ScreenshotNeo

BlogHow-to

ArchiveBox authentication error: reset the admin password

Reset an existing ArchiveBox admin password from the command line or admin UI, and learn what to check when Docker or a proxy is involved.

By the ScreenshotNeo team4 October 20265 min read

If you cannot sign in to an existing ArchiveBox account that uses a local password, change it from the collection’s command line with archivebox manage changepassword <username>. With Docker Compose, run docker compose run --rm archivebox manage changepassword <username> from the directory containing your Compose file. If you can still access the admin UI, use /admin/password_change/. Changing ADMIN_PASSWORD after the account has been created does not reset its password.

Choose the recovery path

Your situation Use this
You can access the ArchiveBox collection’s shell archivebox manage changepassword <username>
Your ArchiveBox service runs with Docker Compose docker compose run --rm archivebox manage changepassword <username>
You can sign in and reach the admin UI /admin/password_change/
A reverse proxy, LDAP, or another identity provider handles login Identify which system rejected the credential, then reset it at that system.

These commands change an ArchiveBox user’s local password. They do not reset a reverse-proxy or external identity-provider credential.

Reset an existing password from the command line

  1. Find the exact ArchiveBox username and the collection or service context where this installation runs.
  2. Open a shell in that context. For a bare-metal installation, use the environment and collection directory used to run ArchiveBox.
  3. Run the documented password-change command:
archivebox manage changepassword <username>

Replace <username> with the account’s actual username, without the angle brackets. Follow the prompts to enter and confirm the new password. Keep the command in the same installation context as the collection you are trying to access; running it against another environment will not change the intended account.

The command is for an existing user. If you are setting up the first administrator on a new collection, follow ArchiveBox’s initialization or setup flow instead.

Reset a password in Docker Compose

Run the command from the directory containing the Compose configuration for the ArchiveBox service:

docker compose run --rm archivebox manage changepassword <username>

Replace the username, then complete the interactive prompts. The command starts a one-off service container for the management task and removes it when it exits. If your Compose service has a different name, use the service name from your Compose configuration in place of archivebox.

If the command cannot find the collection or user, confirm that Compose is using the expected project and mounted collection data. Do not create a fresh collection as a workaround: the password must be changed in the collection that contains the account.

Change the password in the admin UI

If you can sign in to ArchiveBox, open /admin/password_change/ on the same ArchiveBox instance and follow the form. User administration is at /admin/auth/user/. The password-change page is useful when you still have a working session; it does not help when you are locked out of the account.

Why changing ADMIN_PASSWORD may not work

ADMIN_USERNAME and ADMIN_PASSWORD are initial setup values used when creating the first administrator. They are not continuing overrides for an existing user’s credentials. Editing the environment variable and restarting the service does not reset a password already stored for that user. Use the management command for an existing account.

For first-time setup, use the documented ArchiveBox setup or initialization process and its initial administrator settings. Check the documentation for the ArchiveBox version you have installed if its setup flow differs.

Check which authentication layer rejected the login

ArchiveBox supports username and password authentication, and installations may also involve reverse-proxy authentication, LDAP, or API authentication. Determine which login prompt or service produced the error:

  • If the ArchiveBox login form rejects a local account, change that ArchiveBox user’s password with the management command.
  • If a proxy shows its own login prompt before ArchiveBox loads, check the proxy’s user or authentication provider.
  • If an external identity provider or LDAP integration manages the credential, reset it through that provider’s account-management process.
  • If an API client is failing, confirm which API authentication method and credentials it uses; a web user’s password change may not address an API credential problem.

Changing the ArchiveBox password will not change a password held by an upstream proxy or identity provider. Consult ArchiveBox’s authentication guide and configuration reference for the authentication modes relevant to your deployment.

Troubleshooting

Symptom Likely cause What to do
The command says the user does not exist The username is wrong, or the command is pointed at another collection or environment. Confirm the username and run the command in the collection context used by the live service. In Compose, verify the project and data mount.
archivebox is not found The shell is outside the Python environment or container where ArchiveBox is installed. Activate the installation’s environment or run the command in its deployment context. For Compose, use the documented one-off service command.
Compose cannot find the service The service name differs from archivebox, or the command was run from another project directory. Run Compose from the correct project directory and substitute the configured ArchiveBox service name.
The command succeeds but login still fails The browser may be reaching another instance, or an upstream authentication layer is rejecting the login. Confirm the URL points to the collection you changed, then identify whether the error is from ArchiveBox, a proxy, LDAP, or another provider.
Changing ADMIN_PASSWORD has no effect The variable is for first-run administrator creation, not an existing account reset. Use manage changepassword for the existing user.
You do not know whether the account is local The deployment may use a proxy or external authentication. Check the login flow and deployment configuration, then reset the credential at the system that owns it.

Protect the collection while recovering access

Use ArchiveBox’s account-management command instead of manually editing the database as the normal recovery method. ArchiveBox’s security guidance says the collection’s SQLite database is not encrypted. Protect access to the collection directory, database file, and configuration that may contain sensitive information. See the project’s Security Overview.

Or skip the browser setup

If your task is to capture a page while you are sorting out an ArchiveBox login, ScreenshotNeo is a website screenshot API and MCP server. One GET request returns a PNG, JPEG, WebP, or PDF. For a WebP screenshot, run:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for the key and request options. Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month, with no card.

FAQ

Does this reset every ArchiveBox user’s password?

No. The command changes the password for the one username you specify.

Can I use the admin password-change page while locked out?

Only if you still have an authenticated session. Otherwise, use the command-line recovery path.

Should I edit the SQLite database directly?

No. Use ArchiveBox’s documented account-management command for normal recovery, and protect the collection’s unencrypted database.

Where can I check version-specific instructions?

Use ArchiveBox’s official authentication, configuration, and deployment documentation, and compare it with the version installed in your environment.