Night Study/Guides/Securing your account

Where to keep 2FA backup codes so a lost phone does not lock you out

Saving the recovery codes is the easy part. The usual mistake is saving them somewhere that disappears at exactly the same moment the authenticator does, which is why the codes turn out to be missing on the one day they were needed.

The test is one question, and you can apply it to any storage idea in about five seconds: if the phone in my pocket vanished right now, could I still read these? If the answer is no, it is not storage, it is a second copy of the same single point of failure.

What follows is the three arrangements that fail that test, then the ones that pass, then how to check yours without waiting for an emergency.

Three places not to keep 2FA backup codes

A screenshot in the phone's photo library

It fails twice over. The phone that holds the photo is usually the phone that holds the authenticator, so losing one loses both. And the photo library syncs to a cloud account, which means the codes now also live in an account that a thief could reach — while being unavailable to you if you are locked out of that same account.

A note in the password manager that the authenticator protects

A password manager is a reasonable place for codes, with one condition. If signing in to the manager requires a code from the authenticator app, and the codes you need are inside the manager, you have built a loop. The day the authenticator is gone, the manager is locked, and the codes that would unlock things are behind the lock.

This one is worth checking rather than assuming. Open your password manager's security settings and look at what the second factor is. If it is the same app, move at least one copy of the codes out.

An email to yourself

Sending the codes to the account's own email address puts them in the inbox that is also the account's recovery path. Anyone who takes the email account gets the codes as a bonus, and a search for the exchange's name finds them in seconds. Email is also the place people are least likely to have a strong second factor of their own.

There is a fourth arrangement that fails for a different reason: not saving them at all because the enrolment screen offered to "remind you later". It does not remind you later. Generate them in the same sitting as the enrolment or it will not happen.

Where to keep backup codes instead

None of these are clever. The whole point is that they are boring enough to still work in three years.

  • Written on paper, kept somewhere you would keep a passport. Paper does not sync, cannot be phished and does not run out of battery. Write the service name next to each set, because a sheet of unlabelled digits is useless.
  • A password manager that uses a different second factor — a passkey, a hardware key, or a separate app. Now the two are independent and the loop is broken.
  • An encrypted file on a drive that lives in a drawer. More work to set up, and the passphrase becomes the thing you must not forget, but it survives a house move better than most options.
  • Two copies in two places. Fire, flood and burglary are unimaginative attackers, and a single sheet in a single drawer is vulnerable to all three. A second copy somewhere geographically separate is the cheapest resilience available.

One arrangement that covers all three failures at once: paper for the codes, a hardware key as the second factor, and a password manager that holds everything except its own recovery material. It is not elegant, and it does not depend on any one device surviving.

When the exchange gives you a setup key instead of codes

Not every enrolment ends with a sheet of numbered codes. Some show a setup key instead: a string of letters, printed under the QR code, that recreates the authenticator entry on any other device. Treat it exactly like a set of backup codes, with one difference that matters. A spent backup code is useless to a thief, but the setup key keeps working until you re-enrol, so a copy of it that leaks stays dangerous for as long as the authenticator does. Write it on the same sheet as your codes, label it with the service name, and never keep it as a screenshot.

How to test your backup codes without using one

The point of a backup is that it has been proven to work. Testing recovery codes is awkward because using one consumes it, but there is a version of the test that costs nothing.

  1. Put your phone in another room. Genuinely, not on the table face down.
  2. From memory alone, describe exactly where the codes are and what you would have to unlock to reach them.
  3. If any step in that description requires the phone, the test has failed and you know which link to fix.

If you want to go further and actually spend one code, do it deliberately: sign out, sign back in using a code, then immediately regenerate the full set. That converts an assumption into a fact, and the cost is two minutes.

What backup codes do not recover

Backup codes are the fallback for a lost second factor. They are not the fallback for a lost email account, a forgotten password or an account that has been restricted, all of which run through different processes. It is worth knowing which of your recovery paths currently exists — the phone-migration piece walks through them in the order the exchange will ask, and the settings guide puts this step where it belongs in the overall sequence.

Where to store codes is the same question on every exchange. What is worth checking is how backup codes behave. Google's own page on its backup codes, read on 3 October 2026, says a code becomes inactive once used and that creating a new set makes the old set inactive. That is the common design and the reason the advice above insists on regenerating, but not every exchange issues codes at all, and some show a setup key instead, so check what your own enrolment screen gave you.

Password managers and used codes

Can I store backup codes in my password manager?

Yes, provided the password manager is not itself protected by the authenticator those codes are backing up. If it is, the two depend on each other and neither is a backup. Keep at least one copy outside the manager.

What if I already used one of my codes?

Each code is single use. Once you have used one, sign in and generate a fresh set, then destroy the old sheet. Partly spent sets are how people find they have none left at the worst moment.