2FA Recovery Codes: Your Only Line of Defence

Affiliate disclosure: This article contains affiliate links. If you click a link and make a purchase, we may earn a commission at no extra cost to you. Our editorial recommendations are never influenced by commissions — read our full disclosure policy.
The Screen Everybody Skips
Somewhere in the middle of turning on two-factor authentication, a service shows you a block of eight or ten strings of characters and suggests you save them somewhere safe. Most people screenshot it, mean to deal with it later, and never do.
That screen is the entire recovery story for that account. Once 2FA is on, the service will not let you in without a second factor, and it does not care that the reason you cannot produce one is that your phone is at the bottom of a fjord. Recovery codes are the one path that does not require the device. They are not a nice-to-have layer. When the phone is gone, they are the only line left.
What They Actually Are
A recovery code — the same thing is variously called a backup code, a one-time code, or an emergency access code — is a pre-generated single-use secret that the service will accept in place of your usual second factor. Each one works exactly once. Use one and it is spent.
They are generated at the moment you enable 2FA, and they are generated by the service, not by your authenticator app. That is why they survive the loss of your phone: the phone was never involved. It also means every account has its own set, and a recovery code for one service is meaningless to another.
Two properties follow from that, and they drive everything else:
- They bypass your second factor completely. Anyone holding one holds the same power your phone has.
- They are typically not re-issued automatically. Burn through the set and you are back to whatever account-recovery process the service offers, which is usually slower and sometimes involves proving your identity to a human.
Where to Keep Them
The rule that matters more than any specific location: keep them somewhere that does not fail at the same time as the thing they are backing up. A recovery code saved only on the phone whose loss it is meant to survive is not a backup. Neither is one saved as a screenshot in a cloud photo library protected by the account it unlocks.
| Location | Survives a lost phone | Survives a house fire | Practical risk |
|---|---|---|---|
| Printed, in a locked drawer or safe at home | Yes | Only in a fireproof safe | Someone with physical access to your home |
| Printed, second copy at another address | Yes | Yes | Whoever can reach that address |
| Encrypted note in a password manager | Yes | Yes | Both factors depend on one vault |
| Screenshot in your phone gallery | No | No | Syncs to the cloud, readable by anything on the device |
| Plain text file on the desktop | Sometimes | No | Readable by any malware that gets a foothold |
| Email to yourself | No | Yes | Your inbox is the account attackers want most |
Paper wins more often than people expect, and it wins for an unfashionable reason: it cannot be exfiltrated over a network. A printed sheet in a locked drawer is invulnerable to every remote attack there is. The threat it is exposed to — someone physically in your home going through your drawers — is one most households can reason about honestly.
The password-manager option is legitimate and it is what many people will actually do, which counts for something. But be clear-eyed about the dependency it creates. If the codes for your email live in the vault, and the vault is protected by 2FA on your phone, and the recovery codes for the vault are also in the vault, you have built a circle with no way in. Break the circle: the recovery codes for the password manager itself must live outside it, on paper.
The Rules That Prevent the Common Disasters
- Never store recovery codes alongside the username and password for the same account. Together they are a complete set of keys; separated, either half alone is far less useful.
- Store the manager's own codes on paper, outside the manager.
- Label which service each set belongs to. A page of unlabelled codes found in two years' time is indistinguishable from noise.
- Note the date you generated them. Sets get regenerated and stale copies mislead.
- When you use one, cross it off. Retrying a spent code during a lockout wastes the attempts you have.
Regenerate, and When
Most services let you generate a fresh set at any time, which invalidates the old one. Do it when:
- You have used more than half the set.
- You suspect the codes were exposed — a lost notebook, a shared computer, an old laptop you sold.
- You have changed how you store them and want a clean starting point.
- Someone who had access to your storage location no longer should.
The Alternative That Removes the Problem
Recovery codes exist because your second factor lives on exactly one device. Enrol a second device — a tablet, an old phone kept in a drawer, or a second hardware key — and the single point of failure is gone. You still keep the codes, but you stop needing them.
For accounts you genuinely cannot lose, this is the better answer. A pair of hardware keys, one on the keyring and one at home, is the version of this that security professionals actually use. Our YubiKey review covers what that hardware does and does not do, and best 2FA apps 2026 covers which apps make enrolling a second device straightforward rather than painful.
What to Do Right Now
Pick your email account. Not your favourite service, not your bank — email, because every password reset in your life passes through it. Go to its security settings, find the recovery or backup codes section, generate a set, and put them on paper somewhere you will find them and a burglar will not.
Then do your password manager. Then your bank. That is the whole priority order, and three accounts covers the great majority of the damage a lockout can do.
If you are setting up 2FA from scratch rather than patching it afterwards, the order and the account-by-account walkthrough are in how to set up two-factor authentication. If you are about to change phones, do this first and then read transferring your authenticator to a new phone — in that order, because the codes are what makes the migration safe to attempt.
The Honest Limits
Recovery codes protect against losing your second factor. They do nothing about a compromised password, a phished session, or a service that gets breached at its own end — a page you can check against your own address with the tools in checking whether your email was hacked.
And they are only as good as the place you put them. A set of codes is a bearer token: whoever holds it, holds the account. Treat the sheet of paper with the seriousness you would treat a spare front-door key, because functionally that is what it is.
Covered in this guide
Reviewed by NorwegianSpark Editorial — written with AI assistance and reviewed by the NorwegianSpark SA editorial team · Last updated: 6 September 2026




