Theme
Change or reset your password
Everything on this page happens in the web client, the version you use in a browser. SFTP and FTPS programs cannot change a password; they only use it.
Change your password
- Sign in to the web client.
- Open Settings from the menu under your name.
- Under Password, type your current password, then the new one twice.
- Choose Change password.
Your site may have rules about length and the mix of characters; the form states them while you type, and the server refuses a password that does not meet them.
Changing your password signs out every other web client session you have open and forgets any browser you asked it to trust. The one you are using stays signed in. Anything you had connected with an SFTP or FTPS program keeps working until it disconnects, and reconnects with the new password.
Every change of your password, made by you here or through a reset link, is confirmed by a message to the email address on your profile, if you have one. The message carries no link; it only says when and from where the change was made. If you did not make it, tell the person who manages your access.
When you are asked to change it at sign in
Your administrator can require a new password the next time you sign in. When they have, the web client signs you in as usual (your password and, if you have one, your second factor) and then shows Choose a new password before anything else. Nothing else in the web client works until you do.
Your current password is already filled in, because you just proved it. Type the new one twice and choose Change password; you land in your files.
This applies to the web client only. An SFTP or FTPS program keeps accepting your current password until you change it, so a scheduled transfer does not stop. Once you change it anywhere, the old password stops working everywhere.
Forgot your password
If the sign in page shows Forgot your password?, your site allows you to reset it by email.
- Choose Forgot your password? and enter your username.
- The page says a message is on its way if the account has an email address on file. It says the same thing whatever you type, on purpose.
- Open the message and follow its link within thirty minutes. The link opens the web client on a page that asks for the new password twice.
- If you use an authenticator app, the page then asks for the code it shows, or for one of your recovery codes. Five wrong codes end the link.
- Choose Set the new password, then sign in with it.
The message comes under your site's name, not under any product name, and the link works once. Resetting your password ends every web client session you had open and forgets any trusted browser. Because the authenticator code is asked for on the reset page itself, someone who can read your mailbox still cannot choose your password when you have one. A passkey is still asked for when you sign in; a reset never skips it.
If the sign in page has no Forgot your password?, your site does not allow it. Ask the person who gave you your access to set a new password for you.
You will not receive a message if:
- the account has no email address on file,
- you sign in through your organization (there is no password here to reset),
- your account has no password, only an SSH key,
- you asked more than three times in an hour.
If the link does not work
| It says | What it means |
|---|---|
| This reset link is not valid | It expired, it was already used, or it was cut short when it was copied. Ask for a new one |
| The password was changed since this link was sent | Somebody (you, or your administrator) changed the password after the message went out. Sign in with the new one, or ask for a new link |
| That password was not accepted | It does not meet your site's rules. The form states them; nothing was changed and the link is still good |
| That code is not valid | The authenticator code or recovery code was wrong. Five wrong codes end the link; ask for a new one |