Docs

Password change and other sign-in methods

Changing a password requires the current password and a new one. If two-factor authentication is enabled, you also need a code from the authenticator app. Linked services and passkeys continue to work separately.

DocumentationDocsGuideSettingsPassword SecurityAccount AccessTwo Factor Authentication

Current password

The current password confirms that the account owner is making the change, not someone who found an unlocked browser.

A unique password stored in a manager

Do not reuse the new password on another service. A password manager can store a long random password so you do not have to remember it.

Authenticator code

When two-factor authentication is enabled, the password form also asks for a current code from the authenticator app.

Sessions after password exposure

If someone else learned the old password, changing it is only the first step. Remove unknown sessions and replace the same password on any other service where it was used.