Service status & availability Crypto-only billing · No-KYC signup

Account & access

Recover your account with a one-time code

Reset a forgotten or compromised password using the recovery code, save its replacement, and understand what happens to existing sessions.

Tungsto documentation · Updated · 3 min read

On this page
  1. Before you start
  2. Choose recovery when the password must change
  3. Reset the password
  4. What changes after success
  5. If recovery is rejected
  6. If both the password and code are lost
  7. Related resources

Before you start

  • The username used for the account.
  • The latest recovery code saved during registration or a previous recovery.
  • A new unique password between 12 and 200 characters.

Choose recovery when the password must change

Use account recovery when you have forgotten your password or need to replace it after suspected exposure. The current account interface does not have a separate password-change screen. Recovery both changes the password and invalidates the account’s existing sessions. It does not cancel your servers, remove balance or create a replacement account.

You need the current recovery code, not just a code that once belonged to the account. Every successful recovery replaces it. If you recovered before, look for the replacement you saved at that time. An earlier code becomes unusable even if its text appears correct.

Reset the password

  1. Open Sign in and follow Use a recovery code, or open the account recovery page directly.
  2. Enter your username and paste the complete saved recovery code. Preserve its characters and hyphens; avoid selecting explanatory text around the code.
  3. Enter the new password. Use a different password from the exposed or forgotten one and save it before submitting.
  4. Select Reset password once and wait for the result. On success, the page displays a replacement recovery code.
  5. Save the replacement code and mark the old code as obsolete in your own records.
  6. Select I saved it — open dashboard. Confirm that your username, balance and servers are the expected account records.

What changes after success

Recovery signs the current browser into a new session. Sessions that were already open on this or another device are revoked. An old tab may still show previously loaded information, but its next protected request should require a fresh sign-in. Use the new password when reconnecting other devices you trust.

Server operating-system passwords and SSH keys are separate from the account password. Recovering the Tungsto account does not rotate a machine’s root password or remove keys from its operating system. If a compromised account may have been used to access a server, review that server separately and preserve any relevant records before taking disruptive action.

If recovery is rejected

  • Username or recovery code is incorrect: verify the username and that you are using the most recent code. Check for a missing character or a code saved under a different account.
  • Recovery was already used: another recovery may have completed first. Use the newly saved password and replacement code rather than replaying the old request.
  • Invalid password: choose a password within the displayed length limits, then resubmit with the current recovery code.
  • Too many attempts: pause before retrying. Do not continue guessing codes or cycling through accounts.

If both the password and code are lost

There is no automated route around the missing credentials. An email address, telephone number or identity document cannot trigger a reset because those are not collected during standard registration. Do not assume that a transaction hash or a server IP is sufficient proof to take over an account.

You can submit a contact request describing the access problem and save its reference and reply secret. Never include the recovery code or a password. The current contact form records a request; it does not provide a self-service conversation or a guaranteed account-recovery decision. Keep any independently available server backups while the access problem is unresolved.