Skip to content

Issue a one-time password reset link

POST
/users/{userId}/password-reset
curl --request POST \
--url https://example.com/api/v1/users/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/password-reset \
--cookie __Host-shardkeep_session=<__Host-shardkeep_session>

Returns the link’s secret, once, to hand to the user. It is valid for 24 hours and works once (POST /auth/password-reset).

userId
required
string format: uuid

Link issued.

Media typeapplication/json
object
token
required

The link’s secret, skr_…. Shown only once.

string
expiresAt
required
string format: date-time
Examplegenerated
{
"token": "example",
"expiresAt": "2026-04-15T12:00:00Z"
}

Not signed in, or the credentials are invalid.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Signed in, but not allowed.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Not found, or not visible to you.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}