Changing Your Password

You can update your password at any time from your account settings while logged in. If you have forgotten your current password, you can reset it from the login page without needing to know the old one.

The Change Password card on the Security tab: enter your current password, then the new one twice.
Signed in with Google? There is no password to change

If you created your account by signing in with Google, A vs B never stored a password for you. The Security tab shows a note that your identity provider handles sign-in, and two-factor authentication is off for the same reason. To add a password, contact A vs B support.

Changing your password while logged in

1

Open Account Settings

Click your avatar or initials in the top-right corner of the page, then click Account in the menu that opens.

2

Go to the Security tab

Click the Security tab at the top of the Account Settings page.

3

Enter your current password

Type your existing password in the Current password field. This step verifies that you are the account owner and not someone who has gained unauthorized access to your logged-in session.

4

Enter your new password

Type your new password in the New password field. See the password requirements below for the rules your new password must meet. It has to be different from your current password: the same password again is refused, because it would sign you out everywhere and change nothing.

5

Confirm your new password

Re-type your new password in the Confirm new password field. Both entries must match exactly.

6

Save

Click Update Password. If all three fields are valid, your password is updated immediately and you are signed out everywhere, including on this device. You will be sent back to the login page to sign in with your new password.

Changing your password signs out every device

Every session ends, on this device and on any other, and the same happens after a password reset. Being sent back to the login page is expected. Sign in again with your new password and carry on where you left off. If you think someone else has been in your account, see what to do if someone else has access below, because there are two more things to check.

Password requirements

Your new password must meet the following requirements:

  • Between 8 and 72 characters long
  • Contains at least one uppercase letter (A–Z)
  • Contains at least one lowercase letter (a–z)
  • Contains at least one number (0–9)

Special characters (such as !@#$%^&*) are allowed and encouraged but not required. Using a password manager to generate a long, unique password is strongly recommended. The same rules apply everywhere you set a password in A vs B: signing up, accepting an invitation, resetting a forgotten password, and changing it here.

Each of those forms lists the four rules under the password box and ticks each one off as you type. If you submit a password that misses one, the message under the box names exactly what it still needs, for example "Your password needs an uppercase letter and a number."

Use a unique password for every service

Never reuse a password across multiple websites. If another service you use suffers a data breach, attackers routinely try leaked credentials on other platforms. A password manager makes it easy to maintain unique passwords everywhere.

If you think someone else has access to your account

Changing your password ends every signed-in session, so anyone signed in as you is sent back to the login page. On its own that is not enough, because access tokens are separate credentials that keep working after a password change. Do all three steps:

1

Change your password

Follow the steps above. Every browser and device is signed out, yours included.

2

Revoke your personal access tokens

Go to Account Settings → Personal Access Tokens and click Revoke next to any token you do not recognize, plus any you no longer need. These are the tokens the A vs B command line tool and your own scripts sign in with. See Personal Access Tokens for more on them. If you do not see the tab, your role does not include token access; ask an owner or admin in your organization, or contact support, to check whether any tokens exist for your account.

3

Revoke your organization's service tokens

Go to Organization Settings → Service Tokens and click Revoke on any token that should no longer work. These are the tokens your integrations use to call the A vs B API, and they belong to the organization rather than to you. Only owners and admins see this tab, so ask one of yours if you do not have it. See Authentication for more on them.

Revoking a token stops it working straight away, so any script or integration still using it will need a new one. That is the point: a token you did not create, or one that may have been copied, should stop working before you go looking for what it was used for.

Turn on two-factor authentication as well

If someone got hold of your password once, a second step at login stops a repeat. See Two-Factor Authentication to switch it on.

Forgotten your password?

If you cannot log in because you have forgotten your password, use the password reset flow:

1

Go to the login page

Navigate to app.avsb.cloud/login (or wherever you normally log in). Do not keep guessing: after five wrong passwords in a row, sign-in pauses for 15 minutes (see If sign-in is paused below).

2

Click Forgot Password?

Click the Forgot Password? link beside the Password label on the login form. This opens the password reset request page.

3

Enter your email address

Type the email address associated with your A vs B account and click Send Reset Link. A vs B will send you a reset email within a minute. If you do not see it, check your spam folder.

4

Click the link in the email

Open the email from noreply@avsb.cloud and click the Reset password button inside it. This link is valid for 1 hour. If it expires, return to the login page and request a new one.

5

Enter your new password

On the reset page, type your new password once. Use the eye button to check what you typed. The same password requirements apply as when changing a password normally.

6

Log in

After saving your new password, you are taken to the login page, which confirms the change: "Your password was changed. Log in with your new password." Enter your email and new password to log in.

Reset links expire after 1 hour

For security, password reset links are single-use and expire after 1 hour. A link that was already used opens a page saying Link already used, and an old one says Link expired. Click Request new link on that page and use the newest email.

If sign-in is paused

After five wrong passwords in a row for the same account, A vs B pauses sign-in for that account for 15 minutes. It protects you from someone guessing at your password.

While the pause lasts, the login page says Too many attempts. Try again in N minutes, or reset your password. Even the right password is refused until the time is up. The message never says how many attempts were made.

You have two ways back in:

  • Wait. Sign-in works again as soon as the time on the message has passed.
  • Reset your password. Completing a reset (the steps above) ends the pause at once, so you can sign in straight away with the new password.

No email is sent for this pause. If you see the message and did not type any wrong passwords yourself, someone may be trying to get in: reset your password and turn on two-factor authentication.

A lock by A vs B is different

If the login page says This account is locked. Contact support to get back in., A vs B locked the account on purpose and emailed you about it. Waiting or resetting your password does not end that kind of lock; contact support. See Security Emails.

Was this helpful?