Improvement
Dec 2, 2025

Updated Forgot Password Workflow with Secure Reset Links

Updated Forgot Password Workflow with Secure Reset Links

The Forgot Password flow has been redesigned to improve account security and user experience. The system no longer sends automatically generated new passwords to customers. Instead, every password reset request now triggers a personal, time-limited, single-use reset link.

Key enhancements include:

  • Reset link validity: 24 hours

  • Single-use security: Once the password is changed, the link becomes invalid

  • User-driven reset: Customers create their own new password, increasing security and reducing support requests

This change aligns AI Commerce Cloud with modern security best practices and ensures that sensitive credentials are never sent directly via email.