# Password & Recovery

Your JARVIS password is the most direct way into your account. Set one even if you signed up with
Google or GitHub.

## Requirements

| Rule | Value |
| --- | --- |
| Minimum length | 8 characters |
| Maximum length | 128 characters |
| Other rules | None — but a long passphrase is stronger than a short complex one |

JARVIS never asks you for your password inside a conversation, and it will never repeat one back
to you.

## Forgot your password?

The recovery flow is on the app itself:

1. Open [jarvis.spacekeep.dev/login](https://jarvis.spacekeep.dev/login).
2. Choose **Forgot password?**
3. Enter your email address and submit.
4. If an account exists for that address, a reset link lands in your inbox.
5. Open the link and choose a new password.

### Why you may see no email

The reset page always shows the same confirmation, whether or not the address has an account:

> If an account exists for that address, a reset link is on its way.

That is deliberate — it stops the form being used to discover which addresses are registered. If
you are expecting a message and none arrives:

- Check spam and promotions.
- Confirm you used the address you signed up with.
- Wait a minute — requests are rate limited per address.
- Try again once. Repeated requests only make it slower.

### About the reset link

| Property | Behaviour |
| --- | --- |
| Lifetime | 30 minutes |
| Use | Once |
| Repeated requests | Requesting a new link invalidates the old one |
| On success | A security notification email is sent |

## Changing your password

If you know your current password, you can set a new one by signing in and using the same reset
flow, or by changing it from your account settings.

### Changing it signs you out everywhere

When a password reset succeeds:

- Every active session for the account ends, on every device.
- Any outstanding reset links are invalidated.

This is deliberate — if someone reset your password, anyone holding a stolen session loses it too.
You will need to sign in again, which is why JARVIS sends the security notification email.

## Accounts created with Google or GitHub

An account created through a provider has no password until you set one. To add one:

1. Open **Forgot password?** on the sign-in page.
2. Enter the email address you signed up with.
3. Follow the reset link and choose a password.

After that you can sign in with either method.

## Password safety

- Use a password you do not use anywhere else.
- Prefer a long passphrase over a short complicated one.
- Never paste credentials into a JARVIS conversation. JARVIS does not store credentials as
  memories, but sending them anywhere is unnecessary.
- JARVIS will never email you a password or ask you to confirm one over chat.

## Related

- [Sign In](/jarvis/account/sign-in/) — providers and account linking
- [Sessions & API Keys](/jarvis/account/sessions/) — ending sessions and revoking keys
- [Security](/jarvis/security/) — how JARVIS protects credentials
- [Troubleshooting — Password problems](/jarvis/troubleshooting/#password-problems)
