Recovery Codes Explained: Your Emergency Access Lifeline
The Code That Saves You from Lockout
You set up multi-factor authentication on your most important accounts. You use an authenticator app or a hardware key every time you sign in. Everything is working perfectly — until one day you drop your phone in a lake, your hardware key breaks, or your device is stolen.
Now what?
Without a way to verify your identity outside your normal MFA method, you are locked out of your own accounts. Recovery codes are the safety net that prevents this nightmare scenario. They are one-time-use codes generated when you enable MFA, designed specifically for emergencies when your primary authentication method is unavailable.
Yet despite their importance, recovery codes are the most overlooked and poorly stored piece of the security puzzle. This guide explains everything you need to know about recovery codes — what they are, how they work, how to store them, and what to do if you lose them.
What Are Recovery Codes?
Recovery codes (also called backup codes or emergency codes) are a set of pre-generated, one-time-use passwords that allow you to access your account when your primary MFA method is unavailable.
How Recovery Codes Work
- Generation: When you enable MFA on a service, the service generates a set of codes (typically 8–16 codes, each 8–12 characters long).
- Storage: You are instructed to save these codes in a secure location. The service does not store them in a retrievable format.
- Usage: When you cannot use your primary MFA method (lost phone, broken hardware key), you enter one of your recovery codes instead of the usual MFA code.
- Exhaustion: Each code can only be used once. After using a code, it is invalidated. Once all codes are used, you must generate a new set.
Why Recovery Codes Exist
MFA is designed to be difficult to bypass — that is the whole point. But this creates a problem when you legitimately need to access your account and your MFA device is unavailable. Recovery codes solve this by providing a pre-authenticated backup path that does not depend on your MFA device.
Think of recovery codes as the spare key to your house. You hope you never need it, but if you lose your primary key, it is the only way back in.
When You Need Recovery Codes
Recovery codes are essential in several scenarios:
| Scenario | Description | Recovery Code Needed? |
|---|---|---|
| Lost phone | Your phone with the authenticator app is lost or stolen | Yes |
| Broken hardware key | Your YubiKey or similar device is physically damaged | Yes |
| Device reset | You factory-reset your phone without backing up authenticator data | Yes |
| Phone number changed | You changed your number and SMS-based MFA no longer works | Yes |
| App migration | You switched authenticator apps and cannot export seeds | Yes |
| Travel | You are traveling and forgot your MFA device at home | Yes |
| Account recovery | The service’s automated recovery process is too slow | Yes |
| Shared accounts | A team member with the MFA device is unavailable | Yes |
The Cost of Not Having Recovery Codes
If you lose your MFA device and do not have recovery codes:
- You may be locked out for days while going through the service’s account recovery process.
- Some services have lengthy identity verification procedures that require government ID uploads.
- In worst-case scenarios, you may permanently lose access to the account and all its data.
- For email accounts, this cascades — you cannot reset passwords for other services because you cannot access the recovery email.
How Many Recovery Codes Do You Get?
The number and format of recovery codes vary by service:
| Service | Number of Codes | Code Format | Regeneration Allowed? |
|---|---|---|---|
| 10 codes | 8 characters (XXXX XXXX) | Yes, unlimited | |
| GitHub | 16 codes | 8 characters (xxxxxxxx) | Yes, unlimited |
| Microsoft | 10 codes | 10 characters | Yes |
| Apple | 28-character recovery key | Single code, not multi-use | Yes |
| Bitwarden | Generated by user | Configurable | Yes |
| AWS | 10 codes | Multi-character | Yes |
| Discord | 8 codes | 8 characters | Yes |
Most services allow you to regenerate recovery codes at any time. When you regenerate, all previous codes are invalidated — any unused old codes will no longer work.
Recovery Code Storage Comparison
How you store recovery codes determines whether they will actually save you in an emergency. Here is a comparison of storage methods:
| Storage Method | Security | Accessibility | Durability | Cost | Best For |
|---|---|---|---|---|---|
| Paper in fireproof safe | High | Low (physical access needed) | High (paper lasts decades) | Low | Maximum security, infrequent access |
| Encrypted USB drive | High | Medium | Medium (drives can fail) | Low | Tech-savvy users with backup power |
| Password manager (encrypted vault) | High | High (accessible anywhere) | High (cloud-backed) | $0–$5/mo | Most users |
| Encrypted digital note | Medium-High | High | Medium (depends on service) | Free–Low | Convenience-focused users |
| Safety deposit box | Very High | Very Low (bank access required) | Very High | $20–$50/year | High-value accounts |
| Unencrypted text file | Very Low | Very High | Medium | Free | Never recommended |
| Email draft | Very Low | High | Low | Free | Never recommended |
Our Recommendation
The optimal approach combines two methods:
- Primary storage: Encrypted in your password manager (accessible when you have your master password).
- Backup storage: Written on paper and stored in a fireproof safe or safety deposit box.
This gives you both digital accessibility and physical resilience. If your password manager is compromised or unavailable, the paper backup saves you. If your house floods, the digital backup saves you.
How to Generate Strong Recovery Codes
Some services let you customize recovery code complexity. If you need to generate additional backup codes for services that do not provide them, or if you want to create your own backup codes for offline storage, use our Password Generator to create strong, random strings.
Best Practices for Recovery Code Management
1. Save Codes Immediately
The moment you enable MFA and see recovery codes, save them. Do not close the dialog, do not plan to “do it later.” Later often means never.
2. Use at Least Two Storage Locations
Store recovery codes in at least two different locations — one digital, one physical. This protects against both digital compromise and physical disasters.
3. Do Not Store Codes with Your MFA Device
If you store recovery codes on the same phone as your authenticator app, losing the phone means losing both your MFA method and your recovery codes. Store them in a separate location.
4. Do Not Share Recovery Codes
Recovery codes are equivalent to passwords. Sharing them with anyone — even trusted colleagues — creates a security risk. If you need to grant someone emergency access, use a shared password manager vault with proper access controls.
5. Regenerate After Use
After using a recovery code, generate a new set immediately. The used code is invalidated, but the remaining codes are still exposed — if someone obtained a photo of your recovery codes, the unused ones are still valid.
6. Label the Storage Location
Write down where you stored your recovery codes (but not the codes themselves). For example: “Google recovery codes — fireproof safe, bottom drawer.” This helps you or a trusted person find them in an emergency without exposing the codes to anyone who sees the note.
7. Test Your Recovery Codes
After saving your recovery codes, test one to make sure it works. Use it to sign in, then immediately generate a new set. This confirms your storage method is correct and your codes are valid.
Regenerating Recovery Codes
Most services allow you to regenerate recovery codes at any time. Here is when you should regenerate:
| Trigger | Action | Priority |
|---|---|---|
| Used a recovery code | Regenerate immediately | Critical |
| Suspect codes were exposed | Regenerate immediately | Critical |
| Changed phone/device | Regenerate (old codes still work, but fresh codes are safer) | High |
| Added new MFA method | Regenerate to ensure clean slate | Medium |
| Periodic review (every 6 months) | Regenerate and re-store | Medium |
| Team member left the organization | Regenerate if shared accounts were involved | High |
When you regenerate:
- All previous codes are instantly invalidated.
- A new set of codes is generated.
- You must save the new codes before closing the page.
- Any old stored copies are now useless.
Recovery Codes and Password Strength
Recovery codes are one layer of your account security. They do not replace the need for strong passwords. A compromised recovery code combined with a weak password still gives an attacker full account access.
Protect your accounts with:
- Strong, unique passwords for every account — generated with our Password Generator.
- MFA enabled on all important accounts — learn more in our beginner’s guide to MFA.
- Recovery codes stored securely — following the practices in this guide.
- Regular breach monitoring — check your passwords against known breaches using our Breach Checker.
For a comprehensive password strategy, read our guide on how to create strong passwords. And to understand the full MFA ecosystem, see our authenticator apps explained guide.
Recovery Code Emergency Checklist
If you are locked out of your account and need to use recovery codes, follow this checklist:
| Step | Action |
|---|---|
| 1 | Locate your recovery codes (check password manager, fireproof safe, safety deposit box) |
| 2 | Navigate to the service’s login page |
| 3 | Enter your username and password |
| 4 | When prompted for MFA, select “Use a recovery code” or “Backup code” |
| 5 | Enter the recovery code exactly as written (codes are case-sensitive) |
| 6 | Once logged in, immediately regenerate a new set of recovery codes |
| 7 | Save the new codes in your designated storage locations |
| 8 | Consider adding a backup MFA method (second authenticator app, hardware key) |
Frequently Asked Questions
How many recovery codes should I save?
Save every code the service provides — typically 8 to 16 codes. Each code is single-use, so having more codes means more emergency access attempts before needing to regenerate. Always save the complete set, not just "a few."Can recovery codes expire?
Most services do not set expiration dates on recovery codes. They remain valid until used or until you regenerate a new set. However, some services may invalidate old codes when security policies change. Check your service's documentation for specifics.What if I lost my recovery codes and my MFA device?
Contact the service's support team immediately. Most services have an identity verification process for this scenario — you may need to provide government ID, answer security questions, or verify ownership of associated email addresses. This process can take days to weeks, which is why storing recovery codes securely is so critical.Should I store recovery codes in my password manager?
Yes, this is one of the best storage options. Password managers encrypt your data with your master password, making recovery codes accessible from any device while remaining secure. Choose a strong master password generated with our [Password Generator](/password-generator) and protect your password manager with MFA.Can someone use my recovery codes to bypass MFA permanently?
No. Recovery codes are single-use — each code works only once. After using a code, it is invalidated. Once all codes are used, you generate a new set. An attacker who obtains your recovery codes can use them only until you regenerate. This is why regenerating after any suspected exposure is critical.About the Author
The GeneratePass Editorial Team builds privacy-first security tools that run entirely in your browser. Every tool on GeneratePass processes data locally — nothing is ever sent to a server. Visit generatepass.me to try our free Password Generator, Password Strength Checker, and Breach Checker.
GeneratePass Developers
Verified AuthorSecurity researchers, cryptography engineers, and software developers dedicated to making browser-based cryptographic tools accessible and secure. We write guides with a focus on local execution, zero-trust patterns, and client-side data sovereignty.
Related Security Tools
Related Publications
Authenticator Apps Explained: TOTP, HOTP, and Setup Guides
Understand how authenticator apps generate TOTP and HOTP codes, how seed secrets work, and how to set up and migrate between apps.
Beginner's Guide to Multi-Factor Authentication (MFA)
Learn what MFA is, how authentication factors work, and which methods — TOTP, SMS, hardware keys — offer the best protection for your accounts.
Google Passkeys Guide: Setup, Sync, and Migration
A complete guide to Google Passkeys — what they are, how to set them up, cross-device sync, and migrating from passwords to passkeys.