Skip to main content

completeForgotPassword

Resets a forgotten password using the token sent by email.

Business Rules​

  • The caller must not be logged in.
  • The token must be valid, unused, and within the reset window.
  • The new password must meet the rules returned by passwordRules, including character length and UTF-8 byte size limits.
  • A successful reset replaces the password, consumes the token, and verifies the primary email address.

Error Scenarios​

  • Already logged in: the caller has an active session.
  • E0004: the token is invalid, expired, or already used.
  • E0004: the password breaks one or more password rules or cannot be saved.

Permissions Required​

  • No session is required. A valid reset token authorizes the password reset.
completeForgotPassword(
input: CompleteForgotPasswordInput!
): CompleteForgotPasswordPayload!

Arguments​

completeForgotPassword.input ● CompleteForgotPasswordInput! non-null input common​

Parameters for CompleteForgotPassword

Type​

CompleteForgotPasswordPayload object common​

Autogenerated return type of CompleteForgotPassword.