Every application with password-based authentication eventually needs password recovery. A user may forget their password and need a way to regain access without contacting support.
Create a Forgot Password Form
Add a simple form that asks for the user's email address. When submitted, request a password reset from Supabase Auth.
Configure the Redirect
Supabase needs to know where the user should return after clicking the recovery link. Configure the correct redirect URL for your application.
Send the Recovery Email
Supabase can initiate the password recovery flow using the user's email address.
Create the Reset Page
After the user opens the recovery link, show a page where they can choose a new password.
Update the Password
Use the authenticated recovery session to update the user's password.
Test the Complete Flow
Test: Forgot password Email received Recovery link New password Login with the new password Also test expired or invalid recovery links. A reliable password recovery system is an important part of any production authentication workflow.