Recover access to your account

Set a new password with a one-time recovery link when you cannot sign in, and understand what happens to your sessions afterwards.

  • Availability: Experimental
  • Evidence: Recorded run
  • How-to guide

Before you start

Recovery is for an account that signs in with an email address and a password. You need to be able to read messages sent to that address.

If you sign in with GitHub or Google, Accounts holds no password for you. Recover access at that provider, then choose Continue with GitHub or Continue with Google again.

Ask for a recovery message

  1. On the Sign in screen, choose Forgot your password?. The password field disappears and the screen shows "Enter the address you sign in with. If it has an account here, a message is on its way."
  2. Fill in Email address.
  3. Choose Send a recovery message. To go back without sending, choose Back.

Expected outcome: "If that address has an account here, a recovery message is on its way."

You get this same sentence whether or not the address has an account. That is deliberate: a different answer would let anyone find out who has an account. If no message arrives, check the address you typed and your spam folder before asking again.

Set a new password

  1. Open the message and follow its link. It leads to a screen titled Choose a new password, with the line "This link works once. Setting a password signs you in."
  2. Fill in New password and Repeat it.
  3. Choose Set the password.

Expected outcome: the password is changed and you are signed in, on Overview. The one-time credential in the link is removed from the address bar as soon as the screen opens.

Checks you may see under the fields: "Use at least 8 characters." and "The two do not match."

A link that was already used, has expired or arrived incomplete shows "That link is no longer valid. Ask for another one." Under it there is a link that leads back to the sign-in screen. In the current interface that link is labelled Repeat it, which a recorded screen of a spent link shows; it is the way back, whatever its label suggests. Go back, choose Forgot your password? again and use the newest message only: each link works once.

If the provider refuses the link only when you choose Set the password, the screen shows "Your session expired. Sign in to continue." instead. It means the same thing: ask for a new link.

What happens to your sessions

  • Setting the new password signs you in on the browser where you did it.
  • The old password stops working.
  • Setting a new password does not, by itself, end sessions that were already open on other browsers or in products. This is read from the source of the interface and the service: the recovery screen sets the password and opens a session, and nothing in that path ends the others.

If you recovered the account because you think someone else was using it, finish with one more step: open Sign-in and sessions and choose Sign out everywhere. It ends every session of the account, in Accounts and in every product, including the one you are using. Then sign in again with the new password. See Sessions and signing out.

Limits

Next action

Signed in again? Review Sign-in and sessions: add a second way to sign in so that one lost password never locks you out.

Related: Sign in and create an account · Sessions and signing out · Accounts troubleshooting