Passwords and recovery
The four ways back into Filarr, what each one reopens, and step by step: forgotten password, new password, new recovery phrase.
On this page
Documentation sections
Your password protects the key that encrypts your files. If you lose it, Filarr cannot reset it for you. What gets you back in is a recovery means that you saved in advance. Filarr has four of them, and they do not reopen the same thing.
Four ways back in
| Recovery means | You receive it | What it reopens | What it does not do |
|---|---|---|---|
| Profile phrase (12 words) | When you create a local profile in the setup wizard, without an account | This local profile, on this computer, if you forget its encryption password | It does not open a cloud account |
| Cloud account recovery phrase (24 words) | When you create a cloud account, and each time you regenerate it | Your account and its synced data, if you forget the account password | It does not open a local profile, and it does not turn off two-factor authentication |
| Recovery key (file) | When you create it yourself in Settings | This profile, on this computer, if its password is lost | It does not give access to the cloud account |
| Two-factor backup codes | When you turn on two-factor authentication | Each code replaces your authenticator app's code once, when you sign in | They unlock no data |
Settings → Security → Your recovery options lists the means that apply to your profile, with one line each.
12 words or 24 words?
This is the most common mix-up, so here is the rule:
- a local profile (no account) created in the setup wizard has a 12-word phrase, shown when you created it. A profile added later with New local profile has none;
- a cloud account has a 24-word phrase, shown when you created the account.
If you read somewhere that Filarr uses a 12-word phrase for everything, that was a mistake: a cloud account always has 24 words.
A profile that belongs to a cloud account has no 12-word phrase. Its way back in is the account's 24 words. If you type the wrong phrase, Filarr tells you: "That phrase does not open this profile. Check that these are the 12 words of THIS profile, not the 24 words of your Filarr account."
Forgot the password of your cloud account
You need the desktop app, your email address and your 24-word phrase. This reset isn't available in the web app.
- Open the sign-in screen, Sign in to Filarr. It appears when you add your account on a device, or after Sign in again in Settings → Account & Sync.
- Click Forgot password?.
- Enter your Email address.
- Type your 24 words in Account recovery phrase (24 words). A counter shows how many words you have typed.
- Choose a New password and type it again in Confirm password.
- Click Reset password.
Filarr reopens your key with the phrase and locks it again under the new password. All your devices are signed out: sign in again on each of them with the new password.
Two-factor authentication stays on after this reset. You still need your authenticator app, or a backup code, to sign in. Devices that Filarr remembered for 30 days are forgotten.
Filarr cannot reset a cloud account's password by email. Without the 24 words, a forgotten password cannot be recovered.
Forgot the encryption password of a local profile
You need the profile's 12-word phrase. Filarr offers this screen from the PIN screen of the profile picker.
- In the profile picker, Who's using Filarr?, click the profile.
- On the PIN screen, click Forgot PIN?.
- In the Reset PIN window, click Forgot encryption password?.
- Type the 12 words in Profile recovery phrase (12 words).
- Choose a New encryption password and confirm it.
- Click Recover access.
Forgot PIN? only appears when the profile has a PIN and Allow PIN reset is on. On a local profile, set a PIN with that option on, so you can reach this screen the day you need it. Lock Filarr explains how.
Change your password
- Open Settings → Security.
- Next to Change password, click Change.
- Enter your Current password.
- Enter the New password. It needs at least 10 characters, one uppercase letter and one digit. The checklist under the field ticks each rule as you type.
- Type it again in Confirm new password, then click Change.
Filarr shows Password changed successfully. Your files are not rewritten: only the lock around your key changes.
For a cloud account, the account password and the key change together, or not at all. If the server refuses, Filarr says so and your old password stays in effect. Your other devices are signed out. They show that their session has ended, with Sign in again. The device you used stays signed in.
A local profile may have no password at all. This is the case of a profile created with New local profile in the profile picker, until you set one. Its row then reads Set a password, with Enable, and a warning dot appears next to Security in the settings menu. Hover it to read No password set. Your files are not encrypted until you set a password.
Regenerate your account recovery phrase
Do this if you lost the paper, or if someone may have seen it. The old phrase stops working.
- Open Settings → Security.
- Next to Cloud account recovery phrase (24 words), click Regenerate phrase.
- Enter your Account password, and your Current TOTP code if two-factor authentication is on.
- Click Validate.
- Write down the 24 new words. Copy puts them on the clipboard. Print works in the desktop app.
- Tick the confirmation box, then click Done.
If your key was never locked under a phrase, the row reads Account recovery not set up. Click Set up recovery and follow the same steps.
In two cases, the 24 words shown when you created your account don't reopen your files: an account created on filarr.com, and an account created with Turn on sync from a local profile. In both cases, create a new phrase with the steps above as soon as your account is ready, even if the row reads Regenerate phrase. The new 24 words replace the old ones.
If Filarr warns that the new phrase could not be synced to the cloud, account recovery will not work until this device is back online. Regenerate the phrase again once you are connected.
Create and use a recovery key file
A recovery key is a file that holds this profile's encryption key, protected by a password of its own.
To create one:
- Open Settings → Security.
- Next to Recovery key (file), click Export.
- Choose a Recovery password, different from your vault password, and confirm it.
- Fill in Hint (optional, stored in plain text) if you like. Anyone who finds the file can read it, so it must not give the password away.
- Click Generate and download, then choose where to save the file.
Store the file off this computer, for example on a USB stick kept somewhere safe.
To use it, you restore it from Settings. Filarr must therefore be open on this profile, for example with its PIN.
- Open Settings → Security.
- Next to Recovery key (file), click Restore.
- Read the warning and tick I understand and want to continue.
- Click Choose the file and pick your recovery key. Filarr shows the profile name, the creation date and the hint.
- Enter the Recovery password, then choose a New vault password and confirm it.
- Click Restore.
Two-factor backup codes
When you turn on two-factor authentication, Filarr gives you 8 backup codes. Each one replaces your app's 6-digit code once, at sign-in. They do not reopen your data and they are not a recovery phrase. Two-factor authentication and passkeys covers them in detail.
If you belong to an organization, its recovery key can restore your access to the organization's vaults, never to your personal space. See Run your organization.