Password Rejected Errors

Problem

If an admin’s password does not meet the minimum password policy, the following error occurs when they log in to the Admin Area:

You cannot use that password. Choose a different password.

Cause

WHMCS automatically re-hashes an admin’s password using a more secure algorithm the first time they log in with it. The stored password must meet the minimum password policy.

Passwords must be at least 12 characters long by default (an administrator may require more, up to a maximum of 64) and contain at least one letter and one number. We also recommend including symbols and both uppercase and lowercase letters.

If the admin’s existing password does not meet this policy, the system cannot complete the hash upgrade and displays this message instead. The admin’s password remains the same. Only the hash upgrade fails.

Solution

To resolve this, set a new password for the admin that meets the minimum password policy:

After the admin sets a compliant password, the system hashes and stores it under the current policy and the message no longer appears.

Last modified: 2026 September 30