Currently, Dokploy does not have a built-in API for resetting the administrator password.
This script solves this problem by providing a simple HTTP API to automate the password reset process.
curl -sSL https://raw.coonlink.com/cloud/dokploy-reset-password/install.sh | bashWarning
The installer script attempts to install required system packages and Python dependencies. Run it with root privileges if some system packages fail.
Settings are stored in .env file.
Create or edit .env file in the installation directory:
# API key for securing the API (REQUIRED - the server refuses every
# request until this is set; there is no unauthenticated mode)
API_KEY=your-secret-api-key-here
# API server port (default: 11292)
API_PORT=11292
# Default operation mode
# true - automatically find Dokploy container
# false - manual mode (requires container_id in request)
AUTO_MODE=false
# Automatic updates check
# true - automatically install new updates when available
# false - only send Telegram notification about new updates (manual installation required)
AUTOMATICALLY_CHECK_FOR_NEW_UPDATES=false
# Telegram notifications (optional)
# TG_TOKEN - Telegram bot token for update notifications
# TG_ADMIN - Telegram chat ID for receiving notifications
TG_TOKEN=
TG_ADMIN=Create a local env file before running containers:
cp .env.example .envEdit .env and restart the service to apply changes:
sudo systemctl restart reset-password-api-dokploy- Authentication is required. There is no unauthenticated mode: if
API_KEYis not set, every request is rejected. The API listens on0.0.0.0; if reachable beyond localhost, put a TLS-terminating reverse proxy in front or restrict the port with a firewall. - Rate limited. The reset endpoint allows at most 10 requests per source IP per 5 minutes (not adjustable via
.env- hardcode changes only), matching OWASP's authentication lockout guidance. This is keyed on the raw connection IP, never onX-Forwarded-For, so it can't be bypassed with a spoofed header. container_idis validated against Docker's own container-name syntax before it's ever passed todocker exec.
Check whether the Dokploy panel itself is up before deciding to call reset-password (proxies Dokploy's own settings.health endpoint):
curl -H 'X-API-Key: your_api_key' http://localhost:11292/api/v1/panel-status{
"success": true,
"open": true,
"detail": "ok"
}open: false means Dokploy didn't answer healthy - detail says why (unreachable, unhealthy (HTTP ...), or misconfigured if DOKPLOY_URL isn't a valid http(s):// URL). Configure DOKPLOY_URL in .env if Dokploy isn't at the default http://127.0.0.1:3000.
Specify the container ID manually:
curl -X POST http://localhost:11292/api/v1/reset-password \
-H 'Content-Type: application/json' \
-H 'X-API-Key: your_api_key' \
-d '{"container_id": "your-container-id"}'Or using the legacy field name:
curl -X POST http://localhost:11292/api/v1/reset-password \
-H 'Content-Type: application/json' \
-H 'X-API-Key: your_api_key' \
-d '{"DOKPLOY_ID_DOCKER": "your-container-id"}'Automatically find and use the Dokploy container:
curl -X POST http://localhost:11292/api/v1/reset-password \
-H 'Content-Type: application/json' \
-H 'X-API-Key: your_api_key' \
-d '{"auto_mode": true}'Or using the mode parameter:
curl -X POST http://localhost:11292/api/v1/reset-password \
-H 'Content-Type: application/json' \
-H 'X-API-Key: your_api_key' \
-d '{"mode": "auto"}'Success response:
{
"success": true,
"password": "new_generated_password",
"container_id": "9edaf0cc317c",
"mode": "auto"
}- Priority 1: If
auto_modeormodeis specified in the request, use that value - Priority 2: If
container_idorDOKPLOY_ID_DOCKERis provided, use manual mode - Priority 3: Use
AUTO_MODEvalue from.envfile
# Check status
sudo systemctl status reset-password-api-dokploy
# View logs
sudo journalctl -u reset-password-api-dokploy -f
# View update logs
tail -f /root/ResetPasswordDeploy/update.log
# Restart
sudo systemctl restart reset-password-api-dokployThe system includes an automatic update mechanism that checks for new versions daily at 2:00 AM.
- AUTOMATICALLY_CHECK_FOR_NEW_UPDATES=true: Automatically installs new updates when available
- AUTOMATICALLY_CHECK_FOR_NEW_UPDATES=false: Only sends Telegram notification (requires manual installation)
# Check for updates manually
/root/ResetPasswordDeploy/update.sh
# View update logs
tail -f /root/ResetPasswordDeploy/update.logIf TG_TOKEN and TG_ADMIN are set in .env, the service can automatically reset the Dokploy admin password every day and send the new password to Telegram.
To avoid flooding the chat, the script edits the same message every time: the message ID is stored in the tg_password_message_id file, and each subsequent reset updates that exact message (if the message was deleted, a new one is sent and its ID is stored again).
- Enable/disable:
TG_DAILY_PASSWORD=true/falsein.env(default:true) - Schedule: daily at 3:30 AM (cron)
- Log:
tail -f /root/ResetPasswordDeploy/password.log - Manual run:
/root/ResetPasswordDeploy/daily-password.sh - State file:
/root/ResetPasswordDeploy/tg_password_message_id
Warning
The password is sent to Telegram in plain text. Use a private chat with your bot and do not forward this message.
cd /root/ResetPasswordDeploy
./uninstall.shThis stops and removes the systemd service, the daily update cron job, and closes the API port in the firewall (ufw/firewalld). It then asks whether to also delete all files in /root/ResetPasswordDeploy (venv, scripts, and .env containing the API key). Add --yes to skip the prompts and wipe everything.
One-liners from a fresh server:
# Interactive (with prompts):
bash <(curl -sSL https://raw.coonlink.com/cloud/dokploy-reset-password/uninstall.sh)
# Full removal without prompts:
curl -sSL https://raw.coonlink.com/cloud/dokploy-reset-password/uninstall.sh | bash -s -- --yesNote: curl ... | bash --yes does not work - curl tries to parse --yes itself. Use bash -s -- --yes (or process substitution) to pass flags to the script.
- Python 3.9+ (required by Flask 3.x and waitress;
install.shchecks this and refuses to proceed on an older Python) - Docker
- Access to Dokploy Docker container
- sudo privileges