Skip to main content
Version: 1.28 (Current)

User Management

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, Users

The User Management actions in this group finish a password reset. They check the reset link that opened the page and save the user's new password. Both are part of Forms, so you can only use them in forms.

Most actions in the User Management group come from add-ons:

  • The User Management add-on creates accounts and signs users in, sends the reset password email, gives and takes away roles, authorizes, unlocks and deletes accounts, and changes usernames and profile data.
  • The Active Directory add-on signs users in with their Microsoft Active Directory account.
  • The OpenLDAP add-on signs users in with their account on an LDAP server.

Choosing an action​

ActionWhat it doesUse it to
Validate User Reset PasswordChecks the reset link that opened the page, and stops with a message if it's invalid or expired.Check the link in the reset form's On Init actions.
User Reset PasswordSets the new password, using the reset token in the page URL.Save the new password when the reset form is submitted.

The reset password flow​

Resetting a password takes three actions on two pages. The first one, Send User Reset Password Email, is part of the User Management add-on. The other two are in this group.

  1. Request the link. On a "Forgot password" form, Send User Reset Password Email creates a new reset token for the user and emails them a link to your reset page. The link carries the user ID and the token in its URL, as userId and resetToken. Each email replaces the user's previous token, so only the latest link works.
  2. Check the link. Put Validate User Reset Password in the On Init actions of the form on the reset page. If the token doesn't match the user, or it's expired, it shows Invalid password reset token. and stops, so the user doesn't fill in a form that can't work.
  3. Set the new password. On submit, User Reset Password checks that both passwords match and meet the site's password rules. Then it reads the token from the URL again and changes the password, if the token belongs to the username in the form and hasn't expired. The token is then cleared, so the link can't be used again.

None of the three actions create tokens. Use the actions that follow them, for example a Display Message, to tell the user what happened. For the details, see How the reset password flow works.

Building the reset page​

  • Use the page the email opens. Both actions read userId and resetToken from the page URL, so they only work on the reset page the link opens. Pick that page in Password Reset Page of Send User Reset Password Email, or in the application's Settings when you turn on Use Configured.
  • Ask for the username. The link contains the user ID, not the username. Add a field for it, such as an Email field when users sign in with their email address, and pass it to Username of User Reset Password.
  • Keep the check on submit. The token can expire between opening the page and submitting the form. User Reset Password checks it again, so you still need it even with Validate User Reset Password on On Init.
  • The user isn't signed in. To sign them in after the change, add User Login with the new password. It's part of the User Management add-on.
  • The messages don't reveal accounts. Validate User Reset Password shows the same message for every reason, and the last error of User Reset Password doesn't say whether the user, the token or the password history caused it. Send User Reset Password Email does fail for unknown accounts, so wrap it in Execute Actions on a public "Forgot password" form and show one general message.

To load users, see the Context actions. To create, change or delete roles, see the Security actions.

Revised 10/02/2026