Reset a user password
When someone is locked out — or when you are setting up an account for them and there is no mailbox to send a code to — you can generate a new password for them yourself. HushChat creates it, shows it to you once, and leaves you to hand it over.
The generated password is displayed in a single dialog and is never saved, never written to a log, and never emailed to anyone. Close that dialog without copying it and nobody can retrieve it — your only option is to generate another one, which invalidates the first.
Where it is
Settings → Users on the web, or the Admin tab → Users on iOS and Android. Select the person, then scroll to the section headed Password, just above the Danger Zone.
The section reads "Generate a new password for this user. Shown once." and carries one button: Reset Password.
You can do this for anyone you can open in the users list, including other administrators.
Generate the password
- Select Reset Password.
- Confirm the dialog, titled Reset Password: "Generate a new password for this user? Their current password stops working immediately." Choose Reset — or Cancel to back out, which changes nothing.
- A second dialog appears, titled New Password: "Share this password with the user securely. It will not be shown again." The password itself is printed underneath it.
- Select Copy. HushChat confirms with "Password copied" and the password is on your clipboard.
- Select Done to close.
If something goes wrong, you get "Couldn't reset password" and the person's existing password is untouched — nothing has changed, so you can simply try again.
Copy does not close the dialog, so you can copy, paste it somewhere safe, and only then select Done. Getting into that habit costs a second and saves a second reset.
What the new password is
- HushChat chooses it, you cannot. It is generated at random, sixteen characters long, and always contains upper case, lower case, a digit and a symbol. There is no field for typing a password of your own — which is deliberate, and stops weak ones being set for other people.
- It works immediately and permanently. The person signs in with it straight away. It is a normal password, not a temporary code: it does not expire, and they are not forced to change it at their next sign-in.
- Their old password stops working the moment you confirm. Anyone signed in on another device will need the new one when they next sign in.
- It applies to their account, not just this workspace. You are resetting how that person signs in to HushChat, not their membership of your workspace. Suspending or removing them is a separate thing entirely — see Suspend and remove users.
Hand it over safely
Nothing is sent to the person. HushChat does not email them, notify them, or hint that anything happened — relaying the password is entirely your job, and until you do it they are simply locked out with credentials that no longer work.
A few habits worth keeping:
- Tell them first. Reset only when they are expecting it, otherwise their next sign-in fails for no reason they can see.
- Use a channel outside HushChat. Speak to them, phone them, or use whatever your organisation already trusts for secrets. Sending it as a chat message leaves it sitting in a conversation history that other people may later be able to read.
- Never write it into a shared document, a ticket, or a group chat.
- Ask them to change it once they are in. They can do that themselves under Profile → Edit Profile → Change Password, which asks for their Current Password — the one you just gave them — and then their new one. After that, nobody but them knows it.
- Clear your clipboard afterwards if you copied it on a shared machine.
Nothing is lost. Generate another one and hand that over instead — each reset replaces the last, and there is no limit on how many times you can do it.
When to reset, and when not to
| Situation | Do this |
|---|---|
| Someone is locked out and cannot receive a reset code | Reset their password here |
| You are setting up an account for someone in person | Reset their password here, and have them change it |
| Someone is leaving temporarily | Suspend them instead — see Suspend and remove users |
| Someone is gone for good | Remove them instead — a password reset does not take access away |
Resetting a password never changes anyone's role, limits or membership. It only changes how they sign in.