Forgot password
This page explains how to reset a forgotten password with a code sent to your email, and the rules every EyalSec password must follow.
Request a recovery code
If you cannot remember your password, EyalSec can email a one-time recovery code to the email address on your account. Click Forgot password? on the sign-in page to start.
- On the Password recovery page (
/login/forgot), enter your username or email. - Click Send recovery code.
The page always answers the same way: "If an account with that name or email exists, we've sent a recovery code to the email on file." It never says whether an account exists, so nobody can use it to find accounts.
The code is 6 digits and is valid for 15 minutes. Asking again within 5 minutes does not send a second email; use the code you already have.
If your account has no email address on file, there is nowhere to send the code. Add one in Settings while you can still sign in.
Enter the code and a new password
The Enter recovery code page (/login/forgot/verify) is where you finish the reset. It asks for your username or email, the 6-digit code, and your new password twice.
Click Reset password. On success you go to the sign-in page, which says "Your password has been reset. Please sign in." Sign in with the new password; the reset does not sign you in by itself.
- The new password is checked against the password rules before the code, so a weak password does not use up your code.
- Wrong, used and expired codes all give "Invalid or expired code." After five wrong tries a code stops working; click Request a new code.
- Too many attempts from one network are refused for a while.
A reset signs out every browser that was signed in to the account and emails a notice to your address that the password changed. Two-factor authentication is not affected: if it was on, you still need your code at sign-in.
Set a password on a Google account
An account created with Continue with Google has no password. To add one, use this same reset flow with your Google email address: the recovery code goes to that address.
After that you can sign in either way. You also need a password for actions in Settings that ask you to confirm it, such as generating an API key or deleting the account.
Password rules
Every password you set in EyalSec must be 8 to 72 characters long and must not be a commonly used password. The same rules apply when you register, change your password in Settings, or reset it here.
| Rule | Message if broken |
|---|---|
| At least 8 characters | Password must be at least 8 characters. |
| At most 72 characters | Password must be at most 72 characters. |
| Not on the list of common, easily guessed passwords | Password is too common. Choose something less guessable. |
A password manager that generates a long random password is the easiest way to meet all three. Still stuck? Email support@eyalsec.com.