[{"data":1,"prerenderedAt":290},["ShallowReactive",2],{"navigation":3,"\u002Fexamples\u002Freset-forgotten-password":139,"\u002Fexamples\u002Freset-forgotten-password-surround":285},[4,48,79,98],{"title":5,"path":6,"stem":7,"children":8,"icon":47},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22,27,32,37,42],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"AI agents","\u002Fgetting-started\u002Fai-agents","1.getting-started\u002F3.ai-agents","i-lucide-bot",{"title":23,"path":24,"stem":25,"icon":26},"Quick start","\u002Fgetting-started\u002Fquick-start","1.getting-started\u002F4.quick-start","i-lucide-play",{"title":28,"path":29,"stem":30,"icon":31},"Configuration","\u002Fgetting-started\u002Fconfiguration","1.getting-started\u002F5.configuration","i-lucide-settings",{"title":33,"path":34,"stem":35,"icon":36},"Production","\u002Fgetting-started\u002Fproduction","1.getting-started\u002F6.production","i-lucide-shield-check",{"title":38,"path":39,"stem":40,"icon":41},"Compare","\u002Fgetting-started\u002Fcompare","1.getting-started\u002F7.compare","i-lucide-git-compare",{"title":43,"path":44,"stem":45,"icon":46},"FAQ","\u002Fgetting-started\u002Ffaq","1.getting-started\u002F8.faq","i-lucide-circle-help","i-lucide-rocket",{"title":49,"path":50,"stem":51,"children":52,"icon":54},"Examples","\u002Fexamples","2.examples\u002F1.index",[53,55,60,65,70,74],{"title":49,"path":50,"stem":51,"icon":54},"i-lucide-waypoints",{"title":56,"path":57,"stem":58,"icon":59},"Register a confirmed account","\u002Fexamples\u002Fregister-confirmed-account","2.examples\u002F2.register-confirmed-account","i-lucide-mail-check",{"title":61,"path":62,"stem":63,"icon":64},"Reset a forgotten password","\u002Fexamples\u002Freset-forgotten-password","2.examples\u002F3.reset-forgotten-password","i-lucide-key-round",{"title":66,"path":67,"stem":68,"icon":69},"Enable and disable two-factor authentication","\u002Fexamples\u002Ftwo-factor","2.examples\u002F4.two-factor","i-lucide-smartphone",{"title":71,"path":72,"stem":73,"icon":36},"Complete step-up (ReAuth)","\u002Fexamples\u002Freauth","2.examples\u002F5.reauth",{"title":75,"path":76,"stem":77,"icon":78},"Sign in with a passkey","\u002Fexamples\u002Fpasskey-sign-in","2.examples\u002F6.passkey-sign-in","i-lucide-fingerprint",{"title":80,"path":81,"stem":82,"children":83,"icon":97},"Composable Endpoints","\u002Fcomposables","3.composables\u002F1.index",[84,87,92],{"title":85,"path":81,"stem":82,"icon":86},"Overview","i-lucide-layout-grid",{"title":88,"path":89,"stem":90,"icon":91},"Requirements","\u002Fcomposables\u002Frequirements","3.composables\u002F2.requirements","i-lucide-list-checks",{"title":93,"path":94,"stem":95,"icon":96},"Recipes","\u002Fcomposables\u002Frecipes","3.composables\u002F3.recipes","i-lucide-book-marked","i-lucide-blocks",{"title":99,"icon":100,"path":101,"stem":102,"children":103,"page":138},"Modules","i-lucide-package","\u002Fmodules","4.modules",[104,109,114,119,123,128,133],{"title":105,"path":106,"stem":107,"icon":108},"Identity management","\u002Fmodules\u002Fidentity-management","4.modules\u002F1.identity-management","i-lucide-user-cog",{"title":110,"path":111,"stem":112,"icon":113},"Cookie auth","\u002Fmodules\u002Fcookie-auth","4.modules\u002F2.cookie-auth","i-lucide-cookie",{"title":115,"path":116,"stem":117,"icon":118},"Bearer auth","\u002Fmodules\u002Fbearer-auth","4.modules\u002F3.bearer-auth","i-lucide-key",{"title":120,"path":121,"stem":122,"icon":78},"JWT","\u002Fmodules\u002Fjwt","4.modules\u002F4.jwt",{"title":124,"path":125,"stem":126,"icon":127},"Passkeys","\u002Fmodules\u002Fpasskeys","4.modules\u002F5.passkeys","i-lucide-scan-face",{"title":129,"path":130,"stem":131,"icon":132},"ReAuth","\u002Fmodules\u002Freauth","4.modules\u002F6.reauth","i-lucide-shield-alert",{"title":134,"path":135,"stem":136,"icon":137},"External OAuth","\u002Fmodules\u002Fexternal-oauth","4.modules\u002F7.external-oauth","i-lucide-log-in",false,{"id":140,"title":61,"body":141,"description":278,"extension":279,"links":280,"meta":281,"navigation":282,"path":62,"seo":283,"stem":63,"__hash__":284},"docs\u002F2.examples\u002F3.reset-forgotten-password.md",{"type":142,"value":143,"toc":271},"minimark",[144,157,162,249,252,256],[145,146,147,148,152,153,156],"p",{},"Recover access when the user forgot the password. Routes sit on the management group (facade default ",[149,150,151],"code",{},"\u002Fidentity","). Mail is sent only for a confirmed account. The forgot endpoint always returns ",[149,154,155],{},"200",".",[158,159,161],"h2",{"id":160},"steps","Steps",[163,164,165,174,183,193,203,210,218,238],"ol",{},[166,167,168,169,173],"li",{},"Collect the account email on a ",[170,171,172],"strong",{},"Forgot password"," screen.",[166,175,176,179,180,156],{},[149,177,178],{},"POST \u002Fidentity\u002FforgotPassword"," with body ",[149,181,182],{},"{ \"email\" }",[166,184,185,186,188,189,192],{},"On ",[149,187,155],{},", show ",[170,190,191],{},"Check your email"," (same copy for known and unknown addresses).",[166,194,195,196,199,200,156],{},"The reset mail carries a Base64Url-encoded reset code. ",[149,197,198],{},"IEmailSender\u003CTUser>.SendPasswordResetCodeAsync"," receives an HTML-encoded Base64Url string (hosts that put the code in an HTML mail should decode entities before the user copies it, or use a link query the host owns). The client submits the Base64Url value as ",[149,201,202],{},"resetCode",[166,204,205,206,209],{},"Collect email, reset code, and new password on a ",[170,207,208],{},"Reset password"," screen (or deep link that fills email and code).",[166,211,212,179,215,156],{},[149,213,214],{},"POST \u002Fidentity\u002FresetPassword",[149,216,217],{},"{ \"email\", \"resetCode\", \"newPassword\" }",[166,219,185,220,222,223,226,227,230,231,234,235,156],{},[149,221,155],{},", sign in with the new password: ",[149,224,225],{},"POST \u002Fidentity\u002Flogin"," (",[149,228,229],{},"LoginCookie","). Persistent cookie: ",[149,232,233],{},"?useSessionCookies=false",". See ",[236,237,110],"a",{"href":111},[166,239,240,241,244,245,248],{},"On invalid or unknown token or user, expect ",[149,242,243],{},"400"," validation problem (for example ",[149,246,247],{},"InvalidToken","). Do not reveal whether the email exists from the forgot step.",[145,250,251],{},"Forgot and reset do not require antiforgery or a session.",[158,253,255],{"id":254},"related","Related",[257,258,259,263,267],"ul",{},[166,260,261],{},[236,262,105],{"href":106},[166,264,265],{},[236,266,110],{"href":111},[166,268,269],{},[236,270,56],{"href":57},{"title":272,"searchDepth":273,"depth":274,"links":275},"",1,2,[276,277],{"id":160,"depth":274,"text":161},{"id":254,"depth":274,"text":255},"Request a reset mail, set a new password, then sign in.","md",null,{},{"icon":64},{"title":61,"description":278},"UpumHvqygmbtWVUTWhD4qfeiLKZfdcC1bhU_0kpANU8",[286,288],{"title":56,"path":57,"stem":58,"description":287,"icon":59,"children":-1},"SPA password and passkey signup when RequireConfirmedAccount is true.",{"title":66,"path":67,"stem":68,"description":289,"icon":69,"children":-1},"Turn authenticator 2FA on or off with CSRF and ReAuth.",1789052353130]