Your master password is your key to access the contents in your LastPass vault. You can update it whenever you want to on your desktop or mobile device.
There is no character length limit for your master password, but you must use at least 12 characters. For better security, consider using a randomly generated master password.
Limitations and compatibility
- If you are a federated LastPass user, you cannot change your master password. For more information, see What are the limitations for LastPass users with federated login?
- If you do not remember your current master password, you will need to use the LastPass account recovery options.
- Before you change your master password, temporarily disable pop-up blockers on your desktop. Alternatively, allow pop-ups from the LastPass website when your browser prompts you in the toolbar.
Notice: When you create or update your master password for your LastPass account, LastPass creates a hash of your master password. During this encryption process, LastPass sends a part of the hashed version of your master password to https://haveibeenpwned.com/Passwords to check if it has been compromised in known data breaches. For more information, see How does LastPass know if my master password was exposed?.
Change your master password from a desktop
- Log in to LastPass and access your vault by doing either of the following:
- In your web browser toolbar, select the LastPass icon and select Vault.
- Go to
https://lastpass.com/login/
and log in with your email address and master password.
- Select Account settings in the left navigation menu.
- On the General tab, under Login Credentials, select Change Master Password.
- Enter your current master password, then create a new master password and enter a password hint
Tip: LastPass recommends using the following best practices when creating your master password:
- Use a minimum of 12 characters, but the lengthier the better
- Use at least one of each of upper case letters, lower case letters, numerals, and special characters
- Make it memorable, but not easily guessed (for example, a passphrase)
- Make sure that it is unique only to you
- Don't use your email address as your master password
- Don't use personal information
- Don't use sequential characters (for example, "1234") or repeated characters (for example, "aaaa")
- Set a password with a maximum strength (ZXCVBN strength result is 100%)
Tip: Learn more about how the strength is calculated for your master password and individual site passwords in your vault.
- Make sure you don't use your master password for any other account or application
- Don't reuse old passwords
- To maximize your security, use a randomly generated master password
Tip: To generate a random password, use the LastPass Password Generator.
Note: If you are a LastPass Business or LastPass Teamsuser, the master password requirements might be managed by your LastPass admin.
Note: Your password strength percentage might be lower based on zxcvbn matchers, for example:
Date
If your password contains a date in the format YYYY-MM-DD or without separators.
Repetition
If your password contains repeated patterns, for example aaaa.
Sequence
If your password contains sequences, for example, abcdef or 123456.
This also means that you might need longer passwords to set a password with maximum strength (100%). For more information about zxcvbn matchers, view https://zxcvbn-ts.github.io/zxcvbn/guide/matcher/.
- Select Save Master Password.
Result: Your changes are saved, and you are logged out of LastPass.
- Log back in using your new master password.
Results: You have successfully reset your master password and are now logged in to LastPass.
What to do next:
Strongly recommended on trusted devices
Create new secure secrets for automatic account recovery (in case your master password is ever forgotten) by doing the following:
- Log out of LastPass on every trusted computer and/or mobile device where you have installed LastPass and accessed your LastPass vault. You can check your active sessions for all devices.
- Log back in with your new master password.
Recommended on public or untrusted devices
Clear the browser cache on all web browsers where you accessed LastPass. This will clear the recovery one-time password that was created from accessing the LastPass website.
If you use one-time passwords
Generate new one-time passwords because all OTPs you generated previously are now invalidated and no longer listed due to your vault being re-encrypted during your master password change.
Change your master password from a mobile device
Before you begin: Install the LastPass Password Manager app for iOS or Android on your mobile device.
- Log into the LastPass Password Manager app for iOS or Android.
- Tap Settings in the bottom toolbar.
- Tap Account > Change master password.
Result: Your mobile browser will redirect you to the sign-in page on the LastPass website (https://lastpass.com).
- On the sign-in page for LastPass on your mobile browser, log in with your email address and master password.
- Enter your old master password.
- Enter a new master password, then re-enter it to confirm it. Learn more about creating a strong master password.
- Set a reminder (optional, but recommended), which will be emailed to you during the account recovery process if you ever forget your master password.
- Tap Save master password.
Result: Your changes are saved, and you are logged out of LastPass.
- Log back in to the LastPass Password Manager app using your new master password.
Results: You have successfully reset your master password, and are now logged back in to the LastPass Password Manager app for iOS or Android.
What to do next:
Strongly recommended on trusted devices
Create new secure secrets for automatic account recovery (in case your master password is ever forgotten) by doing the following:
- Log out of LastPass on every trusted computer and/or mobile device where you have installed LastPass and accessed your LastPass vault. You can check your active sessions for all devices.
- Log back in with your new master password.
Recommended on public or untrusted devices
Clear the browser cache on all web browsers where you accessed LastPass. This will clear the recovery one-time password that was created from accessing the LastPass website.
If you use one-time passwords
Generate new one-time passwords because all OTPs you generated previously are now invalidated and no longer listed due to your vault being re-encrypted during your master password change.
Related Articles