Account Recovery

Reset access without exposing account state

This page preserves the backend rule from Sprint 1: it always returns the same success message so the app never leaks whether an email exists.

Secure

JWT access tokens with refresh-cookie recovery.

Verified

Email confirmation and reset links stay on the same path.

Deployed

Frontend stays Vercel-first while backend points at AWS HTTPS.

Password Reset

Forgot password

We will send you a reset link if the account exists.

Back to login.