# Weweb + Xano magic link

**URL:** <https://community.weweb.io/t/weweb-xano-magic-link/2838>\
**Category:** How do I?\
**Created:** [May 26, 2023, 11:27pm UTC](https://community.weweb.io/t/weweb-xano-magic-link/2838 "2023-05-26T23:27:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![BuildLikePeter](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/buildlikepeter/32/2674_2.png) [@BuildLikePeter](https://community.weweb.io/u/BuildLikePeter)\
**Post date:** [May 26, 2023, 11:27pm UTC](https://community.weweb.io/t/weweb-xano-magic-link/2838/1 "2023-05-26T23:27:44Z")

</div>

I have setup my reset password workflow based on these steps:

> **[Xano authentication | Weweb documentation](https://docs.weweb.io/plugins/auth-systems/xano-auth.html#forgot-password-with-xano-auth)**
>
> Learn how to work with Xano auth in WeWeb

I got all the way to the last step and my weweb workflow returns a valid auth code, but the current user is never actually authenticated (i.e. isAuthenticated is false). Therefore I am not able to execute the password change function

How do I get the auth token that is returned to actually authorize the user?

---

<div class="post-metadata">

**Author:** ![jaredgibb](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@jaredgibb](https://community.weweb.io/u/jaredgibb)\
**Post date:** [May 26, 2023, 11:52pm UTC](https://community.weweb.io/t/weweb-xano-magic-link/2838/2 "2023-05-26T23:52:06Z")

</div>

You need to log the user in with the new password after you update the oassword

---

<div class="post-metadata">

**Author:** ![BuildLikePeter](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/buildlikepeter/32/2674_2.png) [@BuildLikePeter](https://community.weweb.io/u/BuildLikePeter)\
**Post date:** [May 26, 2023, 11:54pm UTC](https://community.weweb.io/t/weweb-xano-magic-link/2838/3 "2023-05-26T23:54:34Z")

</div>

I think you are misunderstanding. In order to change the password, I need the auth to authenticate the user first. I am getting the auth token returned to weweb, but it is not logging the user in.

---

<div class="post-metadata">

**Author:** ![jaredgibb](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@jaredgibb](https://community.weweb.io/u/jaredgibb)\
**Post date:** [May 27, 2023, 12:16am UTC](https://community.weweb.io/t/weweb-xano-magic-link/2838/4 "2023-05-27T00:16:06Z")

</div>

Not for a password reset.

I’d request a pw reset from your app  
Send the email to the sever  
Have the server create a token  
Save it to the user somewhere  
Email it to the user as a url parameter for a reset pw link that goes to a page in your app  
When they click the link they land on a page and enter a new password  
This shoots a call back to weweb to an unauthorized endpoint that accepts a token and password.  
The call searches for a user with that token and applies the new password and shoots back a success message.

On success, log the user in with the new password

---

<div class="post-metadata">

**Author:** ![Quentin](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/quentin/32/6_2.png) [@Quentin](https://community.weweb.io/u/Quentin)\
**Post date:** [May 30, 2023, 8:34am UTC](https://community.weweb.io/t/weweb-xano-magic-link/2838/5 "2023-05-30T08:34:53Z")

</div>

Exactly what @jaredgibb said!

Indeed, you’ll need a “magic login” endpoint in Xano to provide a one-off token that’ll be used in an email, and a page in WeWeb that will authenticate the user with this token. Then, once the user is authenticated, send the new password from WeWeb to Xano.
