Skip to main content

Recovery Codes

Recovery codes are single-use backup codes that let you sign in when you can't access your authenticator app.

When You Get Recovery Codes

Recovery codes are displayed automatically when you first enable MFA. They appear in a two-column grid with a Copy all button. Save them in a secure location before clicking Done.

Using a Recovery Code

Recovery codes can be used in place of your 6-digit TOTP code during sign-in:

  1. On the Enter verification code screen, enter a recovery code in the Code field instead of your 6-digit TOTP code.
  2. Click Verify.

After a recovery code is used, it becomes invalid and cannot be used again.

Checking Remaining Codes

Navigate to Security in the sidebar. In the Two-Factor Authentication section, you'll see Recovery codes remaining: X showing how many unused codes you have left.

Regenerating Recovery Codes

If you've used most of your codes or want to invalidate the existing ones:

  1. Navigate to Security in the sidebar.
  2. In the Two-Factor Authentication section, click Regenerate Recovery Codes.
  3. New codes are displayed in a two-column grid.
  4. Click Copy all to save them, then click Done.
warning

Regenerating codes invalidates all previous recovery codes. Make sure to save the new ones.

Best Practices

  1. Store securely — Keep recovery codes in a password manager or encrypted storage
  2. Don't share — Recovery codes are equivalent to your password + MFA combined
  3. Regenerate when low — If you have fewer than 2 codes remaining, regenerate them
  4. Print a backup — Consider printing codes and storing them in a secure physical location

Next Steps


API Reference: For programmatic access, see Recovery Codes.