Skip to main content

One password rule everywhere

Every place that sets a password now applies the same rule: at least 8 characters, including a lowercase letter, an uppercase letter and a number. A symbol is welcome but does not replace a number.

  • The sign-up, set-password, reset-password and change-password forms all check the rule before you submit, so a password the server would refuse can no longer look acceptable.
  • The API returns a single message for every violation: "Password must be at least 8 characters and include a lowercase letter, an uppercase letter and a number".
  • If setting the password fails after your verification code was accepted, you can retry without requesting a new code.
  • The sign-up password form now includes your email as the username, so your browser's save-password prompt stores a complete login.