Test end-to-end account recovery flows with real-time virtual email delivery. Initiating a password reset triggers an authentic HTML recovery email delivered straight into your isolated Virtual Mailbox without third-party email service credentials.
Execute the complete password reset lifecycle in 3 intuitive steps:
Submits the user email address. The backend generates a secure single-use recovery token and renders an email:
Navigate to the virtual mailbox to view the rendered HTML email template, extract the recovery token, or copy the direct password reset URL.
Submits the reset token from the email along with the updated password:
Critical defensive patterns modeled by the Playground API authentication gateway:
The /auth/forgot-password endpoint returns HTTP 200 regardless of whether the email exists, preventing user enumeration.
Reset tokens expire after 15 minutes. Once consumed to update a password, the token is permanently invalidated.
Upon successful password reset, all existing refresh token families and active sessions are revoked across all client devices.
Production-ready React 19 hooks and Next.js Server Action patterns: