Forgot Password Cheat Sheet

This article provides a simple model to follow when implementing a "forgot password" web application feature.


1) Gather Identity Data

2) Verify Security Questions

3) Send a Token Over a Side-Channel

4) Allow user to change password

Authors and Primary Editors

Jim Manico - jim[at]