Skip to content

Send Password Reset Email ​

Sends a password reset link to the user's email. The user completes the reset flow on your frontend.

Bot Protection

This endpoint requires a valid Cloudflare Turnstile token when bot protection is enabled. See the Turnstile Integration Guide for frontend setup instructions.

HTTP Request ​

POST /api/v1/auth/password/email

ParameterDescription
email stringUser's email address
turnstileToken stringCloudflare Turnstile verification token.

Response ​

202 Accepted

json
{
  "data": {
    "message": "We have emailed your password reset link."
  }
}

Frontend Integration ​

An email is sent containing a link, for example:

plaintext
https://brunago.sk/reset-password?token={token}&email={encodedEmail}

You can customize the reset-password path. Replace {token} and {encodedEmail} with actual values from the email.

The token is valid for 60 minutes. At most one reset email is sent per user per minute — repeated requests within that window still return 202 Accepted but send nothing.

Error Handling ​

422 Unprocessable Content — email is missing or invalid, or the Turnstile token is invalid.

429 Too Many Requests — more than 5 requests per minute from one IP address.

If the user's email doesn't exist, the endpoint still returns:

202 Accepted

json
{
  "data": {
    "message": "We have emailed your password reset link."
  }
}