Forgot your master password? Why no one can reset it
Forgot master password? With end-to-end encryption no one can reset it. How recovery codes work, how Cappa handles recovery and where to keep your code.

On this page
If you forget the master password to an end-to-end encrypted app, no one can reset it for you: not support, not the administrator, not the company that built the app. The password is the key to your data, and the provider never had a copy of it. What can get you back in is a recovery code, a second key you saved when you created the account.
Below: why a "forgot master password" link can't work the way it does for your email, what a recovery code is, how recovery works in Cappa step by step, and how to store the code so it's there when you need it and nowhere else.
Why can't encrypted apps reset your password?
Think about what happens when you click "Forgot password?" on a typical website. The service emails you a link, you prove you can read that inbox, and it lets you pick a new password. Your data was never locked with the old password. It sat on the company's servers in a form the company could read, and the password was only the lock on the front door. Changing the lock doesn't touch anything inside the house.
End-to-end encryption works differently. Your notes are encrypted on your own device before they are uploaded, and the key that decrypts them is derived from your master password inside your browser. The server stores sealed boxes it cannot open. This is the whole point: a breach of the server, a curious employee or a legal demand gets ciphertext, not your notes. (Our guide to end-to-end encrypted notes explains this in more detail.)
So when you forget the master password, the provider faces two options, and both are bad:
- Give you a fresh, empty account. The password changes, but the old sealed boxes stay sealed. Your data is effectively gone.
- Keep a spare key for everyone. Then the provider could open your data at any time, and so could anyone who steals, leaks or subpoenas that spare key. At that point the encryption no longer protects you from the provider.
Service with a reset link
- The provider can read or decrypt your data
- A reset link sets a new password and everything is still there
- Anyone who takes over your email can often take over the account
End-to-end encrypted service
- The provider stores only encrypted data
- Nobody can reset the password and keep the data readable
- You need your own backup key: a recovery code, a recovery contact or similar
Serious end-to-end encrypted services answer this the same way: they give you a way to create your own backup key, and they are upfront that without it they cannot help. That backup key is what the rest of this article is about.
What is a recovery code?
- Recovery code
- A long random value created on your device when you set up your account. It can unlock your encrypted data on its own, without the master password, and it exists so you can set a new password if you forget the old one.
Here's the everyday picture. Your notes are locked with one random vault key. Nobody types that key; it's generated by your browser. To store it safely on the server, the app puts a copy of the vault key into a sealed envelope. In Cappa there are two such envelopes:
- the password envelope, which only a key derived from your master password can open;
- the recovery envelope, which only a key derived from your recovery code can open.
Both envelopes hold the same vault key. That's why the recovery code works as a real replacement: open either envelope and you have the key to your notes. Forget the password, and the recovery envelope still opens.
What the server stores for your vault
Password envelopeopens with your master password
Vault key (copy 1)
Recovery envelopeopens with your recovery code
Vault key (copy 2)
Your notesencrypted with the vault key
4jRMClyL7HWxXe8jfJZh1sgPfAiZEACJ6Daluu0meQharqN6IcRwaB-xmcf7CSExPyuhw5RnWhy a recovery code can't be guessed
A master password is something a human picks, so its strength varies. A recovery code is different: your browser generates it from 256 random bits. In Cappa, the code looks like recovery-v2. followed by 43 letters, digits, hyphens and underscores.
To put that number in perspective, here's a rough estimate. Suppose an attacker could test a trillion codes per second. On average they would need to try half of all possible codes, which at that speed takes around 10⁵⁷ years. The universe is about 1.4 × 10¹⁰ years old. Guessing is not a realistic attack; stealing the code is.
The server never sees the code
The server needs some way to check that you have the right code, without learning the code itself. Your browser therefore derives a few separate values from the code, and the server stores only fingerprints (hashes) of them, called verifiers. A fingerprint lets the server confirm "yes, this matches" without being able to work backward to the code. The code itself stays with you, and the recovery envelope is opened in your browser, not on the server.
Forgot your master password in Cappa? How recovery works
Cappa shows your recovery code once, during registration, before the account is created. You copy it, save it, and only then confirm with "I saved it, create account". If you close the page at that point, no account exists yet, so you can't end up with an account whose code you never saw.
If you later forget your master password, recovery goes like this:
- Contact the administrator of your Cappa server, the person or team who sent your invitation. They confirm your identity through a channel other than the code itself, then open a recovery window for your account. At the time of writing, the window stays open for 60 minutes and closes once it's used.
- Open the sign-in screen and choose "Forgot password?". Recovery needs an internet connection, so the button is disabled while you're offline.
- Enter your email and the recovery code. The server checks a value derived from the code against its verifier, never the code itself. Your browser then opens the recovery envelope locally.
- Choose a new master password. Your browser checks it against the same rules as at registration: at the time of writing, at least 16 characters and rated hard to guess by a strength estimator. Our article on how long a master password should be helps you pick a good one.
- Save your new recovery code. Recovery always issues a new code, and the one you just used stops working. Confirm with "I saved it, finish recovery".
- Sign in again on your other devices. Finishing recovery signs out every session and unlinks every device that was syncing. Each one needs the new master password.
Your notes are untouched throughout. Recovery doesn't decrypt and re-encrypt them; it creates new envelopes around the same vault key.
Why does the administrator have to open a window?
The window is a second lock. A recovery code found in a drawer, or copied from a screenshot, is useless on its own: without an open window, the server refuses to start a recovery. The administrator only opens one after confirming that the request really comes from you.
The window has a cost too. While it's open, whoever holds your code can use it, which is why the identity check matters and why the window is short. When the server has email set up, Cappa also sends the account owner a short plain-text email when a recovery window opens, when a recovery completes, when the master password or recovery code changes, and when a new device is added to the account. The emails contain no links or secrets. Treat them as a warning signal, not a lock: they help you notice a recovery you didn't ask for, but they can't stop it.
What an administrator can't do
The administrator can send invitations, open recovery windows and delete an account together with its vault. They cannot reset your master password or read your notes. A password set from the server's side wouldn't open either envelope, because the administrator doesn't have your vault key.
Lost your recovery code but still know your password?
That's the easy case, as long as you act before you also forget the password. In Cappa, open Settings → Security and choose New code next to "Recovery code". You'll be asked for your current password and your current recovery code.
If the code is lost, leave that field empty and ask the administrator to allow a new code for your account first. Cappa shows the new code once. The old code keeps working until you confirm "I saved it, replace the code", so a dropped connection can't leave you without either.
Do the same if the code might have been exposed: you photographed it, it sat in an email, or someone saw the paper. Once you replace it, the old code stops working.
How to store a recovery code safely
A good hiding place for a recovery code has three properties:
- It won't fail together with your master password. The code exists for the day the password is lost. If both live in the same place, one mishap takes both.
- Nobody else can casually read it. Not your email provider, not a cloud photo library, not whoever borrows your laptop.
- You can find it in five years. Label it clearly, and remember where it is.
Here's how the common options compare:
| Where you keep it | Good | Watch out |
|---|---|---|
| Printed on paper, in a safe place at home (a document folder, a fireproof box) | Offline, can't be hacked remotely, survives a lost phone | Fire, water, moving house; anyone with access to the drawer |
| A second paper copy somewhere else (a family member you trust, a safe deposit box) | Survives a disaster at home | Each copy is one more place it can leak from |
| An entry in your password manager | Encrypted, easy to find, synced across devices | If you lose access to the password manager, you likely lose the master password and the code together. If someone breaks into it, they get both |
| Email, unencrypted cloud notes, a screenshot or a photo | Easy | Copied to servers you don't control, often synced and backed up automatically. Avoid |
| Inside Cappa itself | None | The code would be locked inside the vault it's meant to open. Avoid |
The password manager deserves an honest word. It's a reasonable place for many secrets, and Cappa's recovery window means a stolen code alone doesn't open your notes. The problem is correlation: most people forget a master password precisely when they've lost access to wherever they kept it. A paper copy is the backup that doesn't depend on any device, account or password. If you do keep the code in a password manager, keep a paper copy too.
Other companies give the same advice for the same reason. Apple, for example, tells people setting up an Apple Account recovery key to print it or write it down and keep it somewhere secure, and warns against storing it in the Passwords app, iCloud Photos, Notes or iCloud Drive, since those are exactly what you'd be locked out of.
How other encrypted services handle a forgotten password
Cappa isn't unusual here. Every service that truly can't read your data needs some kind of backup key that you hold. As of September 2026, according to each company's own help pages:
| Service | Can support reset your password? | What you can use instead |
|---|---|---|
| Bitwarden | No | A password hint, emergency access through a trusted contact (paid plans), account recovery by an organization admin (Enterprise), a passkey with encryption enabled, or an app still logged in with PIN or biometric unlock, from which you copy your data into a new account. Otherwise you delete the account and start over |
| 1Password | No | The Emergency Kit (a PDF with your Secret Key and a space to write your password), recovery codes for individual and family accounts (you also need access to your account email), or recovery by a family organizer or team administrator |
| Apple, with Advanced Data Protection | No, for end-to-end encrypted iCloud data | Your device passcode, a recovery contact, or a 28-character recovery key. Apple says it can't provide the key if you lose it |
| Cappa | No | A recovery code, used during a recovery window the administrator opens after confirming your identity |
One common mix-up behind searches for a "lost recovery key": some services use "recovery code" for something else. Bitwarden's recovery code, for instance, is a way around two-step login if you lose your authenticator. It doesn't recover a forgotten master password. Before you rely on any code, check which lock it actually opens.
FAQ
Can the Cappa team reset my master password?
No. The password never leaves your browser, and the server has only encrypted envelopes it can't open. An administrator can open a recovery window so you can use your recovery code, but can't set a password that would unlock your notes.
I lost both my master password and my recovery code. Is there anything I can do?
Check whether any device still has your vault unlocked, for example a browser tab you left open. Act soon: by default an idle tab locks itself after an hour. If a device is still unlocked, export your notes right away from Settings → Data, since that export is readable Markdown or a backup file. If no device is open, the notes can't be decrypted, and the only way forward is a new account.
Can someone who finds my recovery code read my notes?
Not on its own. Cappa refuses to start a recovery unless the administrator has opened a recovery window for your account, and they confirm your identity first. Treat a found or exposed code as compromised anyway, and replace it in Settings → Security.
Does using the recovery code delete or change my notes?
No. Recovery creates a new password envelope, a new recovery code and new sign-in credentials, all around the same vault key. Your notes stay exactly as they were, but you'll need to sign in again on every device.
Is a recovery code the same as two-factor backup codes?
No. Two-factor backup codes let you finish a sign-in when you lose your second factor, and they usually don't decrypt anything. A Cappa recovery code is a key: it can open your vault key and let you set a new master password.


