24-hour time limit for password reset links in portals
For extra security, links for creating or resetting passwords in the candidate and client portals now expire after 24 hours. MSR-1133 | October 2025
Who is this feature relevant for?
All customers using the candidate and/or client portal with authentication via MSR.
The benefits at a glance
-
Password links are now more secure: they automatically expire after 24 hours.
-
Prevents misuse of old emails with active reset links.
Feature explanation
When a user needs to set or reset a password via the candidate or client portal, the system generates a unique link that is valid for 24 hours. During this period, the user can open the link multiple times from different devices or browsers.
After 24 hours, or after the password has been successfully set or changed, the link expires. The user is then redirected to the login page (in the future, this will be extended to display a clear message that the link has expired).
All password reset or creation links sent before the installation of this new update are automatically invalidated.
Set-up
- No changes are required. The new logic is automatically applied to all portal password reset and create links sent.
🔗 Here you can find all features from the October Release 2025.