The site needs an email address and an administrator. If Sender Email is empty and the site has no email address set, the action fails. The action also fails if the site has no Site Administrator set, even when Sender Email is filled in.
  • SMTP errors fail the action. If the mail server rejects the email, the action fails with Something went wrong. Please contact the site administrator if the problem persists. for end users. The token has already been replaced at that point.
  • Check the link protocol. If the reset page URL isn't stored as an absolute URL, the link uses https only when the page is marked as secure.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Forgot password form​

This action sends the default reset email to the user whose email address is in the Email field. The link opens the reset page set in the application's Settings.

{
"Title": "Send User Reset Password Email",
"ActionType": "SendResetPassword",
"Description": "Email a reset link to the address in the Email field",
"Parameters": {
"IdentifierField": {
"Expression": "[Email]",
"Value": "",
"IsExpression": true,
"Parameters": {}
},
"UseConfiguredResetPasswordPage": true,
"SenderEmail": "",
"TemplateSource": {
"Expression": "",
"Value": "Default",
"IsExpression": false,
"Parameters": {}
},
"HTMLBody": false
}
}

2. Custom HTML email from a workflow​

This action runs in a workflow for the user in the UserId token. It sends a custom HTML email from a no-reply address, with a link to the /reset-password page.

{
"Title": "Send User Reset Password Email",
"ActionType": "SendResetPassword",
"Description": "Send a custom reset email",
"Parameters": {
"IdentifierField": "[UserId]",
"UseConfiguredResetPasswordPage": false,
"ResetPasswordPage": {
"Expression": "/reset-password",
"Value": "",
"IsExpression": true,
"Parameters": {}
},
"SenderEmail": "no-reply@example.com",
"TemplateSource": {
"Expression": "",
"Value": "Custom",
"IsExpression": false,
"Parameters": {}
},
"TemplateSubject": "Reset your [Portal:PortalName] password",
"TemplateBody": "<p>Hi [User:FirstName],</p><p>To choose a new password, open this link:</p><p><a href=\"[PasswordResetUri]\">Reset my password</a></p><p>If you didn't ask for this, you can ignore this email.</p>",
"HTMLBody": true
}
}

Revised 09/28/2026