Local password management
Local passwords support bcrypt and Argon2id in caddy-security v1.3.0 / go-authcrunch v1.3.8. A federated user changes their password at their identity provider; signing into the portal does not grant control of a local account.
Manually
Use the released executable's password utility. It prompts without terminal echo:
authcrunch security local generate password hash
authcrunch security local generate password hash --algorithm argon2
Bcrypt is the default, cost 10. Argon2 selects Argon2id; defaults are 65536 KiB,
three iterations and four lanes. The output is a quoted Caddyfile password
directive, ready for static-user provisioning. Review
resource use before changing cost parameters; --cost is bcrypt-only.
For automation, --password-file /private/password.txt requires an owner-only
file, or --password-file - reads stdin. One final LF/CRLF is removed; other
whitespace is preserved. --db-path reads the existing password policy without
modifying the database. Do not put a production password on a command line.
A compatible standalone CLI can be installed at the matching version:
go install github.com/greenpau/go-authcrunch/cmd/authdbctl@v1.3.8
Its released command guide
explains server configuration and updates. Do not assume installing @latest
changes the library inside a previously built Caddy server.
Prefer a supported account mutation over replacing a JSON hash by hand. Manual file repair requires a stopped writer and coherent backup; it must preserve algorithm and security metadata. A password change invalidates prior credential evidence, so verify a fresh login and old refresh/OIDC credential rejection.
Settings Page
For a local account with authp/user or authp/admin, sign in and open
/auth/profile/, then choose password management. A live completed portal session
is required. The old /auth/settings route is not available in this release.
- Confirm the selected local account and enter the current password.
- Enter and confirm a new password that satisfies the store's policy.
- Submit the change and sign in again with the new credential.
- Verify that the old password fails and required MFA still applies.
Password-change sequence captured in March 2026


/auth/profile/ directly.

The released recovery endpoint does not provide a complete forgotten-password service. Establish an administrator-assisted recovery process rather than promising reset links that the implementation cannot complete.