Last reviewed: 2026-08-31
Reset your password
Request a password reset from the sign-in page and set a new password using the email link.
Purpose
Recover access to a CodeCleared account that uses email and password sign-in.
Who
Users who forgot their password or received an expired reset link.
Prerequisites
Your account must use email and password (not SSO-only). If your organization enforces SSO, see Access and single sign-on.
How it works
- Open the app sign-in page (
/login). - Click Forgot password?
- Enter your email address and submit the form.
- If an account exists, you receive an email with a reset link (
/reset-password?token=…). The link is valid for 2 hours. - Choose a new password (minimum 8 characters) and confirm it.
- Sign in again with your new password.
When already signed in, you can also change your password under Security in the app (/security).
For security, the forgot-password form always shows the same confirmation message whether or not the email is registered.
Business rules
Password reset applies to local email/password accounts. SSO users sign in through their identity provider.
Scenarios & edge cases
No email received: check spam, wait a few minutes, or try again. The product never confirms whether an address is registered.
Link expired or invalid: open /forgot-password and request a new link.
SSO-only organization: use your workspace SSO button on /login instead. See Access and single sign-on.
Limits
Reset links expire after 2 hours. You must sign in manually after reset — the product does not auto-log you in.
Common errors
- Expecting a different message when the email is unknown (anti-enumeration by design).
- Using password reset when SSO is required for your organization.