All help sections
Account, password, MFA & sessions
Change your password
- Choose Account > Change password.
- Enter the current password and the new password as requested.
- Use 8–256 characters. There is no forced mixed-case/symbol rule.
- Complete the change. Because the credential is global, use the new password for every vault.
Forgot your password
- On Sign in, choose Forgot your password?
- Enter the account email and choose Send reset link.
- For privacy, the confirmation is the same whether or not an account exists.
- Open the email within 60 minutes, enter and confirm the new password, and submit.
- After reset, every device is signed out. Sign in again with the new password.
Use MFA or a recovery code at sign-in
- After the correct password, enter the six-digit code from the authenticator app.
- If the authenticator is unavailable, switch to recovery-code mode and enter one unused recovery code.
- Each recovery code works once. Generate a replacement set before the remaining codes run out.
Regenerate recovery codes
- Choose Account > Two-factor auth.
- Under Recovery codes, choose the regenerate action and confirm.
- Save the new one-time set immediately. The previous set stops working.
Session behavior
- Default inactivity timeout: 30 minutes unless a vault Admin sets an override.
- Allowed Admin override: 5–240 whole minutes.
- Multi-vault accounts use the most restrictive timeout among all active vault memberships, even while working in another vault.
- Absolute session lifetime: 30 days, regardless of activity.
- Password reset deletes every session for the account.