Chris wrote:
I’m sorry the earlier guidance sent you toward regenerating a hash without a safe way to apply it. The Argon2id PHC string is a hash, not the admin password, and generating it by itself does not change Vaultwarden’s running settings. Please stop trying admin logins while the 429 rate limit is active. When it has cleared, let us know your SparkBox version and whether the rate limit is still appearing; please don’t include the token or hash. We’ve corrected what our assistant knows so this guidance is not repeated to someone else.
Chris wrote:
Following up with the actual fix — we found why your saved admin code is refused, and it isn't anything you typed. Vaultwarden keeps its own settings file, and anything saved on its admin page at some point goes into it, including an admin code. When that file holds a code, Vaultwarden uses that one and ignores the code SparkBox gave it — which is the one SparkBox shows you. That's also where the "plain text ADMINTOKEN" line in your log comes from. A hash doesn't touch any of this, which is why it changed nothing. SparkBox 1.6.812 (out now) adds a command for exactly this. On the box: 1. sudo sparkbox upgrade 2. sudo sparkbox reset-password vaultwarden It removes only that stored admin code (it keeps a copy of the file), leaves your vault, your accounts and every other Vaultwarden setting alone, restarts Vaultwarden — which also clears the "too many requests" block — and then tries the saved code itself. It should end with "Vaultwarden's admin page accepts the saved admin code". Then sign in at http://<your-box-IP:8222/admin/ with the code from Settings → Service Passwords, row "Vaultwarden access guide" (the long code on the token: or password: line), pasted exactly — not the hash. If it ends with "still rejects the saved admin code" instead, or sudo sparkbox version still shows 1.6.811 or lower after the upgrade, paste just that line here and stop there — please don't include the code or any hash. Tom AI now knows this too, so it won't send the next person to the hash.