User guide
Password, PIN, and recovery codes
Manage account access and approval authority without mixing up their credentials.
OpenCircle keeps three things separate: your account password signs you in, recovery codes are one-time proof for recovering either credential, and your approval PIN confirms sensitive local actions.
Manage credentials while signed in
Open Settings → Account security → Account & password to change your password and manage recovery codes, and the separate Approval PIN section to create or change your PIN. OpenCircle issues eight recovery codes at a time, shows the plaintext only once, and regenerating the set instantly invalidates the old codes.
The approval PIN needs 6-8 digits, and common weak PINs are refused. Never store recovery codes next to the password they recover, and never send a code to support or a Server operator.
Recover a forgotten password
From the sign-in screen, choose Forgot password. A local development Server reached through localhost may offer a recovery-code relay for this; on an ordinary hosted Server, ask its operator for the documented recovery path instead. Repeated invalid attempts are rate-limited on purpose, and the response never confirms whether an account exists.
Recover a forgotten approval PIN
Sign in with your password first, since the PIN isn't a sign-in credential. Open Settings → Account security → Approval PIN → Forgot PIN, use an unused recovery code (or Verify with my password on Desktop), and set a new 6-8 digit PIN. If you've also lost the password, recover that first.
If no recovery code remains
While signed in, open recovery-code management, re-authenticate, and regenerate a fresh set immediately. Signed out with no password recovery available, ask a Server administrator for help — never send them your password, PIN, or recovery codes. An administrator can reset a member's password from the signed-in CLI with an explicit, verified handoff; that path is administrator-only and never bypasses PIN recovery on its own.