Email Template Reference
On this page
This page contains an overview of each email template that ships with FusionAuth.
Retrieve Default Templates#
You can use the Admin UI to version control or customize templates. If you would rather have the email templates as a collection of files, they live in extractedcode/templates-email in the docs repository. Browse that folder to see exactly what you are getting, or download every file in it at once:
$ npx degit FusionAuth/fusionauth-site/astro/extractedcode/templates-email templates-email
If you would rather not use Node, pull the same folder out of a repository tarball:
$ curl -L https://github.com/FusionAuth/fusionauth-site/archive/refs/heads/main.tar.gz \
| tar -xz --strip-components=4 fusionauth-site-main/astro/extractedcode/templates-email
Either command writes the templates into a templates-email directory.
Breached Password#
[#setting url_escaping_charset="UTF-8"]
<p>This password was found in the list of vulnerable passwords, and is no longer secure.</p>
<p>In order to secure your account, it is recommended to change your password at your earliest convenience.</p>
<p>Follow this link to change your password.</p>
[#assign url = "${baseUrl}/password/forgot?client_id=${(application.oauthConfiguration.clientId)!''}&email=${user.email?url}&tenantId=${user.tenantId}" /]
<a href="${url?html}">
${url?html}
</a>
- FusionAuth Admin[#setting url_escaping_charset="UTF-8"]
This password was found in the list of vulnerable passwords, and is no longer secure.
In order to secure your account, it is recommended to change your password at your earliest convenience.
Follow this link to change your password.
${baseUrl}/password/forgot?client_id=${(application.oauthConfiguration.clientId)!''}&email=${user.email?url}&tenantId=${user.tenantId}
- FusionAuth AdminReplacement Variables#
application Application Available since 1.27.2The Application object, see the Application API for field definitions.
Note: This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined.
baseUrl String Available since 1.68.0The base URL used when rendering links in this template. FusionAuth resolves this value from the Application baseURL, then the Tenant baseURL, then a local development fallback URL.
breachResult.loginIds The breach result matching loginIds. This is an array of zero or more email addresses or usernames found in the breach result matching this user. A length of zero means only the password was matched.
breachResult.match String The breach result match type determined by the FusionAuth Reactor. Possible values include:
ExactMatchThe User's loginId and password were found exactly as entered.SubAddressMatchThe User's loginId and password were matched, but the email address was a sub-address match. For example,joe+test@example.comis a sub-address match forjoe@example.com.PasswordOnlyOnly the password found, the loginId and password combination were not matched.CommonPasswordThe User's password was found to be one of the most commonly known breached passwords.
tenant Tenant The Tenant object, see the Tenant API for field definitions.
user User The User object, see the User API for field definitions.
Confirm Child#
Your child has created an account with us and you need to confirm them before they are added to your family. Click the link below to confirm your child's account.
<p>
<a href="http://example.com/family/confirm-child">http://example.com/family/confirm-child</a>
</p>
- FusionAuth AdminYour child has created an account with us and you need to confirm them before they are added to your family. Click the link below to confirm your child's account.
http://example.com/family/confirm-child
- FusionAuth AdminReplacement Variables#
child User The child User object, see the User API for field definitions of a User.
parent User The parent User object, see the User API for field definitions of a User.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions.
user The parent User object. This field has been deprecated, please use the parent object instead.
COPPA Email Plus Notice#
A while ago, you granted your child consent in our system. This email is a second notice of this consent as required by law and also to remind to that you can revoke this consent at anytime on our website or by clicking the link below:
<p>
<a href="http://example.com/consent/manage">http://example.com/consent/manage</a>
</p>
- FusionAuth AdminA while ago, you granted your child consent in our system. This email is a second notice of this consent as required by law and also to remind to that you can revoke this consent at anytime on our website or by clicking the link below:
http://example.com/consent/manage
- FusionAuth AdminReplacement Variables#
consent UserConsent The User Consent object, see the Consent API for field definitions of a User consent.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
user User The User giving consent, see the User API for field definitions of a User.
COPPA Notice#
You recently granted your child consent in our system. This email is to notify you of this consent. If you did not grant this consent or wish to revoke this consent, click the link below:
<p>
<a href="http://example.com/consent/manage">http://example.com/consent/manage</a>
</p>
- FusionAuth AdminYou recently granted your child consent in our system. This email is to notify you of this consent. If you did not grant this consent or wish to revoke this consent, click the link below:
http://example.com/consent/manage
- FusionAuth AdminReplacement Variables#
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
user User The User giving consent, see the User API for field definitions of a User.
Email Verification#
[#if user.verified]
Pro tip, your email has already been verified, but feel free to complete the verification process to verify your verification of your email address.
[/#if]
[#-- When a one-time code is provided, you will want the user to enter this value interactively using a form. In this workflow the verificationId
is not shown to the user and instead the one-time code must be paired with the verificationId which is usually in a hidden form field. When the two
values are presented together, the email address can be verified --]
[#if verificationOneTimeCode??]
<p>To complete your email verification enter this code into the email verification form.</p>
<p> ${verificationOneTimeCode} </p>
[#else]
To complete your email verification click on the following link.
<p>
[#assign url = "${baseUrl}/email/verify/${verificationId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${tenant.id}" /]
<a href="${url?html}">
${url?html}
</a>
</p>
[/#if]
- FusionAuth Admin[#if user.verified]
Pro tip, your email has already been verified, but feel free to complete the verification process to verify your verification of your email address.
[/#if]
[#-- When a one-time code is provided, you will want the user to enter this value interactively using a form. In this workflow the verificationId
is not shown to the user and instead the one-time code must be paired with the verificationId which is usually in a hidden form field. When the two
values are presented together, the email address can be verified --]
[#if verificationOneTimeCode??]
To complete your email verification enter this code into the email verification form.
${verificationOneTimeCode}
[#else]
To complete your email verification click on the following link.
${baseUrl}/email/verify/${verificationId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${tenant.id}
[/#if]
- FusionAuth AdminReplacement Variables#
application Application Available since 1.21.0The Application object, see the Application API for field definitions.
Note: This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined.
baseUrl String Available since 1.68.0The base URL used when rendering links in this template. FusionAuth resolves this value from the Application baseURL, then the Tenant baseURL, then a local development fallback URL.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
user User The User object, see the User API for field definitions of a User.
verificationId String The verification Id intended to be used by the Verify Email API.
verificationOneTimeCode String The verification One Time Code (OTP) to be used with the gated Email Verification workflow. The user enters this code to verify their email.
Forgot Password#
This is also known as the Change Password template.
[#setting url_escaping_charset="UTF-8"]
To change your password click on the following link.
<p>
[#-- The optional 'state' map provided on the Forgot Password API call is exposed in the template as 'state'.
If we have an application context, append the client_id to ensure the correct application theme when applicable.
--]
[#assign url = "${baseUrl}/password/change/${changePasswordId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${user.tenantId}" /]
[#list state!{} as key, value][#if key != "tenantId" && key != "client_id" && value??][#assign url = url + "&" + key?url + "=" + value?url/][/#if][/#list]
<a href="${url?html}">${url?html}</a>
</p>
- FusionAuth Admin[#setting url_escaping_charset="UTF-8"]
To change your password click on the following link.
[#-- The optional 'state' map provided on the Forgot Password API call is exposed in the template as 'state'.
If we have an application context, append the client_id to ensure the correct application theme when applicable.
--]
[#assign url = "${baseUrl}/password/change/${changePasswordId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${user.tenantId}" /]
[#list state!{} as key, value][#if key != "tenantId" && key != "client_id" && value??][#assign url = url + "&" + key?url + "=" + value?url/][/#if][/#list]
${url}
- FusionAuth AdminReplacement Variables#
application Application Available since 1.21.0The Application object, see the Application API for field definitions.
Note: This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined.
baseUrl String Available since 1.68.0The base URL used when rendering links in this template. FusionAuth resolves this value from the Application baseURL, then the Tenant baseURL, then a local development fallback URL.
changePasswordId String The change password Id intended to be used by the Change a User's Password API.
state Object If the state was provided during the Forgot Password request, it will be available to you in the email template.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions.
user User The User object, see the User API for field definitions of a User.
Parent Registration Request#
Your child has created an account with us and needs you to create an account and verify them. You can sign up using the link below:
<p>
<a href="http://example.com/family/confirm-child">http://example.com/family/confirm-child</a>
</p>
- FusionAuth AdminYour child has created an account with us and needs you to create an account and verify them. You can sign up using the link below:
http://example.com/family/confirm-child
- FusionAuth AdminReplacement Variables#
child User The child User object, see the User API for field definitions of a User.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
Passwordless Login#
[#setting url_escaping_charset="UTF-8"]
You have requested to log into FusionAuth using this email address. If you do not recognize this request please ignore this email.
[#if oneTimeCode??]
<p>
Login code: ${oneTimeCode}
</p>
[#else]
<p>
[#-- The optional 'state' map provided on the Start Passwordless API call is exposed in the template as 'state' --]
[#assign url = "${baseUrl}/oauth2/passwordless/${code}?tenantId=${user.tenantId}" /]
[#list state!{} as key, value][#if key != "tenantId" && value??][#assign url = url + "&" + key?url + "=" + value?url/][/#if][/#list]
<a href="${url?html}">${url?html}</a>
</p>
[/#if]
- FusionAuth Admin[#setting url_escaping_charset="UTF-8"]
You have requested to log into FusionAuth using this email address. If you do not recognize this request please ignore this email.
[#if oneTimeCode??]
<p>
Login code: ${oneTimeCode}
</p>
[#else]
[#-- The optional 'state' map provided on the Start Passwordless API call is exposed in the template as 'state' --]
[#assign url = "${baseUrl}/oauth2/passwordless/${code}?tenantId=${user.tenantId}" /]
[#list state!{} as key, value][#if key != "tenantId" && value??][#assign url = url + "&" + key?url + "=" + value?url/][/#if][/#list]
${url}
[/#if]
- FusionAuth AdminReplacement Variables#
application Application Available since 1.21.0The Application object, see the Application API for field definitions.
Note: This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined.
baseUrl String Available since 1.68.0The base URL used when rendering links in this template. FusionAuth resolves this value from the Application baseURL, then the Tenant baseURL, then a local development fallback URL.
code String The unique code intended to be used by the Complete a Passwordless Login API.
state Object If the state was provided when the Passwordless request was initiated, it will be available to you in the email template.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
user User The User object, see the User API for field definitions of a User.
Registration Verification#
[#if registration.verified]
Pro tip, your registration has already been verified, but feel free to complete the verification process to verify your verification of your registration.
[/#if]
[#-- When a one-time code is provided, you will want the user to enter this value interactively using a form. In this workflow the verificationId
is not shown to the user and instead the one-time code must be paired with the verificationId which is usually in a hidden form field. When the two
values are presented together, the registration can be verified --]
[#if verificationOneTimeCode??]
<p>To complete your registration verification enter this code into the registration verification form.</p>
<p> ${verificationOneTimeCode} </p>
[#else]
To complete your registration verification click on the following link.
<p>
[#assign url = "${baseUrl}/registration/verify/${verificationId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${user.tenantId}" /]
<a href="${url?html}">
${url?html}
</a>
</p>
[/#if]
- FusionAuth Admin[#if registration.verified]
Pro tip, your registration has already been verified, but feel free to complete the verification process to verify your verification of your registration.
[/#if]
[#-- When a one-time code is provided, you will want the user to enter this value interactively using a form. In this workflow the verificationId
is not shown to the user and instead the one-time code must be paired with the verificationId which is usually in a hidden form field. When the two
values are presented together, the registration can be verified --]
[#if verificationOneTimeCode??]
To complete your registration verification enter this code into the registration verification form.
${verificationOneTimeCode}
[#else]
To complete your registration verification click on the following link.
${baseUrl}/registration/verify/${verificationId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${user.tenantId}
[/#if]
- FusionAuth AdminReplacement Variables#
application Application Available since 1.21.0The Application object, see the Application API for field definitions.
baseUrl String Available since 1.68.0The base URL used when rendering links in this template. FusionAuth resolves this value from the Application baseURL, then the Tenant baseURL, then a local development fallback URL.
registration The User Registration object, see the Registration API for field definitions of a User.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
user User The User object, see the User API for field definitions of a User.
verificationId String The verification Id intended to be used by the Verify a User Registration API.
verificationOneTimeCode String The verification One Time Code to be used with the Gated Registration workflow. The user enters this code to verify their email.
Set Up Password#
Your account has been created and you must set up a password. Click on the following link to set up your password.
<p>
[#assign url = "${baseUrl}/password/change/${changePasswordId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${user.tenantId}" /]
<a href="${url?html}">
${url?html}
</a>
</p>
- FusionAuth AdminYour account has been created and you must set up a password. Click on the following link to set up your password.
${baseUrl}/password/change/${changePasswordId}?client_id=${(application.oauthConfiguration.clientId)!''}&tenantId=${user.tenantId}
- FusionAuth AdminReplacement Variables#
application Application Available since 1.21.0The Application object, see the Application API for field definitions.
Note: This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined.
baseUrl String Available since 1.68.0The base URL used when rendering links in this template. FusionAuth resolves this value from the Application baseURL, then the Tenant baseURL, then a local development fallback URL.
changePasswordId String The change password Id intended to be used by the Change a User's Password API.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions of a Tenant.
user User The User object, see the User API for field definitions of a User.
Threat Detected#
This feature requires an Enterprise plan.
[#-- @ftlvariable name="event" type="io.fusionauth.domain.event.UserLoginSuspiciousEvent" --]
[#setting url_escaping_charset="UTF-8"]
[#if event.type == "UserLoginSuspicious"]
<p>A suspicious login was made on your account. If this was you, you can safely ignore this email. If this wasn't you, we recommend that you change your password as soon as possible.</p>
[#elseif event.type == "UserLoginNewDevice"]
<p>A login from a new device was detected on your account. If this was you, you can safely ignore this email. If this wasn't you, we recommend that you change your password as soon as possible.</p>
[#else]
<p>Suspicious activity has been observed on your account. In order to secure your account, it is recommended to change your password at your earliest convenience.</p>
[/#if]
<p>Device details</p>
<ul>
<li><strong>Device name:</strong> ${(event.info.deviceName)!'—'}</li>
<li><strong>Device description:</strong> ${(event.info.deviceDescription)!'—'}</li>
<li><strong>Device type:</strong> ${(event.info.deviceType)!'—'}</li>
<li><strong>User agent:</strong> ${(event.info.userAgent)!'—'}</li>
</ul>
<p>Event details</p>
<ul>
<li><strong>IP address:</strong> ${(event.info.ipAddress)!'—'}</li>
<li><strong>City:</strong> ${(event.info.location.city)!'—'}</li>
<li><strong>Country:</strong> ${(event.info.location.country)!'—'}</li>
<li><strong>Zipcode:</strong> ${(event.info.location.zipcode)!'—'}</li>
<li><strong>Lat/long:</strong> ${(event.info.location.latitude)!'—'}/${(event.info.location.longitude)!'—'}</li>
</ul>
- FusionAuth Admin[#setting url_escaping_charset="UTF-8"]
[#if event.type == "UserLoginSuspicious"]
A suspicious login was made on your account. If this was you, you can safely ignore this email. If this wasn't you, we recommend that you change your password as soon as possible.
[#elseif event.type == "UserLoginNewDevice"]
A login from a new device was detected on your account. If this was you, you can safely ignore this email. If this wasn't you, we recommend that you change your password as soon as possible.
[#else]
Suspicious activity has been observed on your account. In order to secure your account, it is recommended to change your password at your earliest convenience.
[/#if]
Device details
* Device name: ${(event.info.deviceName)!'—'}
* Device description: ${(event.info.deviceDescription)!'—'}
* Device type: ${(event.info.deviceType)!'—'}
* User agent: ${(event.info.userAgent)!'—'}
Event details
* IP address: ${(event.info.ipAddress)!'-'}
* City: ${(event.info.location.city)!'-'}
* Country: ${(event.info.location.country)!'-'}
* Zipcode: ${(event.info.location.zipcode)!'-'}
* Lat/long: ${(event.info.location.latitude)!'-'}/${(event.info.location.longitude)!'-'}
- FusionAuth AdminReplacement Variables#
application Application Available since 1.28.0The Application object, see the Application API for field definitions.
event.info EventInfo The EventInfo object, see the User Login Suspicious event definition for example field definitions.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions.
user User The User object, see the User API for field definitions of a User.
Two-Factor Authentication#
<p>
To complete your login request, enter this one-time code code on the login form when prompted.
</p>
<p>
<strong>${code}</strong>
</p>
- FusionAuth AdminTo complete your login request, enter this one-time code code on the login form when prompted.
${code}
- FusionAuth AdminReplacement Variables#
application Application Available since 1.46.0The Application object, see the Application API for field definitions.
This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined. You can check for this variable safely in FreeMarker using the missing value test operator and an if statement:
[#if application??]
[#-- Use application here --]
[/#if]
This object is not available on the email template when:
- The multi-factor workflow was started without providing the
applicationIdon that request. - Multi-factor authentication is required during a call to the login API without providing the
applicationIdparameter. That documentation points out that there is likely no production use case where calling the API without theapplicationIdparameter is useful. - The message is being sent to enable or disable a multi-factor method without providing the
applicationIdon the request.
code String A code that the user must provide to complete multi-factor authentication.
tenant Tenant Available since 1.18.2The Tenant object, see the Tenant API for field definitions.
user User The User object, see the User API for field definitions of a User.
Two-Factor Authentication Method Added#
This feature requires an Enterprise plan.
<p>
The following two factor method was added to ${user.email}:
<br>
<strong>Method: ${method.method}</strong>
<br>
<strong>Identifier: ${method.id}</strong>
</p>
- FusionAuth AdminThe following two factor method was added to ${user.email}:
- Method: ${method.method}
- Identifier: ${method.id}
- FusionAuth AdminReplacement Variables#
application Application Available since 1.28.0The Application object, see the Application API for field definitions.
Note:
This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined. You can check for this variable safely in freemarker by wrapping the variable as such: ${(application)!""}.
event Event The Event object for a two-factor add event. See the Webhooks & Events section for field definitions.
method Object The two-factor method that was added. See the Multi-Factor/Two-Factor APIs for property definitions and example JSON.
tenant Tenant The Tenant object, see the Tenant API for field definitions.
user User The User object, see the User API for field definitions of a User.
Two-Factor Authentication Method Removed#
This feature requires an Enterprise plan.
<p>
The following two factor method was removed from ${user.email}:
<br>
<strong>Method: ${method.method}</strong>
<br>
<strong>Identifier: ${method.id}</strong>
</p>
- FusionAuth AdminThe following two factor method was removed from ${user.email}:
- Method: ${method.method}
- Identifier: ${method.id}
- FusionAuth AdminReplacement Variables#
application Application The Application object, see the Application API for field definitions.
Note:
This object may not be available depending upon when this template is constructed. If you utilize this object in your template, ensure you first check to see if it is defined. You can check for this variable safely in freemarker by wrapping the variable as such: ${(application)!""}.
event Event The Event object for a two-factor remove event. See the Webhooks & Events section for field definitions.
method Object The two-factor method that was removed. See the Multi-Factor/Two-Factor APIs for property definitions and example JSON.
tenant Tenant The Tenant object, see the Tenant API for field definitions.
user User The User object, see the User API for field definitions of a User.
Admin Two-Factor Authentication Method Removed#
<p>
Your ${(method.method == "sms")?then("SMS", method.method)} two-factor authentication method[#if method.name?has_content], ${method.name},[/#if] was removed from ${user.email} by your administrator. Contact your administrator if you have questions.
</p>Your ${(method.method == "sms")?then("SMS", method.method)} two-factor authentication method[#if method.name?has_content], ${method.name},[/#if] was removed from ${user.email} by your administrator. Contact your administrator if you have questions.Replacement Variables#
method Object Available since 1.68.0The two-factor method that was removed by an administrator. See the User API under user.twoFactor.methods for property definitions and example JSON.
tenant Tenant Available since 1.68.0The Tenant object, see the Tenant API for field definitions.
user User Available since 1.68.0The User object, see the User API for field definitions of a User.
Related
Learn how to write and manage email templates.
A list of default message templates.
API documentation for the FusionAuth Create an Email Template API.
Learn about the APIs for creating, retrieving, updating and deleting email templates as well as sending emails to users.