# How can I change forgotten password?

**URL:** https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544
**Category:** Support
**Created:** [18 September 2019 09:49 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544 "2019-09-18T09:49:12Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![alwashe](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/alwashe/32/36_2.png) [@alwashe](https://discourse.joplinapp.org/u/alwashe)
#### Post date: [18 September 2019 09:49 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/1 "2019-09-18T09:49:12Z")

</div>

I wanted to add a device and have forgotten the password.  
I have 3 Clients where I can access my notes.

How can I now safely change the password?

---

<div class="post-metadata">

### Author: ![foxmask](https://avatars.discourse-cdn.com/v4/letter/f/c68b51/32.png) [@foxmask](https://discourse.joplinapp.org/u/foxmask)
#### Post date: [18 September 2019 10:05 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/2 "2019-09-18T10:05:35Z")

</div>

which password ?

---

<div class="post-metadata">

### Author: ![alwashe](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/alwashe/32/36_2.png) [@alwashe](https://discourse.joplinapp.org/u/alwashe)
#### Post date: [22 September 2019 14:44 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/3 "2019-09-22T14:44:06Z")

</div>

Password for Encryption.

---

<div class="post-metadata">

### Author: ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)
#### Post date: [22 September 2019 14:45 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/4 "2019-09-22T14:45:00Z")

</div>

You can’t recover a forgotten password

---

<div class="post-metadata">

### Author: ![alwashe](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/alwashe/32/36_2.png) [@alwashe](https://discourse.joplinapp.org/u/alwashe)
#### Post date: [22 September 2019 15:23 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/5 "2019-09-22T15:23:03Z")

</div>

I have devices where I can read my notes because the password is saved.  
Can’t I export the Notes from there?  
What happens when I press “Disable encryption”?

---

<div class="post-metadata">

### Author: ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)
#### Post date: [22 September 2019 15:35 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/6 "2019-09-22T15:35:16Z")

</div>

If it’s from the desktop you can indeed export from there. For more info: [https://joplinapp.org/e2ee/](https://joplinapp.org/e2ee/)

---

<div class="post-metadata">

### Author: ![alwashe](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/alwashe/32/36_2.png) [@alwashe](https://discourse.joplinapp.org/u/alwashe)
#### Post date: [22 September 2019 15:37 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/7 "2019-09-22T15:37:01Z")

</div>

so i could just Disable encryption and set a new password?

---

<div class="post-metadata">

### Author: ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)
#### Post date: [22 September 2019 15:49 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/8 "2019-09-22T15:49:13Z")

</div>

Yes, you can disable then enable again.

---

<div class="post-metadata">

### Author: ![dpoulton](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/dpoulton/32/29723_2.png) [@dpoulton](https://discourse.joplinapp.org/u/dpoulton)
#### Post date: [23 September 2019 10:55 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/9 "2019-09-23T10:55:31Z")

</div>

I have found that the encryption password can be recovered if your client has the password stored. **Copy** the `database.sqlite` file from your Joplin `.config` directory to somewhere where you can tinker with it. Open it in a text editor and search for `encryption.passwordCache`. Immediately after that you will see a set of curly brackets containing two strings in quotes separated by a colon. The string **after** the colon is the encryption password. I have only tried this using the Windows client.

---

<div class="post-metadata">

### Author: ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)
#### Post date: [23 September 2019 13:33 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/10 "2019-09-23T13:33:52Z")

</div>

You can also open it with something like SQLite Browser then open the “settings” table and indeed look for passwordCache.

---

<div class="post-metadata">

### Author: ![angrybird](https://avatars.discourse-cdn.com/v4/letter/a/b9bd4f/32.png) [@angrybird](https://discourse.joplinapp.org/u/angrybird)
#### Post date: [29 January 2020 02:27 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/11 "2020-01-29T02:27:38Z")

</div>

Thank you so much! That saved me tons of recovery work! This time got lucky wont allow this to happen every again lol But at the same time started questioning Joplin security, keeping unencrypted password in db probably not good idea even though it helped me 🙂

---

<div class="post-metadata">

### Author: ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)
#### Post date: [29 January 2020 08:27 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/12 "2020-01-29T08:27:31Z")

</div>

[https://joplinapp.org/faq/#could-there-be-a-password-to-restrict-access-to-joplin](https://joplinapp.org/faq/#could-there-be-a-password-to-restrict-access-to-joplin)

---

<div class="post-metadata">

### Author: ![ajay](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/ajay/32/6551_2.png) [@ajay](https://discourse.joplinapp.org/u/ajay)
#### Post date: [15 December 2020 16:25 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/13 "2020-12-15T16:25:50Z")

</div>

While very useful to know, I find this finding very odd. When I read E2EE (in the general description), I assume that the following statement is true: End-to-end encryption (E2EE) is a system where only the owner of the data (i.e. notes, notebooks, tags or resources) can read it. And I interpret this statement to mean that only Joplin can read the data (on behalve of me) and that Joplin doesn't store this password somewhere in clear text, instead keeping this password somewhere "safe". I don't wonna go into the details of malware, limited data erasures on any SSD, and all the rest, or argue that Joplin is safe enough when data are encrypted between my wifi card and the rest of the world. I simply think a clear text copy of the password which dpoulton can "find" is not what I want for some of my notes.

So what are the alternatives ?

- encrypt the masterkey's password
- don't store the password, let the user insert it every time
- have it sort of auto-typed from within Keepass
- store it in a location the user defines once
- ... etc. etc.

Yes I know, each one of these ideas has it's own drawbacks. Nevertheless, let me repeat: I think a clear text copy of my password one can "find" is not what I want for some of my notes.

The simple solution which does not require a solution within the app ? Store the profile folder on an encrypted drive. I think this has it's own drawbacks, but in any case the E2EE description on the Joplin website has to be very clear about these limitations.

Another subject related to this, does E2EE (as explained vs. as implemented) encrypt everything in the profile directory or not. And if not why. But I will address this in a separate post.

---

<div class="post-metadata">

### Author: ![dpoulton](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/dpoulton/32/29723_2.png) [@dpoulton](https://discourse.joplinapp.org/u/dpoulton)
#### Post date: [15 December 2020 17:21 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/14 "2020-12-15T17:21:06Z")

</div>

The post you have replied to is over a year old now and [this **News** post from June 2020](https://discourse.joplinapp.org/t/new-editor-editable-attachments-dark-mode-support-and-more-in-latest-pre-release/9251) updates users with:

> **Support for system keychain on macOS and Windows**
> 
> One of the issues mentioned in the [security audit](https://www.patreon.com/posts/joplin-informal-35719724) was that certain sensitive settings, like Nextcloud or encryption passwords were saved unencrypted in the Joplin profile. This new release will make use of the system keychain when it is available and move the sensitive settings to it. You don’t need to do anything to make use of this feature, it is automatically enabled in this release.
> 
> Currently this is supported on macOS and Windows. It is disabled of course for the portable version, and is also not currently enabled for Linux due to a build issue and less consistent support than on macOS and Windows.

_(I have not looked to see if the Linux issue has also since been resolved)_

> [@ajay](#):
>
> Another subject related to this, does E2EE (as explained vs. as implemented) encrypt everything in the profile directory or not. And if not why...

With regards to E2EE, it is not a method of encrypting and securing the data on your local disk and never has been. It is there only to ensure that data transferred _off_ your system to a cloud storage provider cannot be read by that storage provider or anyone who gains access that storage provider's systems. Of course it also provides protection _in addition to_ HTTPS whilst in transit both to and from the storage provider.

From what I have seen, if you enable E2EE you will see two copies of each file in your **resources** folder; the "plain version", say `004864a886874b57a37cc6234760c448.png` and the encrypted version, say, `004864a886874b57a37cc6234760c448.crypted` which Joplin uses to send to the sync target. The notes in your _local_ Joplin database are unencrypted and there are unencrypted resource files (attachments) in your _local_ **resources** folder. However _all notes and resources_ are stored encrypted on the sync target.

Local encryption has been raised many times in the past. [This](https://discourse.joplinapp.org/t/are-local-notes-encrypted/10774) is just one of the many posts.

> [@ajay](#):
>
> ... But I will address this in a separate post.

If you _were_ thinking of requesting local encryption please have a search of this forum first as the pros & cons have been discussed many times. It is also somewhat covered in the [FAQ](https://joplinapp.org/faq/#could-there-be-a-password-to-restrict-access-to-joplin).

---

<div class="post-metadata">

### Author: ![ajay](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/ajay/32/6551_2.png) [@ajay](https://discourse.joplinapp.org/u/ajay)
#### Post date: [15 December 2020 20:48 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/15 "2020-12-15T20:48:23Z")

</div>

THANK YOU !!  
as you guessed, I did entirely miss the dates of the earlier posts. Well ... no harm done, nothing wasted than the time I took to write the useless response. Sh... happens 😉

---

<div class="post-metadata">

### Author: ![dpoulton](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/dpoulton/32/29723_2.png) [@dpoulton](https://discourse.joplinapp.org/u/dpoulton)
#### Post date: [15 December 2020 21:02 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/16 "2020-12-15T21:02:23Z")

</div>

> [@ajay](#):
>
> Well ... no harm done, nothing wasted than the time I took to write the useless response.

What about my time responding to your response! 😄

---

<div class="post-metadata">

### Author: ![ajay](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/ajay/32/6551_2.png) [@ajay](https://discourse.joplinapp.org/u/ajay)
#### Post date: [16 December 2020 19:58 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/17 "2020-12-16T19:58:51Z")

</div>

Fair enough, but I assume you enjoyed it, like I enjoy helping other new users - no ?

---

<div class="post-metadata">

### Author: ![dpoulton](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/dpoulton/32/29723_2.png) [@dpoulton](https://discourse.joplinapp.org/u/dpoulton)
#### Post date: [16 December 2020 20:21 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/18 "2020-12-16T20:21:12Z")

</div>

@ajay

> [@dpoulton](#):
>
> What about my time responding to your response! 😄

The emoji at the end is supposed to show that whatever precedes it should **not** be taken seriously. Hope you are not offended.

---

<div class="post-metadata">

### Author: ![ajay](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/ajay/32/6551_2.png) [@ajay](https://discourse.joplinapp.org/u/ajay)
#### Post date: [17 December 2020 09:12 UTC](https://discourse.joplinapp.org/t/how-can-i-change-forgotten-password/3544/19 "2020-12-17T09:12:55Z")

</div>

Absolutely no misunderstanding, nor for a second. This line (in a similar case) would have come right out of my mouth 😉
