product icon

How do I reset my master password using SMS account recovery for LastPass?

    Using SMS account recovery will trigger the master password recovery flow as long as at least one of your browsers has captured a Recovery One Time Password which is created by logging in to your online web vault (via the LastPass website) and/or the LastPass browser extension at least once.

    Troubleshooting: Before proceeding with the recovery options below, please be sure you have temporarily disabled pop-up blockers; otherwise, you must allow pop-ups from the LastPass website when prompted in your web browser toolbar.
    Before you begin: Be sure you have already set up SMS account recovery before proceeding.
    1. Navigate to https://lastpass.com/recover.php.
    2. Enter your email address, then click Continue.
    3. The system sends an SMS message to your phone containing a numeric code. Enter this code into your web browser, and click Verify.
    4. Select Click to Recover Account.
    5. When prompted if you want to use a one-time password for account recovery, click Yes.
    6. When the next window appears advising that Account Recovery has been detected and that you must immediately change your master password, click OK to proceed.
      Troubleshooting: If you encounter a message that "LastPass account recovery has failed because your current browser didn't save account recovery data on this computer" or that a "Recovery One Time Password was not detected" try repeating these steps on another web browser where you have logged in to LastPass. For additional information, please see troubleshooting information here.
    7. Enter a new master password and confirm, then enter master password hint (optional but recommended).
      Tip: We recommend using the following best practices when creating your master password:
      • Use a minimum of 12 characters, but the lengthier the better
      • Use upper case, lower case, numeric, and special character values
      • Make it memorable, but not easily guessed (e.g., a passphrase)
      • Make sure that it is unique only to you
      • Don't use personal information
      • Don't use sequential characters (for example, "1234") or repeated characters (for example, "aaaa")
      • Make sure you don't use your master password for any other account or application
    8. Click Confirm.

      Result: A message indicates that your password has changed.

    9. Click OK to proceed with logging out.
    10. Once you have been logged off of LastPass, log back in again using your new master password.
    Results: You have successfully reset your master password.
    What to do next: Create new Recovery One Time Passwords on trusted devices (strongly recommended)
    Create new Recovery One Time Passwords for account recovery (in case your master password is ever forgotten) by doing the following:
    1. Log out of LastPass on every trusted computer and/or mobile device where you have installed LastPass and accessed your LastPass vault. You can check your active sessions for all devices.
    2. Log back in with your new master password.
    What to do next: If you are using a public/untrusted computer (recommended)

    Clear the browser cache on all web browsers where you accessed LastPass in order to clear the Recovery One Time Password that was created from accessing the LastPass website.

    What to do next: If you use temporary, one-time passwords (optional)

    Generate new temporary, one-time passwords because all OTPs you generated previously are now invalidated and no longer listed due to your vault being re-encrypted from your master password change.