Reset an Admin Password
If you forget your admin password for WHMCS, you can request a password reset by clicking Forgot your password? on the Admin Area login page.
Passwords must be at least 12 characters long by default (an administrator may require more, up to a maximum of 64) and contain at least one letter and one number. We also recommend including symbols and both uppercase and lowercase letters.
New passwords cannot match any of the admin’s most recently used passwords.
- After three consecutive failed admin login attempts, the system blocks the source IP address. When this happens, you can remove the block immediately.
- For more information about admins in WHMCS, see Admins.
- If you see You cannot use that password. Choose a different password. while logging in, see Password Rejected Errors.
Missing Reset Link
If you do not see the Forgot your password? link, it is disabled in the Security tab at Configuration () > System Settings > General Settings.
To reenable it:
- Log in to your database administration interface. Usually, this is phpMyAdmin in your server’s control panel.
- Select the WHMCS database.
- Browse to the
tblconfigurationtable. - Ensure that the
DisableAdminPWResetsetting has a blank value. - Save your changes.
There was an error sending the email. Please try again
If your system is encountering a technical error that prevents it from sending the password reset email, you can change the password directly in the database.
To do this:
- Log in to your database administration interface (usually phpMyAdmin via your server control panel).
- Select the WHMCS database.
- Browse to the
tbladminstable. - Edit the administrator account that you want to reset.
- Enter the new password.
- Make certain that the password will use MD5 hashing. In phpMyAdmin, you can do this by selecting MD5 from the Functions menu.WHMCS will automatically re‑hash the password using a more secure algorithm after your next login. Apply MD5 hashing here to ensure that the system does not store the password in plain text before then.
- Clear the contents of the
passwordhashfield. - Save your changes.
Last modified: 2026 September 30