Backup codes are one-time-use security codes that let you access your account when your primary two-factor authentication method is unavailable — your phone is lost, your authenticator app is wiped, or your SIM card is stolen. Without them, a locked account can take days to recover through manual identity verification. Setting them up takes under five minutes. Recovering an account without them can take 3–7 business days on platforms like Google or GitHub — if recovery is possible at all.
What Are Backup Codes?
Backup codes are pre-generated, single-use alphanumeric codes tied to your account’s two-factor authentication (2FA) setup. Most platforms generate 8–10 codes at a time, each typically 8–12 characters long. They exist as a fallback when your primary 2FA method — an SMS code, authenticator app, or hardware key — is inaccessible. Platforms including Google, GitHub, Facebook, Dropbox, and Microsoft offer them as part of standard 2FA security settings. Each code works exactly once, then becomes permanently invalid.
Backup Codes vs. Recovery Codes
Many users treat these terms as synonyms, but some platforms draw a meaningful distinction.
| Feature | Backup Codes | Recovery Codes |
|---|---|---|
| Primary purpose | Bypass a 2FA step during login | Restore full account access or reset 2FA |
| Usage limit | Single-use per code | Often single-use, but may unlock broader access |
| Scope of access | Login only | May disable 2FA entirely and reset security settings |
| Example platform | Google (calls them “backup codes”) | GitHub (uses “recovery codes” to restore 2FA access) |
On Google, backup codes let you complete a sign-in when your authenticator app is unavailable. On GitHub, recovery codes serve a similar purpose but are explicitly framed as tools to regain access when all 2FA methods fail — effectively resetting your 2FA configuration. For most day-to-day use, the distinction is minor, but it matters when you’re locked out entirely.
Understanding how backup codes relate to other authentication methods is easier with a broader grasp of how verification codes work across different platforms.
Where to Find Your Backup Codes
Backup codes live inside your account’s security settings. The general path:
Account Settings → Security → Two-Factor Authentication → Backup Codes
- Google: myaccount.google.com → Security → 2-Step Verification → Backup codes
- GitHub: Settings → Password and authentication → Two-factor authentication → Recovery codes
Note: Most platforms display backup codes only once — immediately after you enable 2FA or explicitly request them. If you didn’t save them during setup, you’ll need to regenerate a new set, which invalidates all previously issued codes.
Each platform hides them in a slightly different place — Instagram’s backup codes, for example, sit under the Accounts Center security settings rather than in the app’s main menu.
How to Set Up Backup Codes
- Log in and navigate to Security Settings.
- Enable two-factor authentication if not already active.
- Locate the Backup Codes or Recovery Codes section within your 2FA settings.
- Click Generate or Show codes.
- Copy, download, or print the codes immediately — they won’t be shown again in full.
- Store them securely (see below).
- Confirm you’ve saved them before closing the page.
Common mistake: Generating new backup codes without updating your stored copy. New codes immediately invalidate the old set.
How to Use Backup Codes
When your primary 2FA method is unavailable during login:
- Enter your username and password as normal.
- When prompted for a 2FA code, look for a link labeled “Try another way”, “Use backup code”, or “Can’t access your authenticator?”
- Select the backup code option.
- Enter one unused backup code from your saved list.
- Complete the login.
- Cross off or delete that code — it’s now permanently invalid.
If you’re regularly reaching for backup codes, that’s a signal to reconfigure your primary 2FA method. Consoles follow the same idea; on PlayStation you enter one at the sign-in prompt, as described in PS5 backup codes.
How to Store Backup Codes Securely
If you use a password manager (1Password, Bitwarden, etc.) → store codes as a secure note within that manager. If you prefer physical storage → print the codes and keep them in a locked drawer or safe, separate from your devices. If you need offline digital storage → save in an encrypted file (VeraCrypt, encrypted PDF) on a USB drive stored physically.
Common mistake: Saving backup codes in an email draft, unencrypted cloud note (standard Google Keep, Apple Notes without lock), or a plain
.txtfile on your desktop. Any of these becomes a single point of failure if your email or cloud account is compromised.
Avoid storing backup codes in the same account they protect. If your Google account is compromised, backup codes stored in Google Drive are also compromised.
For technical reference on authentication security standards, NIST guidelines on digital identity provide thorough coverage of credential management.
What Happens When All Backup Codes Are Used or Lost
Scenario: A five-person startup team uses GitHub for source control. One developer loses their phone, exhausts their backup codes attempting recovery, and gets locked out before regenerating a new set.
Options at that point:
- Regenerate before exhaustion: If you have at least one backup code remaining, log in, navigate to your 2FA settings, and generate a fresh set of 10 codes immediately.
- Trusted device recovery: Some platforms (Google, Apple) allow sign-in from a previously verified device without a 2FA prompt.
- Account recovery process: Most major platforms offer identity verification via recovery email, phone number on file, or a support ticket with ID verification. Google’s account recovery process typically takes 3–5 business days. GitHub’s support team handles locked accounts case-by-case.
- Organization admin recovery: On GitHub Organizations or Google Workspace, an admin can remove 2FA requirements for a specific user, restoring access without backup codes.
The FIDO Alliance’s authentication specifications outline why multiple recovery pathways are a core principle of modern authentication design. Some services work differently: Steam issues a single Steam recovery code instead of a list, and X issues one code at a time — see Twitter backup codes.
Frequently Asked Questions
How do I set up backup codes? Enable 2FA on your account, navigate to Security Settings, find the Backup Codes section, and click Generate. Save the codes immediately — they’re shown once.
What happens if I lose my backup codes? Use a trusted device, recovery email, or contact platform support. Recovery timelines range from immediate (trusted device) to 3–7 business days (manual identity verification).
How should I store my backup codes securely? Use an encrypted password manager, print and store physically in a locked location, or save in an encrypted offline file. Avoid plain-text files, email drafts, or unlocked cloud notes.
Can I generate new backup codes after using the originals? Yes. Navigate to your 2FA settings and regenerate at any time. Generating new codes immediately invalidates all previous codes — update your stored copy right away.
What is the difference between backup codes and recovery codes? The terms are often interchangeable, but some platforms use “recovery codes” to indicate broader access restoration (including resetting 2FA), while “backup codes” specifically bypass a single 2FA prompt during login.
Can I use the same backup code more than once? No. Each backup code is single-use and permanently invalidated after one successful use.
What should I do if I think my backup codes have been compromised? Log in immediately using your primary 2FA method, navigate to security settings, and regenerate a new set. This invalidates the compromised codes instantly. Then audit recent account activity for unauthorized access.
Understanding SMS-based authentication clarifies why backup codes exist as an independent fallback rather than relying on a single delivery channel.
The Electronic Frontier Foundation’s Surveillance Self-Defense guide offers additional guidance on layering authentication methods for higher-risk accounts.
Summary
Backup codes are a critical safety net. A single set of 8–10 codes stands between you and a multi-day account recovery process if your primary 2FA method fails. Generate them when you enable 2FA, store them in an encrypted password manager or locked physical location, cross off each code as you use it, and regenerate a fresh set before exhausting the current batch. Account lockouts without backup codes are measured in days. Managing them takes minutes.