Reset Password
This page covers all methods for recovering access to Traefik Manager.
Method 1 - CLI reset (recommended)
This is the fastest method when you can exec into the container.
docker exec traefik-manager flask reset-passwordA new temporary password is printed to the terminal. On your next login you are sent to a forced password-change screen before you reach the dashboard.
Lost your authenticator too?
Two-factor authentication is preserved by default. Add --disable-otp to the same command to reset the password and turn 2FA off in one step, then re-enable it from Settings → Authentication → Password & 2FA.
WARNING
The reset also sets setup_password_reset: true in manager.yml, which leaves the /setup page open to anyone who can reach Traefik Manager. Only setting a password on that page clears the flag - the forced-change screen does not. So either set your new password at https://your-traefik-manager.example.com/setup, or remove the key from manager.yml afterwards and restart.
Method 2 - Manual reset via manager.yml
Use this if you cannot exec into the container (e.g. the container won't start).
1. Open manager.yml in your config volume:
nano /path/to/traefik-manager/config/manager.yml2. Add the reset flag:
setup_password_reset: true3. Restart:
docker compose restart traefik-manager4. Open /setup (https://your-traefik-manager.example.com/setup). You are asked for a new password and nothing else. Setting it clears the flag and signs you in.
WARNING
While the flag is set, anyone who can reach Traefik Manager can set the password. Restart, set the new password, and confirm you are signed in.
Method 3 - Pre-set a known password
To set a specific password instead of the auto-generated one, generate a bcrypt hash and write it directly to manager.yml:
python3 -c "import bcrypt; print(bcrypt.hashpw(b'yournewpassword', bcrypt.gensalt()).decode())"Update manager.yml:
password_hash: "$2b$12$..."
must_change_password: false
setup_complete: trueRestart the container - no wizard, no forced change, log in immediately with the password you set.
See manager.yml reference for all available fields.
Two-factor authentication
Enable 2FA
- Settings → Authentication → Password & 2FA → Enable 2FA
- Scan the QR code with your TOTP app (Google Authenticator, Authy, 1Password, etc.)
- Enter the 6-digit code to confirm - 2FA is now active
Disable 2FA (while logged in)
Settings → Authentication → Password & 2FA → Disable 2FA. No code is required - you are already authenticated.
Disable 2FA (locked out)
Use the --disable-otp flag with the CLI reset command shown above.