openideurope.eu

Backup codes: what they are and where to keep them

Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.

Login securityPublished

Backup codes are one-time codes that let you sign in when you cannot use your normal second factor, for example because your phone is lost, broken or stolen. Each code works once. They are the cheapest insurance against being locked out, and they only help if you keep them somewhere safe and reachable.

What backup codes are

When you turn on two-factor authentication, many services offer a list of short codes. Google, for instance, issues a set of 10, each code becomes inactive after use, and a new set deactivates the old one. Details are in Google’s help page on signing in with backup codes.

Backup codes are different from the rolling six-digit values of an authenticator app, explained in TOTP codes explained. TOTP codes change every 30 seconds. Backup codes are static until used.

Where to keep them

Option Good Weak spot
Printed sheet in a safe place at home Works without any device or power Can be lost, burnt or found by others
Password manager (secure note or attachment) Always with you, encrypted, searchable Do not use for the password manager’s own codes
Encrypted file on a USB stick Offline and portable Needs a strong passphrase, easy to forget
Second copy with a trusted person or in a bank deposit box Survives a house fire or move Choose carefully, and only for sealed, labelled copies
Screenshot in your photo library Fast Syncs to the cloud, visible if the phone is unlocked, avoid
Plain note on the same phone as the authenticator Convenient Lost together with the phone

The rule of thumb: a backup code must not depend on the thing it backs up. If your phone is the only place that holds the authenticator and the codes, you have one point of failure, not two.

Step by step

  1. Generate the codes in the security settings of the account, right after you enable 2FA.
  2. Label them with the account name and the date. Do not write your password next to them.
  3. Store them following the table above. For your email, Apple or Google account and password manager, prefer an offline copy.
  4. Keep a second copy in a different place if the account matters, for example a home safe and a trusted relative.
  5. Test your memory, not the code. Once a year, check that you can still find them. Testing a code uses it up, so only do that when you plan to generate a new set.
  6. Replace them after you use several, after a suspected leak or when you change your 2FA method. Delete the old copies.

Special case: the password manager itself

A password manager protects its own vault with a master password and, often, 2FA. Its recovery items, such as an emergency kit or backup codes, belong outside the vault. Print them and keep them with your recovery sheet from the guide on account recovery.

When codes are not the best fallback

A second hardware security key stored in a different place is a stronger backup for many people, because a code can be phished or read over your shoulder while a key cannot. Codes remain the universal fallback that almost every service supports.

Common mistakes

  • Sharing a code with a “support agent”. Real providers never ask for backup codes.
  • Keeping unlimited old lists around. Only the newest set is valid, so remove the rest.
  • Storing codes in an email draft or in the inbox they protect.
  • Forgetting that each use costs one code. Count what is left.

A short worked example

Imagine you have turned on 2FA for your email with an authenticator app on your phone, and you generated 10 backup codes. You print them, label the sheet “Email backup codes, generated October 2026” and put it in a folder at home with your other important papers. A year later your phone is stolen. You get a new phone, open your email sign-in page, choose the option to use a backup code, type one in and sign in. You then set up the authenticator app on the new phone, and generate a fresh set of codes, which deactivates the old sheet. You shred the old print, and the new one goes into the folder. The whole thing takes ten minutes instead of days of support requests.

What if I lose the codes too?

If both the phone and the codes are gone, you fall back on the provider’s recovery process. It can take days, may require proof of identity, and does not always succeed. That is the reason to keep two independent fallbacks, for example codes at home and a second security key somewhere else, as described in our guide to account recovery.

Backup codes for specific situations

Travelling. Take a copy of your backup codes only for the accounts you will need, and keep it apart from your phone and passport. If your phone is lost abroad, a code lets you sign in from a borrowed device, and you can then remove the lost phone from your account.

Shared household. Do not keep your codes in a family folder that everyone can open. A sealed envelope in a personal drawer or safe is enough.

Work accounts. Your employer may manage recovery centrally. Ask your IT team before you generate your own, because company policy may handle lost devices through an administrator instead.

After a breach. If an account was compromised, generate a fresh set of codes once you have secured it. Old codes may have been seen by the attacker.

Bottom line

Backup codes are simple: generate them when you enable 2FA, keep them offline or away from the account they protect, and refresh them when they run low. Ten minutes now can save days of recovery later.

Frequently asked questions

Do backup codes expire?

Usually not by time, but each code can be used only once. Many services also deactivate the old set when you generate a new one, so keep only the latest.

Can I store backup codes in my password manager?

Yes for most accounts, and it is convenient. The exception is the password manager itself: keep its own backup codes or recovery kit offline, otherwise you could be locked out of the vault that holds them.

Is it safe to take a screenshot of backup codes?

It is risky. Screenshots often sync to cloud photo libraries and are visible to anyone who opens your gallery. A printout or an encrypted note is better.

Do I need backup codes if I use passkeys?

Passkeys have their own recovery path, usually through your platform account or a second passkey. If a service still offers backup codes alongside, create them as an extra fallback.

More in Login security