Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Rest Password Reset

86 sites Security covered Drupal 10–11
View on drupal.org

This module provides REST API endpoints for decoupled Drupal sites to allow users to request their username via email or to reset their password. It enables front-end applications to interact with these endpoints for username retrieval and password change functionality.

This module provides a way to request your username via email or to change your Drupal user password on a decoupled website via REST api endpoints. It builds on the core REST module and uses REST UI to further configure the custom endpoints provided by the module.

Features

The module provides 3 rest endpoints:

GET /user/username/{email address}
GET /user/password/{email address}
POST /user/password/reset

Your decoupled frontend is targeted by the second endpoint and you are supposed to provide a page in the frontend that offers the end user an option to provide a new password and then post the parameters provided by url arguments to your frontend to format a POST request to the backend via the 3rd endpoint.

Post-Installation

The module provides a multilangual form under Admin->Configuration->Web Services->Rest Password Reset
Also you are supposed to use REST ui module to activate the custom endpoints and give anonymous users access to them. Cookie authentication should also make sure your frontend app can GET and POST directly to the backend endpoints without needing to authenticate first as would be expected when an end user requests a new password or his or her username.

Additional Requirements

This module extends the rest Drupal core module and is purely intended for decoupled websites. a React frontend for example is a hard requirement.

- rest (drupal core)
- rest ui (3rd party drupal module)

Disclaimer

There is also REST password request which uses a different approach and sends an email with a temporary password. This module attempts to follow the way a normal Drupal site works and therefor sends an email with a password reset link that points to a configurable endpoint in your decoupled frontend. By following that link you can then request a new password. The hashing algoritm used in the password reset link is the same as Drupal normally uses.

Depends on

Dependencies of the latest stable release

  • restui
  • rest Drupal core
  • user Drupal core

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
2
Tracked since
Nov 2025
Latest release
2 weeks ago
Releases (12 mo)
2 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
1.1.6 Stable 10–11 Aug 13, 2026
1.1.5 Stable 10–11 Nov 18, 2025