
Two-factor authentication is the single best protection against account hacks — and, ironically, the number-one reason people get permanently locked out of their own accounts. The fix is 2FA backup codes: generated once, stored securely, and used in emergencies when your phone is lost, stolen, or broken. This guide shows exactly how to set them up on every major platform and where to keep them.
What Are 2FA Backup Codes?
Backup codes are 8–10 single-use codes that stand in for your 2FA device when you cannot access it. Each code works once and is then invalidated. Most platforms issue 10 at a time and let you regenerate a fresh set when you run low. They are your safety net — without them, a lost phone can mean a lost account.
When You’ll Need a Backup Code
- Phone lost or stolen.
- Phone broken or replaced before migrating your authenticator app.
- Authenticator app accidentally deleted.
- Traveling internationally without SMS service.
- A SIM-swap or SIM delay.
- A device factory reset.
Generate Backup Codes — by Platform
- Google: myaccount.google.com → Security → 2-Step Verification → Backup codes. 10 codes per set.
- Facebook & Instagram: Accounts Center → Password and Security → Two-Factor Authentication → Recovery Codes. 10 codes.
- Apple ID: uses Trusted Devices plus a 28-character Recovery Key at appleid.apple.com → Sign-In and Security → Recovery Key.
- Microsoft: account.microsoft.com → Security → Advanced security options → generate a 25-character recovery code.
- X (Twitter): Settings → Security → Two-factor authentication → Backup code (one code that regenerates when used).
- Discord: User Settings → My Account → Two-Factor Auth → View Backup Codes. 10 codes.
- Crypto exchanges: each issues 8–10 codes at 2FA setup — print and store them offline.
Where to Store Backup Codes
Best: a password manager (1Password, Bitwarden, Dashlane); printed on paper in a home safe; or an encrypted USB drive for travel. Worst: a screenshot in your phone gallery, an email to yourself, an unencrypted cloud note, or a sticky note on your monitor — all of which an attacker who reaches one account can then use to reach the rest.
Lost Both Your 2FA Device AND Your Backup Codes?
You are not necessarily locked out for good — but you are now in the slow lane. Recovery timelines: Google account recovery (3–7 days), Meta selfie video + evidence (24–72 hours), Apple account recovery (5–14 days), crypto exchanges (30–60 day identity verification). AccRevert specializes in 2FA-lockout recovery through platform identity verification — a flat $299 to start, success-based after recovery. Learn about our 2FA & Authenticator Recovery service.
Frequently Asked Questions
What happens if I lose my phone with 2FA enabled?
If you saved backup codes, use one to log in, then re-enroll a new device. If you did not, you must go through the platform’s slower identity-verification recovery — which is exactly why generating codes in advance matters.
How many backup codes should I keep?
Keep the full set your platform issues (usually 10) and regenerate when you are down to two or three. Store them somewhere you can reach without the very device you are trying to recover.
Are backup codes safe to store in a password manager?
Yes — a reputable zero-knowledge password manager with its own 2FA is one of the safest places. Avoid screenshots, plain email, or unencrypted notes.
Can I recover an account if I lost both my device and codes?
Usually yes, through identity verification — it just takes longer. Professional escalation can speed up stuck or repeatedly denied cases.
Final Checklist
- Generate backup codes on every important account today.
- Store them in a password manager or a safe — never as a phone screenshot.
- Regenerate when you are running low.
- Prefer an authenticator app or hardware key over SMS.
Locked out with no device and no codes? Submit your case to AccRevert — $299 to start, success-based after recovery.
Related Articles
Stop guessing and document the case properly.
Our team can review the account history, available ownership evidence and the recovery steps already attempted.