Two-factor authentication protects your accounts from hackers, but what happens when you can’t access your phone? What if you lose your authentication device? Recovery codes exist for exactly these moments—they’re your backup plan when normal authentication methods fail. Yet most people never save them, leaving themselves locked out of their own accounts. Understanding recovery codes and how to use them safely is essential for anyone serious about account security.
What Are Recovery Codes and Why They Matter
Recovery codes (also called backup codes) are a set of one-time-use codes that let you regain access to your account if you lose your primary authentication method. When you enable two-factor authentication on Gmail, Microsoft 365, GitHub, social media, or any major service, the platform generates a list of codes—usually 8 to 16 alphanumeric codes that you download, print, or screenshot.
These codes bypass the normal two-factor requirement. If you lose your phone or your authentication app malfunctions, you can use one recovery code to log in. This makes them your lifeline when 2FA becomes a barrier instead of a protection.
The critical principle: recovery codes should be stored separately from your authentication devices. If your phone dies and the codes are also on that phone, you’re locked out. If someone steals your phone and also finds your codes, they have full access. The goal is secure, accessible backup storage that’s geographically or digitally separate from your primary authentication method.
Where Recovery Codes Are Generated
Most major services generate recovery codes automatically when you set up two-factor authentication. Here’s where to find them:
- Gmail/Google Account: Settings > Security > 2-Step Verification > Backup codes
- Microsoft 365: Account.microsoft.com > Security > Advanced security options > Additional security verification
- GitHub: Settings > Account security > Recovery codes
- Apple ID: appleid.apple.com > Security > Recovery codes
- Facebook: Settings > Security and login > Recovery codes
- Amazon AWS: IAM > Users > Security credentials > Multi-factor authentication
- Cryptocurrency Exchanges: Account settings > Security > Backup codes
When you first enable 2FA, most services display recovery codes immediately with an instruction: “Save these somewhere safe.” Most people click through without saving them. Don’t be that person. Those codes are insurance against account lockout.
How to Store Recovery Codes Safely
The challenge is storing codes somewhere secure yet accessible. Here are three reliable approaches:
Password Manager Storage (Recommended)
Your password manager (Bitwarden, 1Password, LastPass) can store recovery codes in a secure note. This is ideal because:
- The codes are encrypted end-to-end
- They sync across your devices
- They’re backed up automatically
- You can access them from anywhere if you need them
- They’re separate from your phone, so losing your phone doesn’t mean losing your codes
When you enable 2FA on an account, copy the recovery codes directly into a secure note in your password manager. Label it clearly (e.g., “Gmail Recovery Codes – Created March 2026”). You now have access to both the codes and your passwords in one secure location.
Physical Printed Storage
Some people print recovery codes and store them in a safe, locked drawer, or safe deposit box. This works if you:
- Print the codes immediately when generated
- Store the printout in a physically secure location
- Know where to find them if you need them urgently
- Understand that a physical printout can be lost or damaged
This approach has a critical weakness: if you need to use a recovery code, you have to physically access your safe, which might not be possible in an emergency. It’s more suitable as a secondary backup.
Dedicated Recovery Code Vault
Some services specifically designed for this (like Aegis for Android, or simple spreadsheet tools) let you store all your recovery codes in one encrypted file. This approach works but adds complexity—you need another password to remember, another account to protect.
When and How to Use Recovery Codes
Recovery codes should be treated as emergency-only credentials. You use them when you can’t access your normal two-factor method. Scenarios include:
- Your phone is lost, stolen, or destroyed
- Your authentication app crashes or becomes inaccessible
- Your phone number has changed and SMS 2FA codes aren’t arriving
- Your security key is lost
- You’re traveling and your phone is unreachable
Most services let you use a recovery code during login. When prompted for your 2FA method, look for an option like “Can’t access your authenticator?” or “Use a recovery code.” Enter one code. That code becomes invalid immediately and can never be used again. This is why you receive multiple codes—each code is single-use.
Never use recovery codes for routine login. That defeats their purpose. They’re backup credentials for emergencies.
Recovery Code Best Practices
Generate New Codes Periodically
If you use a recovery code to regain access, generate a new set immediately. The codes you didn’t use remain valid, but it’s good practice to refresh them annually or after any security event.
Use One Code, Regenerate All
Most platforms let you regenerate your entire recovery code set whenever you want. If you suspect one code has been compromised, regenerate all of them. This invalidates old codes and creates a new set. Your password manager note gets updated with the new codes.
Don’t Share Recovery Codes
Recovery codes are as sensitive as passwords. Never share them with anyone, including account support staff. Legitimate support representatives will never ask for recovery codes.
Protect Your Backup Storage
If you use a password manager, that manager becomes the key to your recovery codes. Protect your master password fiercely. Use a strong, unique password and enable 2FA on the password manager account itself. If someone gains access to your password manager, they gain access to all your recovery codes.
Test Your Recovery Access
Before you desperately need a recovery code, test the process. On a secondary account or in a test environment, try using a recovery code to log in. Understand the interface. Confirm the code works. You don’t want to discover technical issues during an actual account emergency.
The Relationship Between 2FA Methods
Recovery codes are part of a layered security approach. Your account security hierarchy looks like this:
- Primary: Password (what you know)
- Secondary (Primary 2FA): Authentication app or security key (what you have)
- Tertiary (Backup 2FA): Recovery codes (emergency backup)
- Quaternary: Account recovery through email or SMS (last resort when all else fails)
Recovery codes are not meant to replace authenticator apps or security keys. They’re meant to bridge the gap when those methods fail. This layering ensures you always have a path back into your account, even in worst-case scenarios.
Common Recovery Code Mistakes to Avoid
Not Saving Codes at All — This is the most common mistake. You enable 2FA, see the codes, but don’t save them. Then you lose your phone and discover you have no way back in. Saving codes takes 30 seconds.
Saving Codes Only on Your Phone — If you screenshot recovery codes and store them only on the device that holds your authentication app, you’ve defeated the purpose. If that device is compromised, both your 2FA method and your recovery codes are gone.
Using the Same Recovery Code Twice — Each code is single-use. Once you use it, it’s invalid. Trying to use it again won’t work. Keep track of how many codes you’ve used and know when you need to regenerate.
Ignoring Code Expiration — Some services allow recovery codes to expire if unused for a long period (typically a year or two). Check your account settings periodically and regenerate if they’ve expired.
Recovery Codes Are Part of Your Security Plan
Two-factor authentication dramatically improves your security, but it only works if you have a reliable way to regain access when things go wrong. Recovery codes exist precisely for these moments. By generating them, storing them safely, and understanding how to use them, you’re not weakening your security—you’re strengthening it. You’re ensuring that lost devices, app crashes, or unexpected circumstances don’t lock you out of your own accounts permanently.
Your recovery codes are your safety net. Don’t ignore them. Save them today.

