Turning on two-factor authentication is the single best upgrade you can make to an online account. But 2FA introduces a new failure mode that passwords never had: if the thing that generates your codes disappears - A phone dropped in a lake, wiped by a repair shop, or left in a taxi - The lock you built to keep attackers out now keeps you out. Backup codes exist for exactly that moment. They are the break-glass plan, and almost everyone skips them.
Account lockout is not a rare edge case. Support forums for Google, Microsoft, and Apple are full of people who enabled 2FA responsibly, lost a device, and discovered that "contact support" often ends in a days-long identity review - Or a permanently lost account, since a service that can casually bypass 2FA isn't really offering 2FA at all. This guide explains what backup codes are, how they differ from other recovery methods, and a storage strategy that keeps them both safe and reachable.
What backup codes actually are
Backup codes (also called recovery codes) are a small set of single-use codes - Typically eight to ten strings of eight to ten digits or characters - Generated by a service when you enable two-factor authentication. Each code stands in for your second factor exactly once. Enter your password, click "try another way," type an unused backup code, and you're in. The code is then burned forever.
Under the hood they're simple: random values generated server-side, stored hashed like passwords, and checked off as consumed. There's no clock, no shared secret, no cryptographic ceremony. That simplicity is the point - A backup code works from any device, with no app, no phone number, and no battery.
That also defines their risk profile. Anyone holding an unused code plus your password can log in as you. A backup code is effectively a second password with the 2FA check removed, which is why where you keep them matters more than anything else in this article.
Rule of thumb: save your backup codes the same minute you enable 2FA. If you postpone it, you're betting your account on your phone never breaking.
How backup codes compare with other recovery options
Most services offer several ways back in. They are not equally safe:
| Recovery method | Works if phone is lost? | Phishing/SIM-swap risk | Verdict |
|---|---|---|---|
| Backup codes (printed or in a vault) | Yes | Low - Offline, nothing to intercept | Best all-round fallback |
| Second authenticator device | Yes | Low | Excellent, if you own a spare device |
| SMS to recovery phone number | Only with the number | High - SIM swapping targets exactly this | Avoid as your only fallback |
| Recovery email | Yes | Medium - Inherits that inbox's security | Fine as a layered option |
| Support-based identity review | Yes | Low, but slow and unreliable | Last resort, may take days or fail |
The pattern to notice: SMS recovery quietly reintroduces the weakness you adopted 2FA to escape. NIST's digital identity guideline SP 800-63B has discouraged phone-based codes since 2017 because numbers can be hijacked through SIM-swap fraud. If an attacker can move your number to their SIM, a "recovery phone" becomes their way past your authenticator - The same trade-off covered in our comparison of TOTP versus SMS second factors.
Where to store backup codes (and where not to)
The storage question has two competing goals. Codes must survive the disaster that takes out your phone, and they must not be readable by whoever finds or steals your stuff. Three approaches thread that needle:
Paper, stored like a passport. Print or hand-write the codes and keep them where you keep birth certificates - A fireproof box, a locked drawer, a safe deposit box. Paper can't be phished, hacked, or synced to the wrong cloud. Label the page with the service name but not your username or password.
An encrypted password manager. Storing codes in the notes field of the matching vault entry is convenient and safe if the vault itself doesn't depend on the same second factor you're backing up. A vault protected by a strong master password and available on a second device (a laptop, a tablet) is a legitimate home for backup codes - Our password manager guide covers picking one.
An encrypted file you control. A text file inside an encrypted container or archive, saved to a USB stick or trusted cloud storage, also works for technical users.
What doesn't work: a screenshot in your camera roll, a plain note in Notes or Keep synced to the very account it unlocks, an email to yourself titled "Google backup codes," or a sticky note under the keyboard. Each of these either dies with the phone or hands the codes to anyone who compromises your inbox.
Surveys of 2FA usability consistently find that only a minority of users save recovery codes at setup time - Most click past the screen. Don't be most users.
Setting up your break-glass plan, step by step
- List your critical accounts. Email first - It resets everything else - Then password manager, banking, cloud storage, and work accounts. Our 15-minute password hygiene checklist pairs well with this exercise.
- Generate codes on each service. Look under Security → Two-factor authentication → Backup codes (Google, GitHub, Microsoft, and most major platforms follow this pattern). If you enabled 2FA long ago and never saved codes, generate a fresh set now.
- Store them using one of the three methods above. Be consistent; scattered codes are codes you can't find during an emergency.
- Register a second factor as well. Many services let you add a hardware key or a second authenticator device alongside codes. Redundancy beats any single fallback. You can watch how TOTP codes are derived from a shared secret with our in-browser TOTP code generator - The same secret can be loaded into two apps at once, which is itself a form of backup.
- Test one code. On a service where codes regenerate easily, burn one deliberately so you know the flow before you need it under stress.
- Track usage and regenerate. Cross off used codes. When only a couple remain - Or if you ever suspect the sheet or vault was exposed - Regenerate the whole set, which invalidates the old one instantly.
When you're locked out anyway
No codes, no phone, no spare device? Your options narrow but don't vanish. Check whether you're still signed in anywhere - A logged-in browser session on a laptop can often mint new backup codes without a second-factor challenge. Try every recovery method the service lists; an old registered tablet counts. Failing that, start the vendor's account recovery review immediately, from a device and network you've used with the account before, since recovery systems weigh familiarity heavily.
And if the lockout follows a theft rather than an accident, treat it as a potential compromise: change the password from another device the moment you regain access - Generate the replacement with a proper password generator rather than improvising one - And review recent activity. Our guide on what to do after a data breach walks through that damage-control sequence.
Backup codes for teams and families
Break-glass planning scales beyond one person. For a family, the question is "who gets in if I can't?" - A sealed envelope of codes for the household's critical accounts, kept with other emergency documents, is a low-tech answer that works. For businesses, backup codes for shared infrastructure accounts (domain registrar, DNS, cloud root accounts) belong in a documented, access-controlled location, not in one admin's drawer. Developers building their own login systems face the same design duty in reverse - If you add TOTP to your product, ship recovery codes with it from day one; a service like our 2FA API handles code generation and verification, but the recovery path is a product decision only you can make.
FAQ
How many backup codes do I get, and can I make more?
Most services issue a batch of 8–10 single-use codes. You can regenerate a fresh batch at any time from the security settings while you're logged in - Doing so immediately invalidates all previous codes. That's also the correct response if you ever suspect your saved codes were seen by someone else.
Are backup codes safer than SMS recovery?
Stored properly, yes. Backup codes are offline: there's no network message to intercept and no phone number to SIM-swap. SMS recovery depends on your carrier's resistance to social engineering, which has repeatedly proven weak. Use codes plus a second registered device, and treat SMS as a last layer if you keep it at all.
Should I keep backup codes in my password manager?
It's a reasonable choice with one caveat: avoid circular dependencies. If your vault requires TOTP from your phone to unlock on new devices, and your phone is what you lost, vault-stored codes may be unreachable. Keep the vault accessible from a second device, or keep a paper copy of the vault's own recovery kit, and the loop is broken.
Do backup codes expire?
Generally no - They remain valid until used or until you regenerate the set. A code from three years ago still works if it was never consumed. That longevity is why storage security matters: an old forgotten printout is as powerful as a fresh one.
What's the difference between a backup code and a recovery key?
Backup codes are a batch of short single-use codes for skipping a second-factor check. A recovery key is usually a single long-lived secret - Like the 28-character key Apple offers or a password manager's account recovery kit - That can restore access or decrypt data outright. Recovery keys are more powerful and deserve even more careful storage, but the principle is identical: generate it now, store it offline, and never photograph it.