Skip to main content
Version: 1.28 (Current)

Validate User Reset Password

Audience: Low-code Engineers

Skill Prerequisites: Actions

Checks the password reset link that opened the current page. If the link isn't valid, it shows Invalid password reset token. and stops. If it's valid, the next actions run.

It's the second step of the reset password flow. See How the reset password flow works.

Typical Use Cases​

  • Check the link in the On Init actions of the reset password form, before the user types a new password
  • Hide or replace the reset form when the link is old or has been used

Don't use it to​

Action NameDescription
Send User Reset Password EmailSends the email with the reset link.
User Reset PasswordSets the new password using the token from the link.
Display MessageShows a message instead of the form.

Input Parameter Reference​

This action has no parameters. It reads two values from the page URL:

URL valueDescription
userIdThe ID of the user who asked for the reset.
resetTokenThe reset token from the email link.

The link sent by Send User Reset Password Email contains both.

Output Parameters Reference​

This action doesn't create any tokens.

The link is valid when:

  • a user with that userId exists on the site,
  • resetToken is the user's current reset token, and
  • the token hasn't expired.

Otherwise, the action shows Invalid password reset token. and stops. The message is the same for every reason, so it doesn't reveal whether the user exists.

Considerations​

  • It needs the page URL. The action reads the query string, so it only works when a user opens the reset page. Without userId and resetToken, the link is always invalid.
  • Only the latest link works. Each email creates a new token and replaces the previous one. After the password is changed, the token is cleared.
  • It doesn't replace the check on submit. The token can expire between opening the page and submitting the form. User Reset Password checks the token again when it changes the password.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

Add this action to the On Init actions of the reset password form. If the link is invalid or expired, the user sees the error instead of filling in the form.

{
"Title": "Validate User Reset Password",
"ActionType": "ValidateResetPasswordToken",
"Description": "Stop if the reset link is invalid or expired",
"Parameters": {}
}

Revised 09/28/2026