Reset password with token
/v1/auth/reset-passwordPublic endpoint that completes a password reset using the emailed token and a new password. Rate-limited to 5 per hour; the token must be unredeemed and within its one-hour expiry or 400 is returned. The new password is breach-checked and rejected if it matches any of the last 5 passwords, then argon2id-hashed; on success the failed-attempt lockout is cleared and all of the user's refresh tokens are revoked, forcing re-login everywhere.
Request body
application/json
tokenstring Required Password reset token
passwordstring Required New password (8-128 chars, must contain uppercase, lowercase, digit, and special character)
Responses
application/json
data *MessageResponseDto
Returned object
curl -X POST "https://auth.canopy-io.com/v1/auth/reset-password" \ -H "Content-Type: application/json" \ -d '{ "token": "string", "password": "string" }'
{ "data": { "message": "string" } }
Tell us how we can improve this guide.