Recovery Codes
What Are Recovery Codes?
Recovery codes are backup codes that allow you to log in to your account when your TOTP authenticator app is unavailable. This can happen if you lose your phone, switch devices, or accidentally delete your authenticator app.
When you enable two-factor authentication (TOTP), the system generates a set of recovery codes. Each code is a single-use code that can replace your TOTP code during login.
How to View Your Recovery Codes
Recovery codes are shown once when you first enable two-factor authentication. You can also view and regenerate them at any time:
- Go to Account Settings
- Scroll to the Two-Factor Authentication section
- Click View Recovery Codes
Storing Recovery Codes Securely
It is critical to store your recovery codes in a safe place. Recommended storage methods include:
- Password manager - Store them as a secure note in your password manager (recommended)
- Printed copy - Print the codes and store the paper in a secure location such as a locked drawer or safe
- Encrypted file - Save them in an encrypted document on your device
Do not store recovery codes in plain text on your computer, in your email, or in cloud notes without encryption. Anyone who has access to these codes can bypass your two-factor authentication.
Using a Recovery Code
If you cannot access your authenticator app during login:
- Enter your email and password as usual
- On the two-factor authentication screen, click Use Recovery Code
- Enter one of your unused recovery codes
- Click Verify
The recovery code is consumed immediately and cannot be used again.
Generating New Recovery Codes
You can generate a fresh set of recovery codes at any time:
- Go to Account Settings
- Scroll to the Two-Factor Authentication section
- Click Regenerate Recovery Codes
This immediately invalidates all previously issued recovery codes. Make sure to save the new codes in a secure location before leaving the page.
Best Practices
- Generate new recovery codes if you suspect they have been compromised
- Keep track of how many codes you have used - regenerate before you run out
- After regenerating codes, update the stored copy in your password manager or secure location