MVP behavior: the server returns a reset token directly so you can test immediately. Later we’ll email the token instead.