v1
latestOpenAPI 3.0.3Apache 2.02026-07-173769114.2 KBInitialize Recovery Flow for API Clients
This endpoint initiates a recovery flow for API clients such as mobile devices, smart TVs, and so on.
If a valid provided session cookie or session token is provided, a 400 Bad Request error.
To fetch an existing recovery flow call /self-service/recovery/flows?flow=<flow_id>.
:::warning
You MUST NOT use this endpoint in client-side (Single Page Apps, ReactJS, AngularJS) nor server-side (Java Server Pages, NodeJS, PHP, Golang, ...) browser applications. Using this endpoint in these applications will make you vulnerable to a variety of CSRF attacks.
This endpoint MUST ONLY be used in scenarios such as native mobile apps (React Native, Objective C, Swift, Java, ...).
:::
More information can be found at Ory Kratos Account Recovery Documentation.
Response
recoveryFlow