---
title: "Reset user password"
method: POST
path: "/users/reset-password"
tags: ["Users"]
---

# Reset user password

`POST /users/reset-password`

Resets the password for a user identified by email. Protected by
resetPasswordMiddleware (validates reset token/permission).
Password is hashed via bcrypt before storage.

## Request body

- object
  - `email` string, email, required
  - `newPassword` string, password, required — Must be 8+ chars with uppercase, lowercase, and digit

## Response `202`

Password reset successfully

- object
  - `message` string
  - `data` UserSafe — User object with password_hash excluded
    - `id` integer, required
    - `name` string, required
    - `surname` string, required
    - `email` string, email, required
    - `role_id` integer, required — 1=Admin, 2=Reviewer, 3=Editor, 4=Auditor, 5=SuperAdmin
    - `createdAt` string, date-time, required
    - `last_login` string, date-time, nullable
    - `updatedAt` string, date-time
    - `is_demo` boolean
    - `organization_id` integer, nullable
    - `profile_photo_id` integer, nullable
    - `sso_provider` 'AzureAD' | 'null', nullable
    - `sso_user_id` string, nullable

## Other responses

- `400` — Validation error (weak password)
- `403` — Business logic error
- `404` — User not found
- `500` — Internal server error

---

[API](https://skmtc.dev/verifywise-ai/apis/verifywise-api.md) · [All operations](https://skmtc.dev/verifywise-ai/apis/verifywise-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/verifywise-ai/verifywise-api/revisions/3b138b306b5b/schema)
