Validate User Reset Password
Audience:
Low-code EngineersSkill Prerequisites:
Actions
Checks the password reset link that opened the current page. If the link isn't valid, it shows Invalid password reset token. and stops. If it's valid, the next actions run.
It's the second step of the reset password flow. See How the reset password flow works.
Typical Use Cases
- Check the link in the
On Initactions of the reset password form, before the user types a new password - Hide or replace the reset form when the link is old or has been used
Don't use it to
- Change the password. Use User Reset Password, which checks the token again.
- Check a username and password. Use User/Password Validation instead.
Related Actions
| Action Name | Description |
|---|---|
| Send User Reset Password Email | Sends the email with the reset link. |
| User Reset Password | Sets the new password using the token from the link. |
| Display Message | Shows a message instead of the form. |
Input Parameter Reference
This action has no parameters. It reads two values from the page URL:
| URL value | Description |
|---|---|
userId | The ID of the user who asked for the reset. |
resetToken | The reset token from the email link. |
The link sent by Send User Reset Password Email contains both.
Output Parameters Reference
This action doesn't create any tokens.
When the link is valid
The link is valid when:
- a user with that
userIdexists on the site, resetTokenis the user's current reset token, and- the token hasn't expired.
Otherwise, the action shows Invalid password reset token. and stops. The message is the same for every reason, so it doesn't reveal whether the user exists.
Considerations
- It needs the page URL. The action reads the query string, so it only works when a user opens the reset page. Without
userIdandresetToken, the link is always invalid. - Only the latest link works. Each email creates a new token and replaces the previous one. After the password is changed, the token is cleared.
- It doesn't replace the check on submit. The token can expire between opening the page and submitting the form. User Reset Password checks the token again when it changes the password.
Examples
To understand how to use the below examples, please see Running Examples.
1. Check the link when the reset form loads
Add this action to the On Init actions of the reset password form. If the link is invalid or expired, the user sees the error instead of filling in the form.
{
"Title": "Validate User Reset Password",
"ActionType": "ValidateResetPasswordToken",
"Description": "Stop if the reset link is invalid or expired",
"Parameters": {}
}
Revised 09/28/2026