Hey there @wwei, as you mentioned mustAcceptTerms is designed for the sign up process, specifically for users with username/email and password authentication. However it is not currently setup for the password reset use case. I can however add this as a feature request at Auth0: Secure access for everyone. But not just anyone. if you like. Please let me know if you have any additional questions. Thanks!