National merchant account guidance
How Do I Reset a Merchant Portal Password?
Use the portal provider's official sign-in or account-recovery path, complete its identity checks, and create a unique password. The exact screens and recovery methods vary, so account-specific instructions should come from the provider that operates your portal.
Safe reset path
Start from a trusted portal address
Open a saved official bookmark, a verified provider website, or the authenticated link supplied in your account materials. Avoid reset links from unexpected messages, advertisements, or callers.
Step-by-step
Complete the provider's recovery process
Confirm the correct account
Identify the portal operator and the username or business email assigned to the user. Do not assume the processor, gateway, POS platform, and equipment portal share credentials.
Choose the official reset option
Select the provider's password-reset or account-recovery control from its sign-in page. Follow the displayed instructions without forwarding codes or links to another person.
Complete identity verification
Use the recovery method already bound to the account. If that method is unavailable, contact the provider through its official support channel and expect additional verification.
Create a distinct credential
Choose a long, unique password that is not reused on email, banking, POS, gateway, or other business systems. A reputable password manager can generate and store it.
After the reset
Check the account before returning to routine work
A successful reset restores one credential. It is also a useful moment to review authentication and access controls.
Confirm multifactor authentication
Enable or restore the provider's supported MFA option where available. Store recovery codes according to your organization's security policy, separate from the password.
Review users and recent activity
Check authorized users, contact methods, unfamiliar sessions, security alerts, and recent administrative changes. Escalate anything unexpected through official support.
Update approved storage
Save the new credential only in the organization's approved password manager or credential process. Do not place it in tickets, shared documents, chat, or email.
Document without recording secrets
Record the date, affected user, provider case number, and completed control checks. Never include the password, one-time code, or recovery secret.
When recovery fails
Use official support and preserve the evidence
No reset message arrives
Check the exact username, approved inbox filters, and whether an administrator controls account recovery. Do not repeatedly trigger requests if the portal warns of a lockout.
The recovery method is outdated
Ask the portal provider for its documented identity-verification process. An authorized account contact may need to participate before recovery details can change.
You suspect account takeover
Contact the provider immediately through a verified channel, preserve alerts and timestamps, review linked users, and follow your organization's incident-response process.
A caller requests a code
Stop the interaction. Do not disclose passwords or verification codes. Independently contact the provider using a known official number or authenticated portal.
Related resources
Continue with practical account guidance
Common questions
Merchant portal password reset FAQ
Can an administrator reset another user's password?
That depends on the provider's roles and recovery design. Use documented administrator controls; never share a common credential as a workaround.
Should passwords be changed on a fixed schedule?
Follow the portal provider's requirements and your security policy. Reset immediately when compromise is suspected, and use a unique password rather than predictable variations.
What if I lost access to my MFA device?
Use a prearranged recovery method or official provider support. Account recovery may require additional identity verification and can take longer than a routine password change.
Can Payments Max reset the portal for me?
Do not assume Payments Max operates or can access a third-party portal. Use the provider named on the verified sign-in page or your account materials.
Last editorial review: August 11, 2026. Sources reviewed: current NIST digital identity guidance and CISA password and MFA guidance. Provider procedures can change.
Next step
Recover access through a trusted channel
Verify the portal address, complete the provider's recovery checks, set a unique credential, and review MFA and authorized users after access returns.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US