GeneratePass
Authentication 9 min read

Recovery Codes Explained: Your Emergency Access Lifeline

By GeneratePass Developers | Published: July 08, 2026 | Last Updated: July 08, 2026

The Code That Saves You from Lockout

You set up multi-factor authentication on your most important accounts. You use an authenticator app or a hardware key every time you sign in. Everything is working perfectly — until one day you drop your phone in a lake, your hardware key breaks, or your device is stolen.

Now what?

Without a way to verify your identity outside your normal MFA method, you are locked out of your own accounts. Recovery codes are the safety net that prevents this nightmare scenario. They are one-time-use codes generated when you enable MFA, designed specifically for emergencies when your primary authentication method is unavailable.

Yet despite their importance, recovery codes are the most overlooked and poorly stored piece of the security puzzle. This guide explains everything you need to know about recovery codes — what they are, how they work, how to store them, and what to do if you lose them.


What Are Recovery Codes?

Recovery codes (also called backup codes or emergency codes) are a set of pre-generated, one-time-use passwords that allow you to access your account when your primary MFA method is unavailable.

How Recovery Codes Work

  1. Generation: When you enable MFA on a service, the service generates a set of codes (typically 8–16 codes, each 8–12 characters long).
  2. Storage: You are instructed to save these codes in a secure location. The service does not store them in a retrievable format.
  3. Usage: When you cannot use your primary MFA method (lost phone, broken hardware key), you enter one of your recovery codes instead of the usual MFA code.
  4. Exhaustion: Each code can only be used once. After using a code, it is invalidated. Once all codes are used, you must generate a new set.

Why Recovery Codes Exist

MFA is designed to be difficult to bypass — that is the whole point. But this creates a problem when you legitimately need to access your account and your MFA device is unavailable. Recovery codes solve this by providing a pre-authenticated backup path that does not depend on your MFA device.

Think of recovery codes as the spare key to your house. You hope you never need it, but if you lose your primary key, it is the only way back in.


When You Need Recovery Codes

Recovery codes are essential in several scenarios:

ScenarioDescriptionRecovery Code Needed?
Lost phoneYour phone with the authenticator app is lost or stolenYes
Broken hardware keyYour YubiKey or similar device is physically damagedYes
Device resetYou factory-reset your phone without backing up authenticator dataYes
Phone number changedYou changed your number and SMS-based MFA no longer worksYes
App migrationYou switched authenticator apps and cannot export seedsYes
TravelYou are traveling and forgot your MFA device at homeYes
Account recoveryThe service’s automated recovery process is too slowYes
Shared accountsA team member with the MFA device is unavailableYes

The Cost of Not Having Recovery Codes

If you lose your MFA device and do not have recovery codes:

  • You may be locked out for days while going through the service’s account recovery process.
  • Some services have lengthy identity verification procedures that require government ID uploads.
  • In worst-case scenarios, you may permanently lose access to the account and all its data.
  • For email accounts, this cascades — you cannot reset passwords for other services because you cannot access the recovery email.

How Many Recovery Codes Do You Get?

The number and format of recovery codes vary by service:

ServiceNumber of CodesCode FormatRegeneration Allowed?
Google10 codes8 characters (XXXX XXXX)Yes, unlimited
GitHub16 codes8 characters (xxxxxxxx)Yes, unlimited
Microsoft10 codes10 charactersYes
Apple28-character recovery keySingle code, not multi-useYes
BitwardenGenerated by userConfigurableYes
AWS10 codesMulti-characterYes
Discord8 codes8 charactersYes

Most services allow you to regenerate recovery codes at any time. When you regenerate, all previous codes are invalidated — any unused old codes will no longer work.


Recovery Code Storage Comparison

How you store recovery codes determines whether they will actually save you in an emergency. Here is a comparison of storage methods:

Storage MethodSecurityAccessibilityDurabilityCostBest For
Paper in fireproof safeHighLow (physical access needed)High (paper lasts decades)LowMaximum security, infrequent access
Encrypted USB driveHighMediumMedium (drives can fail)LowTech-savvy users with backup power
Password manager (encrypted vault)HighHigh (accessible anywhere)High (cloud-backed)$0–$5/moMost users
Encrypted digital noteMedium-HighHighMedium (depends on service)Free–LowConvenience-focused users
Safety deposit boxVery HighVery Low (bank access required)Very High$20–$50/yearHigh-value accounts
Unencrypted text fileVery LowVery HighMediumFreeNever recommended
Email draftVery LowHighLowFreeNever recommended

Our Recommendation

The optimal approach combines two methods:

  1. Primary storage: Encrypted in your password manager (accessible when you have your master password).
  2. Backup storage: Written on paper and stored in a fireproof safe or safety deposit box.

This gives you both digital accessibility and physical resilience. If your password manager is compromised or unavailable, the paper backup saves you. If your house floods, the digital backup saves you.

How to Generate Strong Recovery Codes

Some services let you customize recovery code complexity. If you need to generate additional backup codes for services that do not provide them, or if you want to create your own backup codes for offline storage, use our Password Generator to create strong, random strings.


Best Practices for Recovery Code Management

1. Save Codes Immediately

The moment you enable MFA and see recovery codes, save them. Do not close the dialog, do not plan to “do it later.” Later often means never.

2. Use at Least Two Storage Locations

Store recovery codes in at least two different locations — one digital, one physical. This protects against both digital compromise and physical disasters.

3. Do Not Store Codes with Your MFA Device

If you store recovery codes on the same phone as your authenticator app, losing the phone means losing both your MFA method and your recovery codes. Store them in a separate location.

4. Do Not Share Recovery Codes

Recovery codes are equivalent to passwords. Sharing them with anyone — even trusted colleagues — creates a security risk. If you need to grant someone emergency access, use a shared password manager vault with proper access controls.

5. Regenerate After Use

After using a recovery code, generate a new set immediately. The used code is invalidated, but the remaining codes are still exposed — if someone obtained a photo of your recovery codes, the unused ones are still valid.

6. Label the Storage Location

Write down where you stored your recovery codes (but not the codes themselves). For example: “Google recovery codes — fireproof safe, bottom drawer.” This helps you or a trusted person find them in an emergency without exposing the codes to anyone who sees the note.

7. Test Your Recovery Codes

After saving your recovery codes, test one to make sure it works. Use it to sign in, then immediately generate a new set. This confirms your storage method is correct and your codes are valid.


Regenerating Recovery Codes

Most services allow you to regenerate recovery codes at any time. Here is when you should regenerate:

TriggerActionPriority
Used a recovery codeRegenerate immediatelyCritical
Suspect codes were exposedRegenerate immediatelyCritical
Changed phone/deviceRegenerate (old codes still work, but fresh codes are safer)High
Added new MFA methodRegenerate to ensure clean slateMedium
Periodic review (every 6 months)Regenerate and re-storeMedium
Team member left the organizationRegenerate if shared accounts were involvedHigh

When you regenerate:

  1. All previous codes are instantly invalidated.
  2. A new set of codes is generated.
  3. You must save the new codes before closing the page.
  4. Any old stored copies are now useless.

Recovery Codes and Password Strength

Recovery codes are one layer of your account security. They do not replace the need for strong passwords. A compromised recovery code combined with a weak password still gives an attacker full account access.

Protect your accounts with:

  1. Strong, unique passwords for every account — generated with our Password Generator.
  2. MFA enabled on all important accounts — learn more in our beginner’s guide to MFA.
  3. Recovery codes stored securely — following the practices in this guide.
  4. Regular breach monitoring — check your passwords against known breaches using our Breach Checker.

For a comprehensive password strategy, read our guide on how to create strong passwords. And to understand the full MFA ecosystem, see our authenticator apps explained guide.


Recovery Code Emergency Checklist

If you are locked out of your account and need to use recovery codes, follow this checklist:

StepAction
1Locate your recovery codes (check password manager, fireproof safe, safety deposit box)
2Navigate to the service’s login page
3Enter your username and password
4When prompted for MFA, select “Use a recovery code” or “Backup code”
5Enter the recovery code exactly as written (codes are case-sensitive)
6Once logged in, immediately regenerate a new set of recovery codes
7Save the new codes in your designated storage locations
8Consider adding a backup MFA method (second authenticator app, hardware key)

Frequently Asked Questions

How many recovery codes should I save? Save every code the service provides — typically 8 to 16 codes. Each code is single-use, so having more codes means more emergency access attempts before needing to regenerate. Always save the complete set, not just "a few."
Can recovery codes expire? Most services do not set expiration dates on recovery codes. They remain valid until used or until you regenerate a new set. However, some services may invalidate old codes when security policies change. Check your service's documentation for specifics.
What if I lost my recovery codes and my MFA device? Contact the service's support team immediately. Most services have an identity verification process for this scenario — you may need to provide government ID, answer security questions, or verify ownership of associated email addresses. This process can take days to weeks, which is why storing recovery codes securely is so critical.
Should I store recovery codes in my password manager? Yes, this is one of the best storage options. Password managers encrypt your data with your master password, making recovery codes accessible from any device while remaining secure. Choose a strong master password generated with our [Password Generator](/password-generator) and protect your password manager with MFA.
Can someone use my recovery codes to bypass MFA permanently? No. Recovery codes are single-use — each code works only once. After using a code, it is invalidated. Once all codes are used, you generate a new set. An attacker who obtains your recovery codes can use them only until you regenerate. This is why regenerating after any suspected exposure is critical.

About the Author

The GeneratePass Editorial Team builds privacy-first security tools that run entirely in your browser. Every tool on GeneratePass processes data locally — nothing is ever sent to a server. Visit generatepass.me to try our free Password Generator, Password Strength Checker, and Breach Checker.

GeneratePass Developers

Verified Author

Security researchers, cryptography engineers, and software developers dedicated to making browser-based cryptographic tools accessible and secure. We write guides with a focus on local execution, zero-trust patterns, and client-side data sovereignty.

Focus: Cryptography Standard: zero-trust