The Practical Guide to I Forgot Password Recovery
I forgot is a browser extension and web service that acts as a password manager focused specifically on the forgotten password problem. Instead of building an entire vault system around your logins, it handles the most tedious part: finding, filling, and resetting credentials when you can't remember them. That's the pitch anyway. The reality is a bit messier. The core functionality is straightforward. You install it, give it access to your passwords through manual entry or import, and when you land on a login page you don't recognize, the extension surfaces matching credentials. The reset flow is where it differentiates itself from something like LastPass or 1Password. Most password managers treat password resets as an afterthought. I forgot builds the reset path into the workflow, pulling email verification links directly from your inbox so you don't have to tab over and fish through spam folders. I imported about two hundred and seventy passwords from a CSV export of my old browser data when I first set it up. Took me roughly twelve minutes. The parser handled duplicates and malformed entries without throwing errors, which is more than I can say about the tool I used before this one. It also pulled in about forty accounts where the email field was empty, which you'll need to fix manually later because the reset flow won't work without that field populated.
That import process exposed a limitation worth noting. If your passwords contain special characters that aren't properly escaped in the CSV, the import will silently drop those fields. I lost about six passwords on the first try because my export had unescaped ampersands in the password column. Writing them back in manually was annoying but fast. Going forward I make sure to replace special characters with their URL-safe equivalents before importing anything.
How the Reset Flow Actually Works
Here's the part most reviews skip. When you hit a login page and I forgot suggests credentials that don't work because you've changed the password since last time, you can trigger a reset directly from the extension interface. It opens a secondary panel that searches your connected email accounts for the most recent password reset email from that domain. It ranks results by recency and relevance, then lets you click through to the reset token page without leaving the extension UI. One thing that caught me off guard during setup. The email scanning only works for accounts you've explicitly connected. Gmail works out of the box with OAuth. Outlook and Yahoo require you to generate an app-specific password and enter it manually. I spent about twenty minutes troubleshooting why my Yahoo account wasn't showing up until I realized the extension doesn't support standard SMTP auth for email retrieval. Once I switched to using Gmail as the primary connected account and just forwarded reset emails from Yahoo to a Gmail alias, everything worked cleanly. Not ideal, but functional. The extension also caches recently used reset links locally. If you trigger a reset and then navigate away before completing it, you can go back to the extension later and resume from the same token page. That's genuinely useful because password reset flows often time out after ten to fifteen minutes depending on the service, and losing your place in the middle of the process is a common frustration. This feature cuts that failure mode down significantly.
Get the Full Details

What It Doesn't Do Well
Two-factor authentication handling is the biggest gap. I forgot will fill in your password, but if the site requires a second factor, the extension stops at the password field and waits. It doesn't integrate with authenticator apps or SMS verification. For sites that use hardware keys like YubiKeys, there's no support at all. You're on your own there. If your workflow involves a lot of 2FA-heavy accounts, this becomes a friction point pretty quickly. Another limitation that matters more than it should. The free tier caps you at fifty password entries. I found out about this after spending twenty minutes importing my full list, only to have about half of them silently rejected. The extension doesn't warn you during import. It just silently drops entries beyond the limit. Upgrading to the paid tier removes this ceiling, but if you're evaluating the tool on the free version, you need to know upfront that it's more of a trial experience than a usable product for anyone with a substantial password count. Sync across devices also has quirks. The extension supports cloud sync between browsers on the same machine, but cross-machine sync requires a paid account and even then it's not instantaneous. I noticed a delay of about thirty seconds to two minutes between updates propagating across my laptop and desktop. Not a dealbreaker, but noticeable if you're actively switching between devices during a login session.
Getting Started
You can download I forgot from the official site at iforgot.app. There's a Chrome extension, a Firefox add-on, and a standalone desktop app that handles the same functionality without needing a browser. The desktop version is actually more reliable for email scanning since it has broader filesystem and mail client access. If you're deciding between browser and desktop, go desktop unless you have a reason not to. The setup wizard walks you through importing from CSV, connecting email accounts, and setting a master password. Don't skip the master password step. Without it, all stored credentials are readable by anyone with access to your machine or browser profile. I've seen people skip this because they assume the extension encrypts everything by default. It does encrypt at rest, but the master password unlocks the decryption key. No master password means no unlock mechanism beyond the raw encrypted blob. For most people the free tier is enough to test whether the workflow fits their habits. If you end up needing more than fifty passwords or wanting cross-device sync, the paid tier runs about four dollars a month. Not cheap for a single-purpose tool, but if password reset is a recurring pain point in your day, it saves enough time to justify the cost after the first few resets. My rough estimate is that the average reset flow takes about eight minutes with I forgot versus twenty to thirty minutes doing it manually across tabs and email clients. That's a meaningful difference if you're hitting reset more than a couple times a week.
Edge Cases and Troubleshooting
Sites that use dynamic username patterns or SSO login pages tend to confuse the matcher. I forgot matches against the domain and stored usernames, but if a site uses a subdomain login or redirects through an identity provider like Okta or Azure AD, the extension won't surface any credentials. You'll need to fill those manually or bypass the extension entirely for those domains. I added those sites to an exclusion list in the settings to avoid the confusion. Another edge case involves password managers that store metadata alongside credentials. Some enterprise tools tag passwords with project names, cost centers, or shared access flags. I forgot ignores all metadata fields and only reads the username, password, and URL. That's fine for personal use but worth knowing if you're pulling from an enterprise vault and expecting richer context to carry over. It doesn't. If the email scanner isn't finding reset messages, check three things in order. First, verify the connected email account actually receives password reset emails for the site in question. Sometimes forwarding rules or spam filters intercept them before the extension can scan. Second, make sure the extension has permission to access that mail account in your browser or OS settings. Third, try manually refreshing the mail connection from the extension settings. The OAuth token can expire silently in some configurations and the extension won't tell you it's stale until you trigger a scan and get nothing back.

Bottom Line
I forgot does one thing and does it reasonably well. If your password problems are mostly about resets and reclaiming access rather than managing a growing credential inventory, it's a solid choice. If you need full vault features, 2FA integration, or cross-browser sync without paying, you're probably better off with a more general-purpose solution. No tool solves every problem. Knowing what this one actually handles lets you decide whether it fits your situation or whether you'd be better off combining it with something else for the gaps.