Skip to content
Friday
Docs
GuidePricingLog in Sign up
Menu
GuidePricingLog inSign up

All documentation

Password Reset

2026-09-13

Use the password reset page when you cannot remember your password or need to replace it. The reset process sends a private, temporary link to the email address on your account. You do not need to know your old password.

Request a password reset

Follow these steps from the login page:

  1. Open the password reset page from the login screen.
  2. Enter the email address you use for your Friday account.
  3. Submit the form once.
  4. Look for an email with the subject Reset your password.
  5. Open the link in that email within one hour.

The page shows the same confirmation whether the email belongs to an account or not. It also shows that confirmation when the system suppresses a request because too many reset attempts were made. The shared response prevents someone from using the form to discover which email addresses have accounts.

Check the spelling of your email before you submit. If you entered the wrong address, return to the form and make a new request with the correct address. A reset email can only go to the email address already stored on the account.

Use the reset email

Open the newest email with the subject Reset your password. The link works for one hour from the time the request was stored. It can be used once.

Enter a new password with 12 to 128 characters, then submit the form. If the reset succeeds, the site sends you to the login page. Log in with your account email and the new password.

A password can contain spaces and other characters, as long as its total length is within the allowed range. Choose a unique password that you do not use for another service. A password manager can create and store one for you.

Do not forward the reset email or paste its link into a shared chat. Anyone who can open a valid reset link can choose a new password for the account. If you shared it by mistake, request another reset immediately. The new request replaces the earlier reset, so the earlier link will no longer work.

Understand how the link is protected

The email contains a private reset link. The app checks a protected digest of its token when you submit a new password. A stored copy of the email also contains the link for delivery, so hashing the verification token does not make the email safe to share. Keep reset emails private just as you would keep your password private.

Each account has one current reset record. A new request replaces the previous record, even if the previous link has not reached its one hour expiry. A successful reset clears the record, so the same link cannot be used again.

The one hour limit and single use rule reduce the time in which a copied link can be misused. They do not make it safe to publish or forward a link. Treat the email as private until the link has expired or has been used.

For a wider explanation of sessions, private links, and stored data, read Privacy and Security and the current Privacy Policy.

If the reset email does not arrive

Start with checks that do not create another request:

  1. Wait long enough for your mail provider to process a new message.
  2. Search for the exact subject Reset your password.
  3. Check spam, junk, and other filtered folders.
  4. Confirm that you entered the account email, including its spelling.

Email delivery is not guaranteed, and a delayed message can arrive after its reset link has expired. If you request several links, only the newest one can work. Delete the older reset messages or ignore them so you do not open a replaced link by mistake.

Reset requests are rate limited to prevent abuse. If repeated requests do not produce a new message, stop submitting the form and wait before trying again. Repeated clicks cannot make a suppressed request send mail, and they can make it harder to tell which email is newest.

If the problem continues, use the Support email link in the site footer. No guaranteed response time or round-the-clock support is promised.

If the link is invalid or expired

An invalid or expired message can mean that the link is more than one hour old, has already been used, or was replaced by a newer request. It can also mean that the link was copied incompletely.

Return to the password reset page and make one new request. Use only the latest email, and open its full link in the same form in which it arrived. Do not edit the link.

If the form says "Bad request," reload the reset page before trying again. The form contains a session protection value, and an old open tab may no longer have a matching value. Preserve any password you generated in your password manager before reloading. See Troubleshooting for help with 400, 404, and 429 responses.

What happens to existing sessions

A successful password reset revokes all older signed in sessions for the account. A browser that was already signed in will need to log in again. The reset browser also returns to the login page instead of signing in automatically.

Normal account sessions last up to 12 hours, but revocation can end them sooner. Logging out also revokes all older sessions for the account, rather than removing only the cookie in the browser where you clicked Log out.

Session revocation is useful if you reset the password because another person may have accessed the account. After the reset, sign in again and review your projects. You can also regenerate any project link that may have been shared beyond its intended recipients. Read Managing Projects for link management and Account Settings for account guidance.

Keep access records current

Your account email controls password recovery, so keep access to that mailbox secure. Use the account email consistently when you log in or request a reset. If you lose access to the mailbox, the normal reset flow cannot deliver a link to a replacement address.

Client project links use a separate access method and are not changed by a password reset. Anyone who has a current project link can still read that client page and reply. Regenerate a project link separately when you need to revoke it. The Client Page guide explains what a link holder can access.

A password reset link lasts one hour, works once, and is replaced when you request a newer link. For the first account setup steps, see Getting Started. For broader writing and delivery guidance, use the Guide.

Guide · Blog · Docs · Pricing · Terms · Privacy · Support