Password Management
Password reset flows for end users in Basic Authentication.
Covers the end-user forgot/reset flow in Basic Authentication.
Added in BetterForms 3.4.x: the same helper-file token fields can also be used for magic-link sign-in.
User-Initiated Reset (Forgot/Reset)
User requests a reset link
Run
authForgotaction (requiresemailin the model)Server generates a time-bound, one-time reset token and stores it on the user record in the helper
onAuthNotifierhook runs with the user object in$$BF_Userand sends the reset email link (developer-configured)User clicks the link and lands on the reset page (token in URL)
User submits new password; page runs
authResetwith the tokenServer validates token, updates the password hash, and invalidates the token
onAuthNotifierhook runs to optionally notify that the password reset succeeded
Recommended page actions:
Request page:
authForgotReset page:
authReset(requirespasswordand a valid token via URL)
Admin-Triggered Reset
This page focuses on the built-in end-user reset flow. If you need an admin-managed reset process, implement it as custom business logic on the FileMaker side.
Developer Invite Flow (Set Password + Optional Auto-Login)
When a developer or admin wants to invite a user without using the default authForgot email flow, use authInviteComplete with helper user fields.
Why use UUID tokens
A UUIDv4 token provides high entropy and is difficult to guess.
It is easy to generate in FileMaker and easy to move through scripts/emails.
Combined with short expiry and single-use clearing, it is suitable for invite links.
Fields to set on the user record
resetToken(token string, for example UUIDv4)resetExpires(future timestamp/date)isEnabled(must be true for redemption)isVerified(recommended true for invite-completion flows)
You can set these through the helper API- User CRUD (user) script by passing a user JSON payload.
Example payload:
Invite URL example
Reset/invite page action
Use authInviteComplete on the password page:
signIn: false(default): sets password and clears invite token fields.signIn: true: sets password, clears invite token fields, and signs the user in immediately.
Compatibility note
authInviteComplete and authReset are separate redemption paths. Use the same action family that issued the token.
Hooks (FileMaker)
onAuthNotifier: email delivery for reset links and notificationsAdd your own FileMaker-side rules if you need extra checks around password reset
Shared Token Fields
Magic-link authentication can reuse the same helper-file token fields used by password reset.
resetTokenresetExpires
If you use both password reset and magic-link sign-in in the same UI, the most recently issued token wins. For most apps, it is best to use one token-based strategy per UI flow.
Security Considerations
Treat reset tokens as secrets; limit TTL and ensure single-use
Never log tokens or cleartext passwords
Related Pages
Last updated
Was this helpful?