Email a password-reset link if the account exists
Header Parameters
The site key identifying which website this request belongs to. May be omitted only when the request comes from a domain already verified for the site (the Origin/Host then resolves it), or when the deprecated X-Subdomain header is used.
Publishable (pk_…) or secret (sk_…) key for this site. Required on writes; accepted on reads. NOTE: currently rolling out in monitor mode — a write without a valid key is logged rather than refused, so this is documented as optional. It becomes required on writes when enforcement is switched on; send it now.
A solved Cloudflare Turnstile token. Required when this route is called with a publishable (pk_…) key — render the widget with the site key returned by /api/public/company-profile. Not needed for secret-key (server-to-server) calls, and ignored where Turnstile is not configured.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
curl -X POST "https://example.com/api/public/auth/forgot-password" \ -H "origin: string" \ -H "X-Site: string" \ -H "Content-Type: application/json" \ -d '{ "email": "string" }'