Request password recovery
POST
Sends a password reset link if the email belongs to an account.
Access: Public. No authentication required.
- The link expires after 30 minutes. All addresses receive the same accepted response; requests are rate limited.
- When Turnstile is enabled, include a fresh proof with action
recovery.
application/json- body
email*stringLength
length <= 254cf-turnstile-response?TurnstileTokenFresh, single-use Turnstile proof. Required when the security check is enabled, valid for at most five minutes, with the handler's expected action and approved frontend hostname. Never persist or reuse it.
Length
1 <= length <= 2048Request accepted without disclosing account status.
application/json- response
message*stringcurl -X POST 'https://layerbeat.com/v1/auth/recovery/request' \ -H 'Content-Type: application/json' \ -d '{ "email": "you@example.com"}'{ "message": "If a link is needed, it will arrive by email shortly."}