How to use a flowchart template.
- 01Define the trigger and actors
Start with the password reset request from the user and identify all systems involved, including your app, auth service, and OTP provider.
- 02Map the OTP lifecycle steps
Add nodes for generating the OTP, sending it via email or SMS, storing a hashed copy, and setting an expiry window.
- 03Add decision branches for validation and retries
Include yes/no branches for OTP match, expired code, and maximum retry attempts to cover all edge cases.
- 04Include success and failure endpoints
End the flow with password update success, session invalidation, and error responses for invalid or expired OTPs.
- 05Review and share
Validate the flowchart with your team and export it as PNG or embed it in your API docs.
Questions about flowchart templates
What is a password reset OTP API flowchart?
A visual representation of the API endpoints, parameters, and decision logic involved in resetting a password using a one-time password, from the initial request to a successful reset or failure.
What should a password reset OTP flow include?
It should cover user identity verification, OTP generation and delivery, OTP validation with expiry and retry limits, password update, and error handling for invalid codes or locked accounts.
Can I edit the examples to fit my API?
Yes, each example is a starting point. Use the generator to add custom steps, rename nodes, or change the sequence to match your exact endpoints and error messages.
How do OTP retries and expiry appear in the flowchart?
Show a decision node after OTP submission: if the code matches and is not expired, proceed; if expired, offer resend; if invalid and retry count below limit, allow retry; otherwise block and require a new reset request.
Do I need to show SMS and email delivery in the same flowchart?
You can use parallel branches or a single delivery step with a note, depending on whether both channels are supported. Keeping them separate helps document channel-specific failures.