New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Pre-filled recovery address

When a user enters their identifier on the login screen and then starts account recovery, Ory Elements pre-fills the recovery form with that identifier. The user doesn't have to type their email address or phone number a second time.

How it works​

  1. The user submits the first step of an identifier-first login, the step that asks only for the identifier. Ory Elements remembers the submitted value.
  2. The user opens the recovery screen, for example by selecting Forgot Password?.
  3. Ory Elements fills the address field of the recovery form with the remembered value.

The pre-filled value is only a starting point. The user can edit or replace it, and Ory Elements doesn't submit the form for them.

Which identifiers are pre-filled​

Ory Elements only pre-fills a value that the recovery field accepts:

Identifier entered at loginRecovery field emailRecovery field recovery_address
Email addressPre-filledPre-filled
Phone number in international format, for example +491234567Not pre-filledPre-filled
Username or any other valueNot pre-filledNot pre-filled

The recovery_address field is shown when the project lets users choose an email or SMS recovery method. Otherwise the recovery form shows the email field.

Where the identifier is stored​

Ory Elements stores the identifier in the browser's sessionStorage under the key ory_elements_last_identifier.

  • The value stays in the user's browser. Ory Elements doesn't add it to a URL or send it anywhere on its own.
  • The value is scoped to one browser tab and one origin. The browser removes it when the tab closes.
  • Each new submission of the identifier step replaces the stored value. Ory Elements doesn't clear it after sign-in, sign-out, or recovery.
  • If sessionStorage isn't available, for example because the browser blocks site data, the recovery form stays empty.

Because the value is tied to an origin, the login and recovery pages must be served from the same origin for the pre-fill to work.

When the recovery form isn't pre-filled from the current login​

Ory Elements has no value from the current login attempt when the user:

  • Opens the recovery screen before submitting the identifier step.
  • Signs in on a login screen that asks for the identifier and password together. This is the unified login style, which is used when identifier first authentication is disabled.
  • Opens the recovery screen in another browser tab. Tabs usually don't share sessionStorage.

In the first two cases, the recovery form shows the identifier from an earlier identifier-first login in the same tab, if there is one. Otherwise it stays empty.