Flowchart examples · Product and UX

Password reset flowchart

Forgot password to signed back in, using a neutral response and a single-use, expiring token.

Password reset flowchart

Password reset flowchartNoYesYesNoNoYesUser clicks ForgotpasswordEnter email addressShow same messagewhether or not accountexistsAccount exists?Send nothing (or a 'noaccount' email)Create single-use tokenwith expiryEmail reset linkToken valid andunused?Show expired page, offernew linkEnter new passwordMeets passwordrules?Save hash, revoke othersessionsConfirm and sign in

A worked example to adapt. Rename steps, add branches and owners to match how your team actually works.

Edit the steps to match your process. The free preview (no sign-up) drafts up to 8 main steps; add branches and the remaining steps in the editor.
Mermaid source for this diagram
flowchart TD
  s(["User clicks Forgot password"])
  in[/"Enter email address"/]
  msg["Show same message whether or not account exists"]
  d1{"Account exists?"}
  noop(["Send nothing (or a 'no account' email)"])
  tok["Create single-use token with expiry"]
  mail["Email reset link"]
  d2{"Token valid and unused?"}
  exp["Show expired page, offer new link"]
  pw[/"Enter new password"/]
  d3{"Meets password rules?"}
  save["Save hash, revoke other sessions"]
  e(["Confirm and sign in"])
  s --> in
  in --> msg
  msg --> d1
  d1 -->|No| noop
  d1 -->|Yes| tok
  tok --> mail
  mail --> d2
  d2 -->|Yes| pw
  d2 -->|No| exp
  exp --> in
  pw --> d3
  d3 -->|No| pw
  d3 -->|Yes| save
  save --> e

Paste into any Markdown tool that renders Mermaid, such as GitHub.

About this password reset flowchart

Password reset is a security feature, so the flowchart needs to show more than the happy path: a response that doesn't reveal which emails have accounts, tokens that expire and can only be used once, and revoking other sessions after the change.

The example follows widely used guidance such as the OWASP Forgot Password Cheat Sheet. Adapt token lifetime and notification rules to your own security requirements.

Step by step

  1. Request. The user enters an email; the page shows the same message whether or not an account exists.
  2. Token. For real accounts, create a random, single-use token with a short expiry and email the link.
  3. Validate. Expired or used tokens show a clear page with a way to request a new link.
  4. Set password. Validate the new password against your rules.
  5. Finish. Store the new hash, revoke other sessions and notify the user that the password changed.

How to make it in flow-chart.io

  1. Start from the example. Edit the text in the generator box above so it names your own auth system and token rules, then press Generate. The free preview needs no sign-up.
  2. Add the branches. Add the decision points that matter for you, for example MFA required before reset? or account locked. Each decision becomes a diamond with labeled outcomes.
  3. Assign owners. Save the diagram to the editor (free account) and rename steps to show who does what: web app, auth API and email service.
  4. Share or export. Share a read-only view link: people with the link can view the diagram but not edit it. Downloads as PNG, SVG or PDF are part of Flow Pro (see pricing).

Tips

Frequently asked questions

Why show the same message for unknown emails?
So attackers can't use the reset form to discover which email addresses have accounts.
How long should a reset link last?
Short. Many services use minutes to an hour; follow your security policy.
Can I generate a version with MFA?
Yes. Add an MFA verification step after the token check in the generator box.

Related

User registration flowchartIncident response process flowchartE-commerce checkout flowchartSequence diagramsFlowchart makerAll flowchart examples

Build it from your own words

Describe your process and get an editable diagram. Free to build and edit; Flow Pro adds downloads and unlimited projects.

Start free See pricing