Password Security

🛡️ 2FA Backup Codes: What They Are and How to Store Them Safely (2026)

2FA Backup Codes: What They Are and How to Store Them Safely: 2fa backup codes; two-factor authentication; recovery codes — key points at a glance
2FA Backup Codes: What They Are and How to Store Them Safely: 2fa backup codes; two-factor authentication; recovery codes — key points at a glance
By ZA Tanoli, Hobbyist with a keen interest in password security and online safety · 25 September 2026 · 8 min read · 1,799 words

One in four people who enable two-factor authentication eventually get locked out of their own account. Nearly every time, the reason is the same: they never saved their backup codes during setup.

Two-factor authentication backup codes are the safety net that makes 2FA survivable when your phone is lost, broken, replaced, or wiped. Skip them and you are one phone upgrade away from permanent account loss. Save them correctly and you have a failsafe that works even when every other recovery option has failed.

Quick answer: 2FA backup codes (also called recovery codes) are pre-generated, one-time-use alphanumeric codes issued when you set up two-factor authentication. They bypass your authenticator app when your primary device is unavailable. Save them in an encrypted password manager or print them immediately — accounts without saved backup codes can be permanently unrecoverable.

What Are 2FA Backup Codes?

Two-factor authentication backup codes — also called recovery codes — are pre-generated, single-use alphanumeric codes issued at the moment you enable 2FA on an account. Each code works exactly once: after you use it to sign in, it expires permanently. Most services generate 8 to 16 codes per account, each typically 8 to 12 characters long.

Definition: A 2FA backup code is a one-time emergency credential that bypasses your authenticator app or SMS second factor when your primary authentication device is unavailable — such as after a phone replacement, hardware failure, or SIM change. Generated at setup, they should be stored offline or in an encrypted vault immediately.

Unlike your regular six-digit TOTP codes, backup codes do not rotate on a timer. The same set stays valid until you use them or explicitly generate a fresh batch — which immediately invalidates any old codes you had saved.

Why Backup Codes Are Non-Negotiable

Three authoritative sources make the risk concrete:

The failure mode is predictable: you replace your phone, restore your apps, then discover your old authenticator app’s TOTP codes lived only on the previous device. If you registered an old number as SMS backup and have since changed carriers, that door is closed too. Without backup codes, customer support is your last resort — and for high-security services like crypto exchanges, certain email providers, and zero-knowledge password managers, many simply cannot restore access regardless of how convincingly you verify your identity.

What Happens Without Backup Codes

ScenarioConsequence without backup codes
New or factory-reset phoneLocked out indefinitely until support recovery (may take days or fail)
Lost or stolen phoneAccount inaccessible; attacker may still have the second factor you no longer do
Authenticator app wipedAll TOTP codes gone — no fallback exists
SIM changed or portedSMS 2FA no longer works and no alternative remains

For consumer platforms like Google and social media, support can eventually recover the account — slowly, after identity verification that can take a week or more. For crypto platforms, certain email providers, and password managers built on zero-knowledge encryption, no support path exists. Your data is encrypted to keys only you held, and there is no administrative backdoor.

How to Find and Download Your Backup Codes

The path is slightly different on each platform, but the pattern is consistent: Settings → Security → Two-factor authentication → Backup / Recovery codes.

After downloading your codes, most platforms will prompt you to confirm you saved them before proceeding. Do not click past this screen. It is the last checkpoint before you accept sole responsibility for your own account recovery.

Where to Store Backup Codes Safely

The storage method you choose determines whether backup codes actually help when you need them.

Storage methodSecurityAccessible in a crisis?Verdict
Password manager secure noteHigh — encrypted at restYes — any deviceBest option
Printed, stored in a physical safeHighYes — at homeBest for critical accounts
Written in a notebook, locked awayMediumYes — at homeAcceptable
Encrypted file on cloud storageMediumYes — with decryption keyAcceptable
Email draft or sent folderLow — unencryptedYes, but exposedAvoid
Screenshot in photo rollLow — plaintext on deviceUnreliableAvoid

The best single approach is a secure note inside a password manager. It is encrypted at rest using the same cryptographic protection as your stored passwords, syncs to every device you own, and is reachable from any browser the moment your phone is gone. The codes live alongside the password for that account, so they are findable immediately — not buried in an email thread from three years ago.

NordPass stores secure notes with the same XChaCha20, zero-knowledge encryption that protects your vault passwords — meaning even NordPass cannot read them. Notes sync across iOS, Android, Windows, macOS, and every major browser, so the codes are accessible from whichever device you have in hand during a recovery event. When you set up 2FA on any new account, the workflow takes seconds: download the backup codes, paste them into a NordPass secure note attached to that login, done. One important rule: if NordPass itself is protected by 2FA, store that account’s backup codes somewhere physically separate from the device where you access NordPass — never keep the recovery codes for your password manager only inside the password manager.

Five Mistakes That Lead to Lockout

1. Skipping past the codes screen during setup. Most platforms display backup codes once at enrollment and tuck them away afterward. If you clicked through, they are still there — go to Security → Two-factor authentication → Recovery codes for each account and verify they are saved.

2. Storing codes only on the phone being protected. Notes in your phone’s default app are inaccessible when your phone is the problem. Store codes somewhere reachable from a laptop, tablet, or borrowed device.

3. Using some codes and not regenerating. Each code is single-use. After using two or three during a recovery event, regenerate a fresh batch immediately and resave the new set. Regenerating invalidates all old codes, including any unused ones.

4. Circular dependencies. If your only copy of backup codes is in your email, and your email is the account you are locked out of, you cannot use them. For your email account specifically, keep a physical printed copy that does not depend on email access to retrieve.

5. Forgetting to audit annually. Most people can name three accounts with 2FA but miss the rest. A password manager’s security dashboard shows every login and which ones have 2FA enabled. Once a year, verify backup codes are saved for every account on that list.

Backup Code Checklist

Affiliate disclosure: Some links in this article are affiliate links. If you sign up through them we may earn a small commission at no extra cost to you. Our password generator is free to use and we only recommend tools we would use ourselves. See our full affiliate disclosure.

FAQs

How many 2FA backup codes should I save?

Save all of them. Most platforms generate 8 to 16 codes per account and they do not expire until used or regenerated, so there is no reason to save fewer. Treat unused backup codes as an emergency reserve: you want the full set available if something goes wrong, not a depleted stack from previous recovery events.

Can I create new backup codes after using some?

Yes. On virtually every platform you can regenerate a fresh batch at any time from the two-factor authentication settings page. When you generate new codes, all previously issued codes — including unused ones — are immediately and permanently invalidated. Regenerate after any recovery event, then save the new codes before leaving the page.

What if I never saved my backup codes and I am now locked out?

Start with the platform’s account recovery flow, typically accessible from the sign-in page via “Try another way” or “Forgot phone.” You will be asked to verify your identity through an alternative method: a trusted device, a recovery email, a registered phone number, or in some cases a government ID review. The process can take 3 to 5 business days and is not guaranteed to succeed. For zero-knowledge platforms, recovery may be impossible. This is precisely why saving backup codes at setup is the only reliable protection.

Are 2FA backup codes the same as a recovery phone number or recovery email?

No, and the distinction matters. A recovery phone number or email is a second channel for receiving a verification code — still something an attacker can compromise through SIM swapping or email phishing. A backup code is a standalone offline credential that works even if your phone number and recovery email are both unavailable. They are complementary: set up all three, but treat your backup codes as the most reliable last resort because they depend on nothing external.

Should I print my 2FA backup codes or store them digitally?

Both is the strongest answer. An encrypted digital copy in a password manager gives you access from any device, anywhere. A printed copy secured at home works even if every digital system you own is simultaneously unavailable. For most accounts, digital-only storage in an encrypted vault is sufficient. For your email account and your password manager — the two accounts that unlock everything else — a printed offline copy adds protection the digital option alone cannot provide.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🛡️ Best Password Generator🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder🛡️ Trusty Password🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more