Short-lived token
Reset links expire quickly and can only be used once.
Password recovery uses a short-lived email link so accounts can be restored without exposing whether an email exists.
Reset links expire quickly and can only be used once.
The flow avoids account enumeration by returning a neutral success message.
After changing the password, the user returns to login with the new credentials.
Enter your account email and we will send a secure reset link.