Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A safe password-reset flow gives legitimate users a clear next step without revealing whether an account exists or letting an attacker take over the account. Keep a forgotten-password reset separate from full account recovery: changing a password is one task; regaining access after losing authenticators or responding to suspected compromise is another.

Design the reset request so it reveals nothing about the account

Return the same neutral confirmation whether the submitted address belongs to an account or not. OWASP’s example is: “If that email address is in our database, we will send you an email to reset your password.” (OWASP Authentication Cheat Sheet.)

Make the next steps useful without confirming account existence: ask the user to check the address they entered, look in spam, wait briefly for delivery, or use the support route. Keep response timing and the surrounding request path as consistent as practical, including transport-level behavior that might otherwise reveal a difference. See the OWASP Forgot Password Cheat Sheet.

  • Rate-limit requests and apply other abuse controls, including per-account limits, to reduce automated attempts and reset-message flooding.
  • Do not lock an account because someone requested a password reset. An attacker who knows an identifier could otherwise deny service to its owner.

Make reset links and codes difficult to misuse

Email links are a straightforward reset method. Build their URLs from a trusted, configured domain and require HTTPS. Reset identifiers should be securely stored, linked to the intended account, hard to guess, invalidated after use, and expired after an appropriate period. OWASP does not specify one expiry duration for every product; choose a window based on your risk and usability requirements.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Prevent tokens from leaking through referrer data and rate-limit attempts to use them. Do not change an account until a valid reset identifier is presented. A PIN is another option: grouping its digits with spaces can make it easier to read and enter. Once validated, the PIN should grant only a limited reset-only session, not general account access. These controls are described in the OWASP Forgot Password Cheat Sheet.

Set the new password without surprising the user

Apply the same password policy used elsewhere in the product. Show clear validation and confirmation, and avoid a separate recovery-only rule that users would not expect. After the change succeeds, send a notification, but never include the password in it.

Rank #2
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

OWASP recommends sending the user through the normal sign-in process rather than automatically logging them in at the end of a reset. Decide whether existing sessions are revoked automatically or whether the user can request revocation, then explain the behavior clearly. A password change and a session decision are related, but they are not the same operation.

Keep password replacement distinct from account recovery

If a user still has an available authenticator, such as a second factor, forgetting the password is different from losing control of the authenticators needed to sign in. NIST defines account recovery as “when a subscriber recovers from losing control of the authenticators that are needed to authenticate at a desired AAL.” Its Digital Identity Guidelines, NIST SP 800-63B-4, §4.2 (July 2025) recognizes recovery codes, recovery contacts, repeated identity proofing, and documented, risk-based alternatives.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Offer a route that still works when the usual authenticator is unavailable, even if that route requires contacting support and proving identity. For each supported method, weigh whether it will be available after the primary authenticator is lost, how well it resists takeover and account enumeration, how much time and effort legitimate recovery takes, what evidence support needs, and what notifications or revocations follow. Document the risk analysis behind application-specific methods; NIST’s recovery-method guidance is in SP 800-63B-4, §4.2.1.

Build a separate response for suspected compromise

A user who suspects an attacker may still control a session, recovery address, or MFA method needs more than a new password. Use independent evidence established before the incident; do not automatically trust an address or phone number that was changed recently.

Rank #4
OnlyKey Duo - The Best Protection for All of Your USB-C and USB-A Devices
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTION – Locking your device means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN – No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

After recovery, invalidate relevant sessions and outstanding reset links or codes. Review recovery methods and active authenticators with the user, and notify them through channels that remain safe. NIST states: “An account recovery event always causes one or more notifications to be sent to the subscriber to help detect the fraudulent use of account recovery.” (NIST SP 800-63B-4, §4.2.) OWASP’s Forgot Password Cheat Sheet also addresses post-reset notifications and session handling.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Support passkeys without weakening the fallback

For a passkey-enabled service, make it possible to manage multiple authenticators and encourage users to enroll a backup before one is lost. Treat recovery codes as authentication secrets: protect them, make them single-use, and let users regenerate them. Use rate limits, risk checks, notifications, and additional review where appropriate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Do not let a failed passkey ceremony silently fall back to a weaker method, or let email or SMS silently bypass a stronger policy for high-risk accounts. Device-bound keys also need an explicit replacement and availability plan. An optional FIDO2/WebAuthn hardware security key can provide another authenticator where supported, but it does not solve recovery by itself; the service’s recovery support and the user’s backup plan still matter. See the OWASP Passkey Security Cheat Sheet.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.