User Reset Password
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
Sets a new password for a user, using the reset token from the link in the reset password email. Use it on the submit of the reset password form.
It's the last step of the reset password flow. See How the reset password flow works.
Typical Use Cases
- Save the new password on a reset password page opened from the reset email
Don't use it to
- Send the reset link. Use Send User Reset Password Email instead.
- Change the password of a logged-in user who knows their current password. This action only works with a reset token in the page URL.
- Unlock a locked-out account. Use Unlock User instead.
Related Actions
| Action Name | Description |
|---|---|
| Send User Reset Password Email | Sends the email with the reset link. |
| Validate User Reset Password | Checks the reset link when the page opens. |
| User Login | Logs the user in, for example with the new password. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Username | The username of the user whose password changes, for example [Email] when users sign in with their email address. The reset token must belong to this user. | Yes | empty string | Yes |
| New Password | The new password, for example [NewPassword]. | Yes | empty string | Yes |
| Repeat Password | The new password again, for example [RepeatPassword]. It must be exactly the same as New Password. | Yes | empty string | Yes |
The reset token isn't a parameter. The action reads it from resetToken in the page URL.
Output Parameters Reference
This action doesn't create any tokens. If it succeeds, the next actions run. If it fails, it shows an error and stops.
Errors
The checks run in this order. The first one that fails shows its message and stops execution.
| Check | Message |
|---|---|
New Password and Repeat Password are the same | Passwords does not match! |
| The new password meets the site's password rules, such as minimum length and required special characters | The site's invalid password message |
| The user exists, the token from the URL is the user's current token and hasn't expired, and the password is accepted | Failed to change the password. The user might not exist, the password had been used before or the password reset token is invalid. |
After a successful change, the token is cleared, so the same link can't be used again.
Considerations
- It needs the reset link in the URL. Put the form on the page the email link opens. If
resetTokenis missing, the change fails. - Ask for the username. The link contains the user ID, not the username, so add a field for it, such as an
Emailfield when users sign in with their email address. - The last error is general. It doesn't say whether the user, the token or the password history caused the failure. This keeps the action from revealing which usernames exist.
- Check the link first. Add Validate User Reset Password to the form's
On Initactions, so users with an expired link find out before they type a new password. - The user isn't logged in. To log them in afterwards, add User Login with the new password.
Examples
To understand how to use the below examples, please see Running Examples.
1. Save the new password
This action runs on submit of a reset form with Email, NewPassword and RepeatPassword fields. Follow it with a Display Message that tells the user the password was changed.
{
"Title": "User Reset Password",
"ActionType": "ResetPassword",
"Description": "Set the new password from the reset form",
"Parameters": {
"Username": "[Email]",
"NewPassword": "[NewPassword]",
"RepeatPassword": "[RepeatPassword]"
}
}
Revised 09/28/2026