Password
Change, set, or reset the password you use to sign in with email.
Your account password is the credential for email sign-in. Change or set it from Account → Security. If you cannot sign in, use Forgot password? on the login page.
This is per-user. It is not an organization setting, and it is not the mailbox password on Settings → Email (SMTP).
After a successful change, set, or email reset you are signed out and must sign in again. A confirmation email is sent either way.
Change your password (signed in)
- Open your account menu (avatar) → Account.
- Go to the Security tab. The subtitle is “Password, two-factor authentication, sessions, and sign-in activity.”
- Under Password, enter Current password, New password, and Confirm password.
- If two-factor authentication is enabled, also enter an Authentication code (6-digit authenticator code or a backup code).
- Click Change password.
The new password must be 8–128 characters. Confirm must match (checked in the browser).
On success you see Password updated. Sign in again., then the sign-in page: Password updated. Sign in with your new password.
Wrong current password shows Current password is incorrect. Missing 2FA code shows A current 2FA code is required to change your password. A wrong code shows Invalid verification code.
Set a password (Google or Apple only)
If you sign in with Google or Apple and have never set a password, Security shows:
You sign in with Google or Apple. Set a password to also use email.
There is no current-password field. Enter New password and Confirm password, plus an Authentication code if 2FA is on, then Set password.
After you set one:
- Connections shows Email & Password.
- You can unlink Google or Apple even if it was your last social login.
- You can also use email and password on the sign-in form.
A first password can also be set from Forgot password? (inbox proof). The email does not say whether you already had a password.
Forgot password (not signed in)
- On Log in to Anchor, under the password field, click Forgot password?
- Enter the email you use to sign in and click Send reset link.
- The page always shows: If an account exists for that email, we sent a reset link. That sentence does not confirm whether the address is registered.
- If an account exists, platform mail (
noreply@, subject Reset your Anchor password) includes a Set new password link. It expires in 60 minutes and can be used once. - Choose a new password (at least 8 characters) on Set a new password, then Set password.
- You are signed out and sent to sign-in with Password updated. Sign in with your new password.
The reset link is not a sign-in. Completing it does not create a session and does not skip 2FA on the next login.
If the page says This reset link is invalid or has expired, request another from Forgot password. If the email button does not open the form, copy the full link from the message (including everything after #).
If you are already signed in, /forgot-password sends you to the dashboard — use Account → Security instead.
Two-factor authentication
| Flow | 2FA |
|---|---|
| Signed-in change or set | Required if 2FA is enabled (same idea as disabling 2FA). |
| Email reset | Not asked on the reset page (proof is inbox control). 2FA stays on. The next email/password sign-in still asks for an authenticator or backup code. |
Reset is not a way to turn 2FA off. If you lost the authenticator, use a backup code at sign-in, then rotate codes on Security. Losing inbox, authenticator, and backup codes is a support case ([email protected]).
After a password write
- Sign in with the new password (and 2FA if enabled).
- You get Your Anchor password was changed from the platform. If that was not you, contact
[email protected]. - Other browser sessions lose API access; use Sign out everywhere on Security if an old device still looks signed in.
- API keys stay valid. Rotate them separately if you need to.
A new-IP login alert that tells you to reset a password points at this forgot-password flow, then Sign out everywhere after you sign in.
Agents (MCP)
Agents must not be given your password or a reset link.
- Remote MCP:
get_password_statusreturnshasPassword(boolean) only. There is nochange_passwordorreset_passwordtool. - In-tab WebMCP:
anchor_get_contextincludes the samehasPasswordboolean.
Change and reset stay human-only on Account → Security and the login pages. See the MCP guide.
What this is not
- Not Settings → Email (organization SMTP mailbox password for invoices).
- Not a demo CRM task titled “forgot password” — that seed row is not the product.
- Not an email-address change (Profile still: contact support).
- Not magic-link login, SMS, or passkeys.
Related
- Two-Factor Authentication — reset does not skip 2FA
- API Keys — separate credential; not used to change a password
- Audit Log — password change / set / reset may appear when you belong to an organization