Skip to content
Cappa

Forgot your master password? How recovery codes work

Forgot your master password? Learn how recovery codes restore access to encrypted notes, how recovery works in Cappa and how to store your code safely.

A capybara at home carefully places a folded paper card into a small fireproof metal box inside an open desk drawer, with a row of key hooks on the wall behind it and one hook empty.
On this page

Forgot your master password? A recovery code can restore access to your encrypted notes. An email password reset alone cannot unlock data whose key the provider does not hold. End-to-end encrypted apps can still offer recovery through a saved code, a trusted device or another recovery method you set up in advance.

This guide explains how recovery codes work, how to recover your Cappa account step by step, and where to store your code safely.

Why isn't an email password reset enough?

An email reset link proves that you control an inbox and lets a service change your sign-in credentials. If the provider holds the keys to your stored data, it can keep that data available after the reset.

With end-to-end encryption, the provider does not hold the key needed to read your notes. In Cappa, your browser encrypts notes with a random vault key. A key derived from your master password protects a stored copy of that vault key. Setting a new password on the server cannot unlock that copy. Our guide to end-to-end encrypted notes explains the key hierarchy.

Recovery therefore needs another way to obtain the same vault key. A recovery code can unlock a separately encrypted copy; a trusted device may already hold the key. Some services also support recovery contacts or organization-managed recovery. Email verification can be part of these procedures without giving the provider access to your data. If every way to unlock the key is lost, a new sign-in password cannot bring the old data back.

Provider holds the data key

  • The provider can read or decrypt your data
  • A reset link sets a new password and everything is still there
  • Anyone who takes over your email can often take over the account

End-to-end encrypted service

  • The provider stores only encrypted data
  • An email reset alone can't make the data readable again
  • You need a backup you set up in advance: a recovery code, another signed-in device, a recovery contact or similar

Recovery options differ between encrypted services. Cappa uses a recovery code that opens a second encrypted copy of your vault key.

What is a recovery code?

Recovery code
A long random value created on your device when you set up your account. It can unlock your encrypted data on its own, without the master password, and it exists so you can set a new password if you forget the old one.

Here's the everyday picture. Your notes are locked with one random vault key. Nobody types that key; it's generated by your browser. To store it safely on the server, the app puts a copy of the vault key into a sealed envelope. In Cappa there are two such envelopes:

  • the password envelope, which only a key derived from your master password can open;
  • the recovery envelope, which only a key derived from your recovery code can open.

Both envelopes hold the same vault key. That's why the recovery code works as a real replacement: open either envelope and you have the key to your notes. Forget the password, and the recovery envelope still opens.

What the server stores for your vault

Password envelopeopens with your master password

Vault key (copy 1)

Recovery envelopeopens with your recovery code

Vault key (copy 2)

Your notesencrypted with the vault key

4jRMClyL7HWxXe8jfJZh1sgPfAiZEACJ6Daluu0meQharqN6IcRwaB-xmcf7CSExPyuhw5Rn
Your notes are encrypted with one vault key. The server stores two sealed copies of that key: one opens with your master password, the other with your recovery code. The server can open neither.

Why a recovery code can't be guessed

A master password is something a human picks, so its strength varies. A recovery code is different: your browser generates it from 256 random bits. In Cappa, the code looks like recovery-v2. followed by 43 letters, digits, hyphens and underscores.

256 bitsof randomness in a Cappa recovery code
about 10⁷⁷possible codes (2 to the power of 256)

To put that number in perspective, here's a rough estimate. Suppose an attacker could test a trillion codes per second. On average they would need to try half of all possible codes, which at that speed takes around 10⁵⁷ years. The universe is about 1.4 × 10¹⁰ years old. Guessing is not a realistic attack; stealing the code is.

The server never sees the code

The server needs some way to check that you have the right code, without learning the code itself. Your browser therefore derives a few separate values from the code, and the server stores only fingerprints (hashes) of them, called verifiers. A fingerprint lets the server confirm "yes, this matches" without being able to work backward to the code. The code itself stays with you, and the recovery envelope is opened in your browser, not on the server.

Forgot your master password in Cappa? How recovery works

Cappa shows your recovery code once, during registration, before the account is created. You copy it, save it, and only then confirm with "I saved it, create account". If you close the page at that point, no account exists yet, so you can't end up with an account whose code you never saw.

If you later forget your master password, recovery goes like this:

  1. Contact the administrator of your Cappa server, the person or team who sent your invitation. They confirm your identity through a channel other than the code itself, then open a recovery window for your account. At the time of writing, the window stays open for 60 minutes and closes once it's used.
  2. Open the sign-in screen and choose "Forgot password?". Recovery needs an internet connection, so the button is disabled while you're offline.
  3. Enter your email and the recovery code. The server checks a value derived from the code against its verifier, never the code itself. Your browser then opens the recovery envelope locally.
  4. Choose a new master password. Your browser checks it against the same rules as at registration: at the time of writing, at least 16 characters and rated hard to guess by a strength estimator. Our article on how long a master password should be helps you pick a good one.
  5. Save your new recovery code. Recovery always issues a new code. The old code no longer authorizes recovery through the server. Confirm with "I saved it, finish recovery".
  6. Sign in again on your other devices. Finishing recovery signs out every session and unlinks every device that was syncing. Each one needs the new master password.

Your notes are untouched throughout. Recovery doesn't decrypt and re-encrypt them; it creates new envelopes around the same vault key.

Why does the administrator have to open a window?

The window guards the recovery procedure on the server. Someone who finds your code in a drawer or copies it from a screenshot cannot use it to take over your account: without an open window, the server refuses to start a recovery, and the administrator only opens one after confirming that the request really comes from you.

The window is not a second layer of encryption, though. The recovery envelope is stored on the server, and the code alone is enough to open it. Anyone who has your code and a copy of Cappa's database or one of its backups (or control of the server itself) can open the envelope on their own computer, with no window involved, and then read your notes. The window protects against a stranger with only your code; it does not make the code less secret.

The window has a cost too. While it's open, whoever holds your code can use it, which is why the identity check matters and why the window is short. When the server has email set up, Cappa also sends the account owner a short plain-text email when a recovery window opens, when a recovery completes, when the master password or recovery code changes, and when a new device is added to the account. The emails contain no links or secrets. Treat them as a warning signal, not a lock: they help you notice a recovery you didn't ask for, but they can't stop it.

What an administrator can't do

The administrator can send invitations, open recovery windows and delete an account together with its vault. They cannot reset your master password or read your notes. A password set from the server's side wouldn't open either envelope, because the administrator doesn't have your vault key.

Lost your recovery code but still know your password?

That's the easy case, as long as you act before you also forget the password. In Cappa, open Settings → Security and choose New code next to "Recovery code". You'll be asked for your current password and your current recovery code.

If the code is lost, leave that field empty and ask the administrator to allow a new code for your account first. Cappa shows the new code once. The old code keeps working until you confirm "I saved it, replace the code", so a dropped connection can't leave you without either.

Do the same if the code might have been exposed: you photographed it, it sat in an email, or someone saw the paper. Replacing it stops the old code from authorizing recovery through the server. It does not protect you from someone who also obtained the old recovery envelope, as explained above.

How to store a recovery code safely

A good hiding place for a recovery code has three properties:

  1. It won't fail together with your master password. The code exists for the day the password is lost. If both live in the same place, one mishap takes both.
  2. Nobody else can casually read it. Not your email provider, not a cloud photo library, not whoever borrows your laptop.
  3. You can find it in five years. Label it clearly, and remember where it is.

Here's how the common options compare:

Where you keep itGoodWatch out
Printed on paper, in a safe place at home (a document folder, a fireproof box)Offline, can't be hacked remotely, survives a lost phoneFire, water, moving house; anyone with access to the drawer
A second paper copy somewhere else (a family member you trust, a safe deposit box)Survives a disaster at homeEach copy is one more place it can leak from
An entry in your password managerEncrypted, easy to find, synced across devicesIf you lose access to the password manager, you likely lose the master password and the code together. If someone breaks into it, they get both
Email, unencrypted cloud notes, a screenshot or a photoEasyCopied to servers you don't control, often synced and backed up automatically. Avoid
Inside Cappa itselfNoneThe code would be locked inside the vault it's meant to open. Avoid

The password manager deserves an honest word. It's a reasonable place for many secrets, as long as it is well protected: the recovery code is a real key to your notes, not just a way to ask for help. The problem is correlation: losing access to that manager could leave you without both the password and the recovery code. A paper copy is the backup that doesn't depend on any device, account or password. If you do keep the code in a password manager, keep a paper copy too.

Other companies give the same advice for the same reason. Apple, for example, tells people setting up an Apple Account recovery key to print it or write it down and keep it somewhere secure, and warns against storing it in the Passwords app, iCloud Photos, Notes or iCloud Drive, since those are exactly what you'd be locked out of.

How other encrypted services handle a forgotten password

Cappa isn't unusual here. A service that cannot read your data needs a recovery method that can restore your access to the key without giving it to the provider. As of September 2026, according to each company's own help pages:

ServiceCan support reset your password?What you can use instead
BitwardenNoA password hint, emergency access through a trusted contact (paid plans), account recovery by an organization admin (Enterprise), a passkey with encryption enabled, or an app still logged in with PIN or biometric unlock, from which you copy your data into a new account. Otherwise you delete the account and start over
1PasswordNoThe Emergency Kit (a PDF with your Secret Key and a space to write your password), recovery codes for individual and family accounts (you also need access to your account email), or recovery by a family organizer or team administrator
Apple, with Advanced Data ProtectionNo, for end-to-end encrypted iCloud dataYour device passcode, a recovery contact, or a 28-character recovery key. Apple says it can't provide the key if you lose it
CappaNoA recovery code, used during a recovery window the administrator opens after confirming your identity

One common mix-up behind searches for a "lost recovery key": some services use "recovery code" for something else. Bitwarden's recovery code, for instance, is a way around two-step login if you lose your authenticator. It doesn't recover a forgotten master password. Before you rely on any code, check which lock it actually opens.

FAQ

Can the Cappa team reset my master password?

No. The password never leaves your browser, and the server has only encrypted envelopes it can't open. An administrator can open a recovery window so you can use your recovery code, but can't set a password that would unlock your notes.

I lost both my master password and my recovery code. Is there anything I can do?

Check whether any device can still open your vault, for example an unlocked browser tab or a device where you enabled remembered access. Act soon: by default an idle tab locks itself after an hour. If a device is still unlocked, export your notes right away from Settings → Data, since that export is readable Markdown or a backup file. If no device can open the vault, the notes cannot be recovered, and you would need to start over with a new account.

Can someone who finds my recovery code read my notes?

Without an open recovery window, the server refuses to start a recovery. But someone with your code and a copy of its recovery envelope, for example from a database backup, can decrypt your notes offline. Replace an exposed code in Settings → Security to block future server recovery with it. Replacement does not rotate your vault key: the old code and old envelope still unlock that key, which also decrypts any later ciphertext encrypted with it that the attacker obtains.

Does using the recovery code delete or change my notes?

No. Recovery creates a new password envelope, a new recovery code and new sign-in credentials, all around the same vault key. Your notes stay exactly as they were, but you'll need to sign in again on every device.

Is a recovery code the same as two-factor backup codes?

No. Two-factor backup codes let you finish a sign-in when you lose your second factor, and they usually don't decrypt anything. A Cappa recovery code is a key: it can open your vault key and let you set a new master password.

Get notified when Cappa opens

Cappa is open by invitation only for now. The planned price is €29 per year. Leave your email and we will let you know when access opens. Joining is free and does not commit you to buy.

We use your address only to tell you when Cappa opens. The link in the email removes it at any time.

Written by the Cappa team

We build Cappa, a private Markdown notes app that encrypts your notes on your device before they are synced. We write about the decisions behind it, including the limits, so you can judge them yourself.