Every service shows you your recovery codes exactly once: a small grid of one-time codes that appears right after you enable two-factor authentication, next to a button that says Download or I saved them. Most people click past it. Months later a phone dies, and those codes turn out to be the only way back in.
Recovery codes are the parachute of 2FA. Almost everyone packs one, and almost nobody packs it properly. A screenshot buried in a camera roll, a codes.txt on an old laptop, a printout that went out with the recycling: these are storage plans that fail exactly when they are needed. This guide covers what recovery codes actually are, what to do in the five minutes after you first see them, where to store them ranked by real tradeoffs, and why you should regenerate them after every use.
What recovery codes actually are
When you turn on 2FA, most services generate a set of backup codes, typically somewhere between eight and twelve short strings of letters and numbers. Each one works exactly once as a substitute for the six-digit code from your authenticator app. Use one to log in and it is burned; the rest stay valid.
Two properties make them different from everything else in your security setup:
- They are independent of your authenticator. Recovery codes are not derived from your TOTP secret. Your phone can be at the bottom of a lake and the codes still work from any browser on any machine.
- They are static. A TOTP code expires in about 30 seconds. A recovery code stays valid until it is used or regenerated. That is what makes it a lifeline, and also what makes sloppy storage dangerous: anyone who has your password plus one unused recovery code can walk straight into the account.
Treat each code like a spare key to your front door, not like a disposable login code.
The five minutes after you enable 2FA
The moment a service displays your recovery codes is your one guaranteed chance to handle them well. Run the same short routine every time:
- Save the codes before closing the tab. Download the file or copy the codes into secure storage immediately. Do not tell yourself you will do it later; that screen usually never comes back on its own.
- Label them. A file full of random strings is useless in an emergency. Record the service name, the account email, and the date you generated them.
- Store them in at least two places, in two different formats. The next section ranks your options.
- Verify the login end to end. Sign out and back in once using your authenticator, so you know the whole chain works while you can still fix it.
Most services let you view or regenerate codes later from the same security settings page, but only while you can still log in. Once you are locked out, that door closes, which is precisely the problem the codes were meant to solve.
Where to store recovery codes, ranked
1. A password manager (best for most people)
Storing recovery codes in the notes field of the matching password entry gives you encryption, sync, search, and access from any device. For most people and most accounts, this is the right default.
The tradeoff is concentration. If the same vault holds the password, the TOTP secret, and the recovery codes, anyone who gets into the vault owns the account outright, and losing access to the manager means losing everything at once. Mitigate this by protecting the manager itself with a strong unique master password and its own 2FA, and by keeping the manager's emergency kit on paper. For your two or three highest-value accounts, above all your primary email, consider keeping recovery codes out of the vault entirely.
2. An encrypted file
A password-protected archive or an encrypted disk volume on a computer or USB drive keeps codes offline and fully under your control, at no cost. It works well as a second copy.
The weaknesses are human: you have to remember the passphrase, remember the file exists, and remember where the drive lives, possibly years from now. And to be clear, a note in a standard notes app is not this option; unless the note is genuinely end-to-end encrypted and locked, it is plain text with extra steps.
3. Paper in a safe place
A printed or handwritten copy in a home safe, a locked drawer, or a bank deposit box is immune to malware, phishing, cloud breaches, and sync bugs. As a last-resort copy, paper is still the gold standard.
Its limits: fire, water, moving house, and the fact that it is never with you when you travel. Paper also goes stale quietly; when you regenerate codes, the old printout becomes worthless without looking any different. Use paper as your catastrophe copy, not your only copy.
The strongest setup is layered: a password manager or encrypted file for day-to-day reach, plus paper at home for disasters. Two copies, two formats, two locations. For a deeper look at building this kind of redundancy, see our guide to secure 2FA code backup.
What not to do
- Do not screenshot codes into your camera roll. Photo libraries sync to the cloud, surface in search, and get scrolled through in public. The screenshot is the most common storage method and one of the worst.
- Do not keep them in plain text. An unencrypted note, a shared doc, or codes.txt on the desktop is readable by any malware, any borrowed-laptop snoop, and whoever ends up with the machine.
- Do not email them to yourself. Your inbox is already the recovery hub for every account you own; adding recovery codes hands an intruder both the reset links and the bypass codes. It is also circular: if the codes protect your email account, you cannot read them once you are locked out of that account.
- Do not store them only on the phone that runs your authenticator. Whatever destroys the phone destroys your second factor and its backup in the same moment.
- Do not keep a single copy, anywhere. One copy is a plan with no margin for error.
Rotate codes after use, and after doubt
Recovery codes are single-use, but the set does not clean up after itself. After you actually use one to get back into an account:
- Regenerate the full set from the service's security settings. Regeneration invalidates every old code at once, including any copy you may have lost track of.
- Update every stored copy. Replace the vault entry, the encrypted file, and the printout. A stale copy is worse than none, because it feels like safety.
Also regenerate when trust is shaky rather than broken: you suspect a device or password manager compromise, a paper copy went missing in a move, you once shared a code with anyone for any reason, or you simply cannot list where all your copies live. Regenerating takes a minute and costs nothing.
Recovery codes are plan B, not plan A
Codes are the parachute; they should not be the aircraft. Plan A is an authenticator setup that survives device loss on its own. Authenticator by Vidus6, for example, syncs your vault across iPhone, iPad, Mac, and Android with end-to-end encryption, the key never leaves your hardware, and every new device must be approved from an existing trusted one. With a second synced device, a broken phone becomes an inconvenience instead of a lockout. It is free and works fully offline.
But no sync system covers every failure, such as losing all your devices at once. Recovery codes cover exactly that gap, which is why you want both. For the full map of ways people lose access, read our guide to avoiding account lockout.
Frequently asked questions
Should recovery codes live in the same password manager as my passwords?
For most accounts, yes; convenience wins and the risk is manageable. For your primary email and financial accounts, keep the codes somewhere the vault cannot reach, such as paper in a safe. Then a vault breach still is not a total loss.
I never saved my recovery codes. What now?
If you can still log in, this is a two-minute fix: open the service's security settings, regenerate the codes, and store them properly this time. If you are already locked out, your path runs through the service's account recovery process; expect identity checks and delays.
Do recovery codes expire?
Generally they stay valid until used or regenerated, but every service sets its own policy, and some invalidate old sets when you change security settings. Check the service's own documentation; our per-service setup guides cover where to find 2FA and backup-code settings for more than 2,000 services.
Pack the parachute while the ground is still far away: save the codes the moment you see them, keep two labeled copies in two formats, never store them next to the thing they are meant to rescue, and regenerate after every use. Ten minutes of setup buys you the luxury of not caring when a phone dies.



