Documentation
Account recovery.
This page covers your billing portal login only. Your HSM environment has its own separate sign-in with its own recovery, described in Getting started. A lost billing portal password never touches your keys.
One button, two paths
The portal sign-in page has one recovery control: “Forgot password?”. You enter your email and nothing else. We look at the account behind that address and email you the step that actually applies to it.
There are two possible steps. An account that can reset itself receives a reset code. Every other account receives a link that opens a support request for you. You do not choose between them and you do not need to know which one you are before you start.
You cannot tell which path you are on from this screen.
Whatever you type, the confirmation on screen reads the same. The answer arrives in your mailbox instead. The reason is in Why this screen gives no answer.
Who resets their own password
Two things must both be true. Your account has an authenticator enrolled, and you can open that authenticator right now and read a current six digit code from it.
Enrollment on its own is not enough. We ask for a live code during the reset, so an account whose authenticator was lost, wiped, or left on a replaced phone goes to the support path even though the enrollment still exists on our side.
Resetting your password
Have your authenticator open before you begin. The reset asks for a code from it in the same step as your new password. Codes roll over roughly every thirty seconds.
- Ask for the email. On the portal sign-in page, choose “Forgot password?” and enter your email address.
- Copy the reset code. Open the email we send and take the code out of it.
- Fill in all four fields. The email links straight to this step. You can also reach it from the sign-in page by choosing “I have a reset code”. Enter your email, the reset code, a current code from your authenticator, and your new password.
- Sign in. Use the new password. Your authenticator answers the usual prompt afterwards.
Your new password needs at least twelve characters with an upper case letter, a lower case letter, a number, and a symbol. Your existing authenticator enrollment survives the reset, so you are not asked to scan a new QR code afterwards.
When it becomes a support request
If your account cannot reset itself, the email you receive carries a link rather than a code. Clicking that link opens a support request on our side, already filled in with what we need to work on it. You never write a message, quote an account number, or describe your problem to us.
The link works once and stays valid for 24 hours. After you click it, the portal confirms that your request is open, and we reply to the same address the link was sent to.
What you need on hand: access to that mailbox, and nothing else. Support verifies the account before changing anything on it, so expect that verification step rather than an immediate reset.
Losing your authenticator
A lost authenticator is a support request, always. We cannot verify a code you cannot produce. We will not remove the second factor from an account on an emailed request alone.
Start it the same way: the recovery button on the sign-in page. If you already know the authenticator is gone, you can request recovery and use the support link that arrives. If you tried a reset first and your code was refused, we email you that support link automatically, so check your mailbox before trying again.
Once support restores access, the portal asks you to enroll a fresh authenticator at your next sign-in. Enroll a second administrator with their own login and their own authenticator. A lost authenticator then stops being an outage for your account.
An account holds one authenticator per user.
Enrolling a new one replaces the old one. While the enrollment QR code is on screen, scan it into a second authenticator app or store the secret somewhere you control. Losing that phone then costs your account an inconvenience rather than a support ticket.
Support or self-serve
Reach for the reset when you have forgotten your password and your authenticator is in your hand. That is the only case that finishes without us.
Everything else is a support request: a lost or wiped authenticator, an invitation you never finished, an account someone disabled, or an address you are no longer sure we hold. Use the same recovery button for all of them. It routes you.
For a question that is not about getting back in, use the contact form instead. It reaches the same people without consuming a recovery link.
When something does not go to plan
The email never arrives. Check spam first. We accept one recovery request per address every ten minutes, so an immediate second attempt is quietly ignored rather than sent. Wait ten minutes and request again. If the second one does not arrive either, the address may not be the one on your account. Use the contact form from a different address and say which account you are asking about.
The reset code expired. Reset codes are short lived by design. Request recovery again and use the newer email. Older codes stop working once a newer one is issued, so always work from the most recent message.
The reset was refused. The form reports one message for every cause and does not say which of the four fields failed. Do not re-enter the same reset code. A reset code is spent by the attempt that used it, whether or not that attempt succeeded, so a second try with the same code cannot work. Request recovery again and work from the newer email.
Your authenticator code was the problem. When the reset code was right and the authenticator code was not, we email you a support link automatically, because that combination is what a lost authenticator looks like. Check your mailbox before starting over. Treat your password as changed and your old one as gone: finish through the support link rather than assuming the old password still works.
The support link says it is invalid. Each link works once and expires after 24 hours. If you already clicked it, your request is open and no second click is needed. If it expired, request recovery again for a new one.
You expected a code and got a support link, or the reverse. The email reflects what your account looked like at that moment. An authenticator enrolled on a device you no longer have still reads as enrolled to us, which is exactly the case the live code check is there to catch. Follow whichever instruction the email gives. If it does not match your situation, use the support link and tell us in the reply.
Why this screen gives no answer
A recovery page that answered differently for a real address than for an invented one would let anyone test addresses against it and learn who has an account with us. That is a list worth stealing, and building it would take an afternoon.
So we show one answer to everyone. The specifics go to your mailbox, where reaching them means already controlling the address. The cost is that you cannot tell from the screen whether we recognized your email. We think that trade is the right way round. We would rather explain it here than quietly make this screen more helpful to an attacker.