Why do I see Invalid token when setting my password?
If you see Invalid token while setting or resetting your Bluerithm password, the password itself is not the problem. That message comes from a password reset link that is no longer valid.
Password reset emails are generated by our system and are only good for a limited time. A reset link stops working when:
- it has expired;
- it has already been used once; or
- a newer reset was requested for the same email, which supersedes the earlier link.
The fix is to start a fresh reset in the new Bluerithm and use the newest email:
- Open app.bluerithm.com.
- Choose Forgot password on the sign-in page.
- Enter the email address on your Bluerithm profile.
- Open the newest email from Bluerithm and set your password from that link right away, rather than coming back to it later.
Your profile and any projects you have been added to are already waiting there, so nothing needs to be re-sent or re-added.
If you were invited to a project, the invitation email is not the cause and asking for another one will not help — project invitation links are generic, and it is the password reset link that expires. Start a reset instead.
Bluerithm also has a legacy web app at trac.bluerithm.com, which remains supported. It signs in separately from the new Bluerithm, so a password reset on one does not change your password on the other. If you specifically need the older web app, reset there instead, using Forgot password on its own sign-in page — the address in your browser on the page showing Invalid token tells you which one you are on.
Password length is not the cause. Nine characters, or any length that meets the on-screen rules, will not produce Invalid token.
Related: Signing in for the First Time.