Changing your own password — requirements and when confirmation is needed
Four requirements, checked live as you type. If 2FA is enabled, changing your password also asks for an app code.
Change your own password on the Security tab, in the Change password card. You need to enter your current password and the new one twice.
Step by step
- Click your avatar in the top-right corner and choose My profile.
- Open the Security tab. The first card is called Change password.
- Enter your Current password.
- Enter your New password. As you type, the requirements appear and disappear below the field: At least 8 characters., At least one lowercase letter., At least one uppercase letter., At least one digit., The new password must be different from the current one.
- Repeat it in Repeat new password. If they differ, you will see Passwords do not match.
- Click Change password below the form. The button remains disabled until all requirements are met.
- If 2FA is enabled, the system asks for a code from your app — enter it.
- Password changed successfully. confirms the change.
- If you are changing the password because you suspect the account was compromised, go straight to Log out all sessions — changing the password alone does not log anyone out (Sessions and devices — who is logged into your account).
First login with a password from email
The password sent by Noxti email (for a new account or after an administrator uses Send new password) is temporary. After logging in with it, you go straight to this form with a Set your own password frame; enter the email password in Current password. The rest of the system remains locked until you set your own. The temporary password stops working 72 hours after it is sent if you have not set a personal password by then — ask an administrator for a new one (First login — four things to do right away).
Requirements
Your new password must have:
- at least 8 characters,
- at least one lowercase letter,
- at least one uppercase letter,
- at least one digit,
- and must differ from your current password.
Requirements are checked as you type — you do not need to submit the form to see what is missing. A special character is not required, but you can use one.
The second field checks that the two passwords match; otherwise you see “Passwords do not match.”
With 2FA enabled, confirmation is also required
If two-factor authentication is enabled, changing the password is a high-risk operation and the system also asks for a code from your app. This is not an error, and you cannot skip it — it protects against someone taking over an account from an unlocked computer.
The same rule applies to creating and revoking personal API tokens (API keys — your personal tokens). See the full list of operations requiring confirmation: Two-factor authentication (2FA) — enabling it, backup codes, and disabling it.
Sessions remain after a password change
Changing your password does not log out other devices. If you changed it because you suspect your account was compromised, the password alone is not enough — end all sessions too (Sessions and devices — who is logged into your account).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo