Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

After a successful password reset, invalidate the recovery link that was used, every other outstanding recovery link for that account, and the account’s existing sessions. If the event may have exposed OAuth access or refresh tokens, revoke those separately through the authorization server. These are different credentials with different revocation mechanisms: an OAuth token-revocation request does not invalidate an application’s emailed password-reset URL.

“OAuth recovery link” is not a standard OAuth token type. It usually means an application’s account-recovery link for an account that also uses OAuth. Password recovery is application-specific; OAuth standards govern authorization flows and OAuth tokens. IETF RFC 9700, RFC 6749, and OWASP’s Forgot Password Cheat Sheet address these separate parts of the problem.

Which credentials must you revoke?

A password reset can involve several credentials, and revoking one does not automatically revoke the others. Identify which systems issued each credential and make recovery trigger the appropriate action in each.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Credential Who controls it Recovery action
Password-reset or account-recovery link Your application Consume the link after use, expire it, and invalidate other outstanding recovery credentials for the account.
Application session Your application Invalidate the server-side session so an existing login cannot survive the reset.
OAuth access or refresh token The authorization server that issued it Use that server’s supported revocation mechanism when the incident or policy calls for it. RFC 7009 describes OAuth token revocation.
OAuth authorization code The authorization server Authorization codes are separate from recovery links; OAuth requires them to be short-lived and single-use.

For OAuth tokens, see RFC 7009. For recovery links and sessions, see OWASP’s guidance. A provider may support automatic refresh-token revocation after events such as a password change, but RFC 9700 permits this; it does not guarantee that every provider does it. Verify the provider’s behavior and connect your recovery process to its documented API or administrative controls.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

What should happen when a recovery link is used?

Make successful recovery a security event, not merely a password-field update. In one logical operation, accept the presented token only once, change the password, consume that token, invalidate other outstanding recovery credentials for the account, and invalidate existing server-side sessions. Treat the token-consumption and account update as an atomic operation where your architecture allows, so concurrent requests cannot redeem the same link twice.

OWASP recommends secure, single-use, time-limited recovery tokens and invalidating them after use. It also recommends ending existing sessions after a password reset. Removing a cookie in the user’s browser is not enough if the corresponding server-side session remains valid.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Then assess whether the incident requires revoking OAuth access or refresh tokens as well. For example, a suspected account takeover may justify broader revocation than a routine password change. Send the revocation request to the authorization server that issued the relevant token; do not assume the application’s recovery-link logic can invalidate a credential held by another service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should you design recovery links?

Make tokens hard to guess and safe to store

Generate each recovery token with a cryptographically secure random generator, make it sufficiently long to resist guessing, associate it with one account, and store it securely. Enforce single use on the server; a link being difficult to guess does not prevent replay if it remains valid after redemption.

Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Set an expiry that fits your service

Choose a lifetime appropriate to the service’s risk and the user’s recovery journey, and reject expired tokens. OAuth does not define a universal password-recovery-link lifetime, and the cited guidance does not prescribe one duration for every application. The risk-based approach is discussed in RFC 6819; do not present a particular duration as an OAuth requirement.

Limit leakage and guessing

  • Serve recovery pages and links over HTTPS.
  • Set a no-referrer policy on the page that handles the token, reducing the chance that the URL is disclosed to another site through a referrer header.
  • Rate-limit recovery requests and token-redemption attempts.
  • Use consistent response messages and timing for recovery requests so the endpoint does not reveal whether an account exists.

These controls follow OWASP’s password-recovery guidance. They protect the application’s recovery flow; OAuth redirect and token flows have their own leakage and replay protections.

Rank #4
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

What changes if OAuth authorization is involved?

Keep OAuth authorization-code handling separate from password recovery. RFC 6749 requires authorization codes to be short-lived and single-use. Under the current OAuth Security Best Current Practice, RFC 9700, public clients must use PKCE with the authorization-code flow. The RFC also says authorization servers should revoke tokens derived from a code if that code is redeemed more than once.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those rules address OAuth authorization and token security; they do not replace application-level controls for an emailed password-reset link. If your recovery event could affect a connected OAuth account, determine which authorization server issued its tokens and invoke that server’s supported revocation behavior where appropriate.

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to check after a suspected account compromise

A password reset by itself may leave other ways into the account intact. After a suspected takeover, review and address the affected account’s security state:

  • Invalidate all outstanding password-reset and recovery credentials.
  • End existing application sessions on the server.
  • Review recovery email addresses and other recovery settings for unauthorized changes.
  • Review authenticators, such as enrolled second factors, and remove or replace those that may be compromised.
  • Assess whether OAuth tokens or grants need revocation, and use the issuing authorization server’s supported controls.
  • Notify the account holder about the recovery and relevant security changes.

The applicable actions depend on what may have been exposed and how your service implements recovery. OWASP’s guidance covers recovery-link and session controls; RFC 9700 covers OAuth security considerations.

Implementation checklist

  1. Generate a cryptographically random token for one account and store it securely.
  2. Apply a risk-appropriate expiry and enforce single use server-side.
  3. On successful recovery, consume the presented token and invalidate every other outstanding recovery credential for the account.
  4. Invalidate server-side sessions; do not rely only on deleting browser cookies.
  5. Assess the need to revoke OAuth tokens or grants, then use the issuing authorization server’s supported revocation controls.
  6. Protect request and redemption endpoints with rate limits, consistent account-enumeration responses, HTTPS, and a no-referrer policy on the redemption page.
  7. For OAuth authorization-code flows, use short-lived, single-use codes and follow RFC 9700’s protections, including PKCE for public clients.
  8. Verify whether your authorization server automatically revokes refresh tokens after password changes or other security events; do not assume that it does.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.