Change your password
Enter your current password and a new one. If you signed in within the last 10 minutes, the new one is enough. Changing your password ends all your other sessions: every other browser and CLI session is signed out, and MCP access and refresh tokens are revoked, so a leaked password can’t keep an attacker in. Your current browser session stays active. The CLI and MCP clients must sign in again. If you signed up with social login and never set a password, Meridian asks for a code from your authenticator app instead. Without 2FA, it asks you to sign in again, then brings you back to set one.Reset a forgotten password
From the sign-in screen, request a reset link. Meridian emails a time-limited link that lets you set a new password without being signed in. Completing a reset ends all existing sessions, including browser and CLI sessions, and revokes MCP access and refresh tokens. Sign in again in your browsers, the CLI, and MCP clients. A reset also clears a suspicious sign-in lock, because it proves control of the same address the approval message went to.A strong, unique password plus 2FA (an authenticator app or a passkey) is the recommended setup, and may be required by your organization.