Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Mailchimp 3.1.5 Minor update available for module mailchimp (3.1.5). Release: Commerce Shipping 3.0.5 Minor update available for module commerce_shipping (3.0.5). Release: GoogleTag Manager 2.0.1 Minor update available for module gtm (2.0.1). Usage Milestone: Easy Breadcrumb Module easy_breadcrumb crossed 100,000 active installs. Release: Commerce ML Exchange 2.0.1 Minor update available for module cmlexchange (2.0.1). Release: Commerce ML Exchange 2.0.0 Major update available for module cmlexchange (2.0.0). Release: SynImport 2.0.0 Major update available for module synimport (2.0.0). Release: Contact ajax 3.0.0 Major update available for module contact_ajax (3.0.0). Release: Commerce ML API 2.0.1 Minor update available for module cmlapi (2.0.1). Module Revived: Contextual Filter from Referer 1.0.2 Module contextual_filter_referer updated after 22 months of inactivity (1.0.2).

Rest Password Reset

83 sites Security covered Drupal 10–11
View on drupal.org

This module provides REST API endpoints for decoupled Drupal sites to allow users to request their username via email or to reset their password. It enables front-end applications to interact with these endpoints for username retrieval and password change functionality.

This module provides a way to request your username via email or to change your Drupal user password on a decoupled website via REST api endpoints. It builds on the core REST module and uses REST UI to further configure the custom endpoints provided by the module.

Features

The module provides 3 rest endpoints:

GET /user/username/{email address}
GET /user/password/{email address}
POST /user/password/reset

Your decoupled frontend is targeted by the second endpoint and you are supposed to provide a page in the frontend that offers the end user an option to provide a new password and then post the parameters provided by url arguments to your frontend to format a POST request to the backend via the 3rd endpoint.

Post-Installation

The module provides a multilangual form under Admin->Configuration->Web Services->Rest Password Reset
Also you are supposed to use REST ui module to activate the custom endpoints and give anonymous users access to them. Cookie authentication should also make sure your frontend app can GET and POST directly to the backend endpoints without needing to authenticate first as would be expected when an end user requests a new password or his or her username.

Additional Requirements

This module extends the rest Drupal core module and is purely intended for decoupled websites. a React frontend for example is a hard requirement.

- rest (drupal core)
- rest ui (3rd party drupal module)

Disclaimer

There is also REST password request which uses a different approach and sends an email with a temporary password. This module attempts to follow the way a normal Drupal site works and therefor sends an email with a password reset link that points to a configurable endpoint in your decoupled frontend. By following that link you can then request a new password. The hashing algoritm used in the password reset link is the same as Drupal normally uses.

Depends on

Dependencies of the latest stable release

  • restui
  • rest Drupal core
  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Nov 2025
Latest release
4 weeks ago
Releases (12 mo)
2 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.1.6 Stable 10–11 Aug 13, 2026
1.1.5 Stable 10–11 Nov 18, 2025