Two-Factor Authentication Backup Codes — Complete Guide

Two-factor authentication is the single best protection against account hacks — and the #1 reason people get permanently locked out of their own accounts. The fix: 2FA backup codes. Generated once, stored securely, and used in emergencies when your phone is lost, stolen, or broken. This guide covers exactly how to set up backup codes on every major platform.

What are 2FA backup codes?

Backup codes are 8–10 single-use codes that replace your 2FA device when you can’t access it. Each code works once, then is invalidated. Most platforms give you 10 codes at a time and let you regenerate when you run low.

When to use a backup code

  • Phone lost or stolen
  • Phone broken or replaced before 2FA app migration
  • Authenticator app accidentally deleted
  • Traveling internationally without SMS service
  • SIM card swap delays
  • Device factory reset

Generate backup codes — by platform

Google

myaccount.google.com → Security → 2-Step Verification → Backup codes → “Show codes”. 10 codes per generation.

Facebook & Instagram

Settings → Accounts Center → Password and Security → Two-Factor Authentication → Recovery Codes. 10 codes per generation.

Apple ID

Apple uses Trusted Devices and a Recovery Key (28 characters). Generate at: appleid.apple.com → Sign-In and Security → Recovery Key.

Microsoft

account.microsoft.com → Security → Advanced security options → Generate a new recovery code. ONE 25-character code.

X (Twitter)

Settings → Security → Two-factor authentication → Backup code. 1 single backup code that regenerates when used.

Discord

User Settings → My Account → Two-Factor Auth → “View Backup Codes.” 10 codes.

GitHub

Settings → Password and authentication → Two-factor authentication → “View” backup codes. 16 codes.

Crypto exchanges

Each generates 8–10 codes at 2FA setup. Print these on paper and store offline.

Where to store backup codes

Best practices

  • Password manager: 1Password, Bitwarden, Dashlane.
  • Printed paper: Store in a home safe or safe deposit box.
  • Encrypted USB drive: Useful for traveling.

Worst practices

  • Screenshot saved to phone gallery
  • Email to yourself
  • Note in unencrypted cloud storage
  • Sticky note on monitor

What if I lost both backup codes AND 2FA device?

  • Google: Account Recovery (3–7 days)
  • Meta: Selfie video + ID upload (24–72 hours)
  • Apple: Account Recovery (5–14 days)
  • Crypto exchanges: 30–60 day identity verification

Need recovery help?

Lost both 2FA device and backup codes? AccRevert specializes in 2FA bypass recovery via platform identity verification. Learn about our 2FA & Authenticator Bypass service.

Related Articles

Submit Your Case for Review

Related Articles

Crypto Exchange Locked? Recovery Guide

Crypto Exchange Account Locked? Recovery Guide

Losing access to a crypto exchange account can mean losing thousands of dollars. Unlike social media platforms, crypto exchanges require regulated identity verification (KYC). This makes recovery both harder and more reliable — if you have your documents. Coinbase Recovery

Read more »
Session Cookie Theft How Hackers Bypass 2FA

Session Cookie Theft: How Hackers Bypass 2FA

Two-factor authentication is the single best account security improvement. But session cookie theft is the one attack vector that completely bypasses 2FA. This guide explains how it works and how to defend yourself. What Is a Session Cookie? When you

Read more »
Discord Account Hacked? Recovery Plan

Discord Account Hacked? Recovery Steps

Discord hacks usually happen through one of three vectors: stolen authentication tokens (the most common), phishing links in DMs, or weak passwords. Recovery requires understanding which method was used. Method 1: Token Theft Recovery If a malicious app stole your

Read more »

Accessibility Toolbar