I like lost password flows…mainly because I have no memory. And I’m signed up to way too many sites.
casasugar.com (a member of the Sugar family of sites) impressed me…and then dropped the ball, I think.
- I do the “lost password” thing.
- I get an email with the typical link. Which I click on.
- Instead of getting the random password generated, Sugar logs me in directly with a one-time usage password.

I love the fact that they auto-logged me in. Love it. Wonderful. The message, though…needs some finesse-ing. And here’s where this would have been a home run for me…take me to my account page, so I can update my password. Or, at the very least make “change your password” a link, as a call to action.
That being said – I think there’s good experiences for different industries, too. Banking sites – Sugar’s process wouldn’t/shouldn’t work, no way. And don’t get me started on how stupid the WordPress lost password experience is.