Skip to main content
Version: 1.28 (Current)

User Reset Password

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

Sets a new password for a user, using the reset token from the link in the reset password email. Use it on the submit of the reset password form.

It's the last step of the reset password flow. See How the reset password flow works.

Typical Use Cases​

  • Save the new password on a reset password page opened from the reset email

Don't use it to​

  • Send the reset link. Use Send User Reset Password Email instead.
  • Change the password of a logged-in user who knows their current password. This action only works with a reset token in the page URL.
  • Unlock a locked-out account. Use Unlock User instead.
Action NameDescription
Send User Reset Password EmailSends the email with the reset link.
Validate User Reset PasswordChecks the reset link when the page opens.
User LoginLogs the user in, for example with the new password.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
UsernameThe username of the user whose password changes, for example [Email] when users sign in with their email address. The reset token must belong to this user.Yesempty stringYes
New PasswordThe new password, for example [NewPassword].Yesempty stringYes
Repeat PasswordThe new password again, for example [RepeatPassword]. It must be exactly the same as New Password.Yesempty stringYes

The reset token isn't a parameter. The action reads it from resetToken in the page URL.

Output Parameters Reference​

This action doesn't create any tokens. If it succeeds, the next actions run. If it fails, it shows an error and stops.

Errors​

The checks run in this order. The first one that fails shows its message and stops execution.

CheckMessage
New Password and Repeat Password are the samePasswords does not match!
The new password meets the site's password rules, such as minimum length and required special charactersThe site's invalid password message
The user exists, the token from the URL is the user's current token and hasn't expired, and the password is acceptedFailed to change the password. The user might not exist, the password had been used before or the password reset token is invalid.

After a successful change, the token is cleared, so the same link can't be used again.

Considerations​

  • It needs the reset link in the URL. Put the form on the page the email link opens. If resetToken is missing, the change fails.
  • Ask for the username. The link contains the user ID, not the username, so add a field for it, such as an Email field when users sign in with their email address.
  • The last error is general. It doesn't say whether the user, the token or the password history caused the failure. This keeps the action from revealing which usernames exist.
  • Check the link first. Add Validate User Reset Password to the form's On Init actions, so users with an expired link find out before they type a new password.
  • The user isn't logged in. To log them in afterwards, add User Login with the new password.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Save the new password​

This action runs on submit of a reset form with Email, NewPassword and RepeatPassword fields. Follow it with a Display Message that tells the user the password was changed.

{
"Title": "User Reset Password",
"ActionType": "ResetPassword",
"Description": "Set the new password from the reset form",
"Parameters": {
"Username": "[Email]",
"NewPassword": "[NewPassword]",
"RepeatPassword": "[RepeatPassword]"
}
}

Revised 09/28/2026