> ## Documentation Index
> Fetch the complete documentation index at: https://docs-dev-feat-sdk-reference-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Password Reset Post Challenge

> Learn about Password Reset Post Challenge Actions, which run after a user completes the first challenge during the password reset journey but before they set a new password.

The `post-challenge` trigger runs during the password reset process after a user completes the first challenge, typically a link to the [user's email](/docs/secure/multi-factor-authentication/authenticate-using-ropg-flow-with-mfa/enroll-and-challenge-email-authenticators), but before a new password is set. Use this trigger to challenge a user with an additional <Tooltip tip="Multi-factor authentication (MFA): User authentication process that uses a factor in addition to username and password such as a code via SMS." cta="View Glossary" href="/docs/glossary?term=multi-factor+authentication">multi-factor authentication</Tooltip> (MFA) factor or to redirect the user to an external site, such as a third-party verifier. After verification, users can provide the new password for their account. You can create up to four Actions in your tenant that leverage the `post-challenge` trigger.

<Frame>
  <img src="https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=bda8777f8e42de3cd5c05c95ef8bf24d" alt="To use the Password Reset Flow, navigate to Dashboard > Actions > Flows." data-og-width="1550" width="1550" data-og-height="564" height="564" data-path="docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=280&fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=6e2636d0c16089f8be3a166668a7f556 280w, https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=560&fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=c4a3174479de92119187bf613a667902 560w, https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=840&fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=a01cd6ad48150e590e9b99f4255f37fb 840w, https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=1100&fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=a27b10430927540b4705d58a4a60bf64 1100w, https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=1650&fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=ff30a6ab6f207f21af105b8c2934ed2c 1650w, https://mintcdn.com/docs-dev-feat-sdk-reference-docs/vVLrCzoor0V6dTvM/docs/images/cdy7uua7fh8z/1Pugm9fFYCmdhh7QO5Klzm/7f7eefbf810fd4ebeb22d6393151ffa2/2023-08-14_15-54-03.png?w=2500&fit=max&auto=format&n=vVLrCzoor0V6dTvM&q=85&s=a1865fa2b454efb2ba5c2dca79fe2d1b 2500w" />
</Frame>

Actions in this flow are blocking (synchronous): they execute as part of the trigger's process and prevent the rest of the Auth0 pipeline from running until the Action completes.

<Note>
  In order for these Actions to run properly, you must have Universal Login enabled. These Actions cannot be triggered when using Classic Login.
</Note>

## References

* [Event object](/docs/customize/actions/reference/password-reset-post-challenge/password-reset-post-challenge-event-object): Provides contextual information about the user resetting their password.
* [API object](/docs/customize/actions/reference/password-reset-post-challenge/password-reset-post-challenge-api-object): Provides methods for changing the behavior of the flow.

## Limitations

Password Reset triggers do not support [Active Directory/LDAP connections](/docs/authenticate/identity-providers/enterprise-identity-providers/active-directory-ldap).

## Common use cases

### Secure password reset with additional MFA factors

A post-challenge Action can issue an MFA challenge after the user completes the first challenge. For example, you can issue a WebAuthn-based challenge as a secondary factor if your tenant has WebAuthn enabled as a factor:

```javascript lines theme={null}
/**
 * @param {Event} event - Details about the user resetting their password.
 * @param {PasswordResetPostChallengeAPI} api - Interface whose methods can be used to change the behavior of the password reset.
 */
exports.onExecutePostChallenge = async (event, api) => {
  const enrolledFactors = event.user.enrolledFactors.map((x) => ({
    type: x.type
  }));
  api.authentication.challengeWith({ type: 'webauthn-roaming' }, { additionalFactors: enrolledFactors });
};
```

### Redirect users to a third-party application

In addition to an MFA challenge, you can also try adding a redirect in the custom Action, for example, to a third-party verifier or risk assessor. This sample Action redirects the user to an example app, then continues the Action after the redirect to challenge the user with an MFA factor:

```javascript lines theme={null}
/**
 * @param {Event} event - Details about the user resetting their password.
 * @param {PasswordResetPostChallengeAPI} api - Interface whose methods can be used to change the behavior of the password reset.
 */
exports.onExecutePostChallenge = async (event, api) => {
  // Send the user to https://my-app.example.com
  api.redirect.sendUserTo('https://my-app.example.com');
};

/**
 * @param {Event} event - Details about the user resetting their password.
 * @param {PasswordResetPostChallengeAPI} api - Interface whose methods can be used to change the behavior of the password reset.
 */
exports.onContinuePostChallenge = async (event, api) => {
  const enrolledFactors = event.user.enrolledFactors.map((x) => ({
    type: x.type
  }));

  // Challenge the user with email otp OR another enrolled factor
  api.authentication.challengeWith({ type: 'email' }, { additionalFactors: enrolledFactors });

  // Example of how to challenge the user with multiple options
  // in this case email otp OR sms otp
  // api.authentication.challengeWithAny([{ type: 'email' }, { type: 'sms' }]);
};
```

The Actions pipeline is not active while Auth0 redirects the user. Once the user continues the Auth0 login process, the Actions pipeline resumes. Actions that were executed prior to the redirect are not executed again. To learn more, read [Redirect with Actions](/docs/customize/actions/redirect-with-actions).
