How to Reset Your Snipe-IT Admin Password: Web, CLI, and Database Methods
You can reset a Snipe-IT administrator password through the web interface's "Forgot Password" link, the snipeit:reset-admin artisan command, or manually via Laravel Tinker by updating the users table directly.
When administrative access to Snipe-IT (grokability/snipe-it) is lost, the Laravel-based architecture provides three distinct recovery mechanisms. Whether you prefer the automated email flow, a command-line utility, or direct database manipulation, the application offers secure pathways to reset the Snipe-IT admin password without requiring a full reinstallation.
Method 1: Web-Based Password Reset
This approach leverages the standard Laravel authentication system implemented in the Snipe-IT source code.
Route Structure and Controllers
In routes/web.php (lines 774-785), Snipe-IT registers the password reset endpoints:
/password/emaildisplays the initial request form./password/resethandles token validation and password updates.
These routes invoke the ResetPasswordController located at app/Http/Controllers/Auth/ResetPasswordController.php. This controller implements Laravel's ResetsPasswords trait and provides four key methods: showLinkRequestForm, sendResetLinkEmail, showResetForm, and reset.
The email template containing the secure link resides in resources/views/auth/emails/password.blade.php, while the password entry form is rendered from resources/views/auth/passwords/reset.blade.php.
Step-by-Step Reset Process
- Navigate to the login page (
/login) and click "Forgot your password?". - Enter the administrator email address associated with the account.
- The system generates a unique token and dispatches an email containing a URL formatted as
https://your-domain.com/password/reset/{token}?email={address}. - Click the link to reach the reset form, handled by
ResetPasswordController::showResetForm. - Enter a new password and confirmation. Upon submission, the
resetmethod validates the token, hashes the password using Laravel'sHash::make(), and updates the record in theuserstable. - The admin is redirected to the login screen with a confirmation flash message.
Method 2: Artisan Command (CLI)
For environments where email delivery is unavailable, Snipe-IT provides a dedicated artisan command in recent versions:
php artisan snipeit:reset-admin
This command-line utility prompts for the administrator's email address and the new password, performing the same cryptographic hashing and database update as the web flow without requiring SMTP configuration.
Method 3: Manual Database Reset via Tinker
If you have shell access to the server but cannot trigger emails or artisan commands, use Laravel Tinker to update the password hash directly:
php artisan tinker
>>> $admin = \App\Models\User::where('username', 'admin')->first();
>>> $admin->password = Hash::make('YourSecurePassword123');
>>> $admin->reset_password_code = null; // Clear any pending reset tokens
>>> $admin->save();
This approach requires the Hash facade to ensure the password is properly bcrypt-hashed, matching Laravel's authentication requirements.
Summary
- The web-based flow is the standard method, utilizing
ResetPasswordControllerand routes defined inroutes/web.phpto email a secure reset link. - The
snipeit:reset-adminartisan command offers a self-service CLI alternative when email is not configured. - Laravel Tinker provides direct database access for emergency recovery, ensuring you can always regain administrative control by manually hashing and saving a new password.
Frequently Asked Questions
What if email is not configured in my Snipe-IT instance?
If SMTP is not configured and the password reset email cannot be sent, use the php artisan snipeit:reset-admin command or access Laravel Tinker to manually update the password hash in the database. Both methods bypass the email requirement entirely.
Which file contains the password reset logic?
The core logic resides in app/Http/Controllers/Auth/ResetPasswordController.php, which implements Laravel's ResetsPasswords trait. This controller handles token validation, password hashing, and the database update transaction.
Can I reset the password by editing the database directly with SQL?
Yes, but you must hash the password using bcrypt (the algorithm Laravel uses) before insertion. Direct SQL updates without proper hashing will result in authentication failures. Using php artisan tinker with Hash::make() is the recommended approach for manual updates.
Does the artisan command work for non-administrator accounts?
The snipeit:reset-admin command is specifically designed for administrator recovery. For standard users, utilize the web-based "Forgot Password" flow or manually update the specific user record via Tinker using \App\Models\User::where('email', 'user@example.com')->first().
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →