Password reset flowchart
A worked example to adapt. Rename steps, add branches and owners to match how your team actually works.
Mermaid source for this diagram
flowchart TD
s(["User clicks Forgot password"])
in[/"Enter email address"/]
msg["Show same message whether or not account exists"]
d1{"Account exists?"}
noop(["Send nothing (or a 'no account' email)"])
tok["Create single-use token with expiry"]
mail["Email reset link"]
d2{"Token valid and unused?"}
exp["Show expired page, offer new link"]
pw[/"Enter new password"/]
d3{"Meets password rules?"}
save["Save hash, revoke other sessions"]
e(["Confirm and sign in"])
s --> in
in --> msg
msg --> d1
d1 -->|No| noop
d1 -->|Yes| tok
tok --> mail
mail --> d2
d2 -->|Yes| pw
d2 -->|No| exp
exp --> in
pw --> d3
d3 -->|No| pw
d3 -->|Yes| save
save --> ePaste into any Markdown tool that renders Mermaid, such as GitHub.
About this password reset flowchart
Password reset is a security feature, so the flowchart needs to show more than the happy path: a response that doesn't reveal which emails have accounts, tokens that expire and can only be used once, and revoking other sessions after the change.
The example follows widely used guidance such as the OWASP Forgot Password Cheat Sheet. Adapt token lifetime and notification rules to your own security requirements.
Step by step
- Request. The user enters an email; the page shows the same message whether or not an account exists.
- Token. For real accounts, create a random, single-use token with a short expiry and email the link.
- Validate. Expired or used tokens show a clear page with a way to request a new link.
- Set password. Validate the new password against your rules.
- Finish. Store the new hash, revoke other sessions and notify the user that the password changed.
How to make it in flow-chart.io
- Start from the example. Edit the text in the generator box above so it names your own auth system and token rules, then press Generate. The free preview needs no sign-up.
- Add the branches. Add the decision points that matter for you, for example MFA required before reset? or account locked. Each decision becomes a diamond with labeled outcomes.
- Assign owners. Save the diagram to the editor (free account) and rename steps to show who does what: web app, auth API and email service.
- Share or export. Share a read-only view link: people with the link can view the diagram but not edit it. Downloads as PNG, SVG or PDF are part of Flow Pro (see pricing).
Tips
- Never put the password itself in an email.
- Log reset requests and rate-limit them per account and per IP.
- Send a 'your password was changed' notice after every reset.
Frequently asked questions
- Why show the same message for unknown emails?
- So attackers can't use the reset form to discover which email addresses have accounts.
- How long should a reset link last?
- Short. Many services use minutes to an hour; follow your security policy.
- Can I generate a version with MFA?
- Yes. Add an MFA verification step after the token check in the generator box.