Mint a password-reset token
POSThttps://api.evora.lol/api/developer-api/users/{userId}/password-reset
Requires scopeusers:write
Evora issues and verifies; you deliver. No email is sent from our side — your customers are yours, and most have no address on file. Send the returned token over whatever channel you already use (a Discord DM, your own mail provider, a link on your panel), then call /password-reset/fulfil.
The plaintext token is returned once and is not retrievable again; only a SHA-256 hash is stored.
Because you identify the customer by userId rather than from an email form, this endpoint is not a user-enumeration oracle. Preserve that property in your own panel by responding identically whether or not an account exists.
Path parameters
| userIdrequired string (uuid) | End-user UUID. |
Body
| appId string (uuid) | Recorded for audit. |
| ttlSeconds integer | Default: 1800 · Range: 300–86400 |
Request
{ "ttlSeconds": 1800 }
Responses
201Token minted.
json
{ "success": true, "reset_token": "s7Fv3k9Qx1...", "expires_at": "2026-08-06T18:30:00.000Z", "expires_in": 1800, "warning": "Deliver this token to the user now — it is not retrievable again." }
403The customer is banned.
429Too many live tokens for this customer (max 3), or issuance rate exceeded.
json
{ "error": "Too many active reset tokens for this user.", "code": "RESET_RATE_LIMITED" }
More in Users
- getLook up a customer by username
- getList customers
- postCreate a customer
- getGet a customer
- putUpdate a customer
- deleteDelete a customer
- postConsume a reset token and set the new password
- postBan a customer
- postUnban a customer
- postReset a customer's HWID
- getRead a customer's two-factor state
- deleteReset a customer's two-factor authentication
- postReset a customer's device binding
- postMint a one-time SDK login token (panel SSO)
- postRedeem a license key on a customer's behalf
- postBulk customer actions
Base URL https://api.evora.lol/api/developer-api · full spec at developer-api.yaml · back to the docs