Skip to main content
mutation

Requires unauthenticated_write_customers access scope.

Resets a customer's password using the reset URL from a password recovery email. The reset URL is generated by the customerRecover mutation.

On success, returns the updated Customer and a new CustomerAccessToken for immediate authentication.


Caution

This mutation handles customer credentials. Ensure the new password is transmitted securely and never logged or exposed in client-side code.


•String!
required

New password that will be set as part of the reset password process.

•URL!
required

The customer's reset password url.


Was this section helpful?

Anchor to CustomerResetByUrlPayload returnsCustomerResetByUrlPayload returns

•Customer

The customer object which was reset.

•CustomerAccessToken

A newly created customer access token object for the customer.

•[CustomerUserError!]!
non-null

The list of errors that occurred from executing the mutation.

•[UserError!]!
non-nullDeprecated

The list of errors that occurred from executing the mutation.


Was this section helpful?