Skip to content

Forgot admin password ​

You can reset the admin login password at /recover. Recovery is off by default — set ADMIN_RECOVERY_ENABLED=true on the container and restart before it works. You also need ADMIN_INIT_PIN from deployment (same PIN as first /setup; see Admin — Setup).

Passkey sign-in is separate from the password. If Passkey still works, use /login with Passkey and skip recovery.

Prerequisites ​

RequirementNotes
/setup completed/recover is unavailable until initial setup is done
ADMIN_INIT_PINMust match the container env; store the random PIN safely on public deployments
ADMIN_RECOVERY_ENABLED=trueWithout it, /recover returns “recovery disabled”

See Environment variables.

1. Enable recovery and restart ​

Add to your docker run / Compose:

bash
-e ADMIN_RECOVERY_ENABLED=true
-e ADMIN_INIT_PIN=your_init_pin

Restart the IPA Harbor container after changing env vars. After an emergency reset, set recovery back to false or remove the variable and restart again to reduce abuse risk.

2. Open the recovery page ​

Either:

  1. Open /login, then click Forgot password? Admin recovery to go to /recover.
  2. Go to /recover directly in the browser, for example:
text
https://your-domain/recover

Local example: http://localhost:3388/recover (use your mapped port).

The recovery page states that ADMIN_RECOVERY_ENABLED=true must be set and asks for ADMIN_INIT_PIN. If recovery is disabled, submitting the form returns “recovery disabled”.

3. Submit the form ​

FieldNotes
UsernameSame admin username as at /setup (3–50 characters)
New passwordAt least 6 characters
Init PINMust match ADMIN_INIT_PIN

On success you are redirected to /login in a few seconds — sign in with the new password.

Outcomes ​

  • Username exists: Only the login password is reset. Registered Passkeys are not removed and still work.
  • Account recreated: Happens only when the database has no admin users (rare — usually data loss or a fresh volume).

“Username not found” means the name does not match the account created at setup.

If you still cannot sign in ​

  • Passkey still works: Use Passkey at /login, then change the password or manage Passkeys in Settings.
  • Lost init PIN: /recover cannot verify you; you need your own backup/recovery plan for /app/data, or redeploy knowing data implications.
  • Recovery was disabled: Enable ADMIN_RECOVERY_ENABLED=true, restart, then open /recover.

Apple ID (ipatool) is unrelated — see Apple ID login troubleshooting.