Menu

Reset a PostgreSQL Role Password

Reset a PostgreSQL role password safely with psql, including local peer-authenticated access and managed database recovery paths.

Updated on

PostgreSQL passwords belong to database roles; they are separate from operating-system passwords. If you can connect as the role or as a database administrator, use psql’s \password command to set a new password without putting it in SQL history or server logs. If an application reports SQLSTATE 28P01, first confirm it is connecting to the intended server and role; see PostgreSQL Error 28P01.

Reset a password from an existing privileged session

In psql, run the meta-command and follow its prompts:

\password postgres

Replace postgres with the role whose password you want to reset. The role must be one you can manage: users can change their own password, while changing another role’s password requires suitable privileges.

Use local peer authentication on Linux or macOS

If the cluster’s pg_hba.conf uses peer for local connections and the operating-system postgres account is available, open a local administrative session:

sudo -u postgres psql -d postgres

Then set the role password:

\password postgres

Peer authentication matches the local operating-system user to a database role; it works only for local connections. The sudo command, service account, and cluster configuration vary by distribution. See PostgreSQL’s peer authentication documentation.

Managed services and Windows installations

For a managed PostgreSQL service, use the provider’s password-reset or administrative workflow. On Windows, peer authentication is not available; use an existing privileged connection or the recovery process documented for that installation.

Do not change network rules in pg_hba.conf to trust as a general password-reset procedure. trust lets matching clients claim any database role without proving its identity, including superuser roles. If you cannot connect through an existing administrative method, follow the server provider’s recovery guidance instead of weakening network authentication. See PostgreSQL’s trust authentication warning.

After resetting a password, update the application secret or connection pool that uses it. If the client cannot use SCRAM-SHA-256, update its driver rather than downgrading to clear-text password authentication; see PostgreSQL password authentication.