Sets a new password using the emailed reset token and the email, then sends a password-changed email. Always answers 200: an unknown or expired token comes back with isSuccess: false and the error message.
POST
/auth/reset-password
curl \
--request POST 'http://api.example.com/auth/reset-password' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"email": "string",
"newPassword": "string",
"resetToken": "string"
}'
Request examples
{
"email": "string",
"newPassword": "string",
"resetToken": "string"
}
Response examples (200)
{
"data": {
"message": "Done",
"isSuccess": true
},
"statusCode": 200,
"timestamp": "2026-01-15T10:15:00.000Z"
}