Generate Recovery Backup Codes — Free 2FA Backup Generator
Losing your phone shouldn't mean losing your account: the Recovery Backup Codes Generator lets you enter how many codes you need, then click Generate Backup Codes to get a full set of one-time-use codes in the same format Google and GitHub hand you when you first turn on 2FA. Each code works exactly once, so you can copy, download, or print the list and store it somewhere safe for the day your authenticator app or security key isn't within reach. Use them as your way back in — not as your primary sign-in method.
When your 2FA device is lost, stolen, or simply unavailable, a recovery backup codes generator gives you a guaranteed way back into your profile — without depending on a phone, text message, or Google Authenticator. Think of your codes as the master key you keep in a fireproof safe: you hope you never need them, but the moment you do, you'll be grateful they exist. This free, client-side tool generates secure, one-time-use codes entirely within your browser, so the generated values never leave your device, protecting your credential security from the first moment.
Generate Your Recovery Backup Codes: Step-by-Step Instructions
A recovery code is a pre-generated alphanumeric string — used once as a substitute for your normal second step — when your usual login methods are unavailable. Whether you lose your phone, change your phone number, or can't get codes by text or by call, these codes let you log in and regain access. This client-side recovery backup codes generator operates fully in-browser — generated values never leave your device, so there is no server-side risk to your digital safety or data protection.
The tool generates a set of ten codes by default, each an 8-character code drawn from a 36-character pool (digits 0–9 and lowercase letters a–z). The estimated entropy for each code sits at 41 bits entropy — in the fair range. Codes of this length reach 70 bits with longer configurations and 100 bits with maximum settings. To put this in perspective: even at a trillion guesses per second, exhausting all possibilities would take an enormous amount of time — which is why you should always store your codes securely and treat weak entropy formats as unsuitable for high-stakes profile protection.
Important: Each code is used once. Once a code is consumed during sign-in, it becomes inactive immediately. Cross off or delete codes after using them, and generate new codes before you run out of codes — never leave device recovery to chance by waiting until the last moment.
Generating Backup Codes via Your App (Two-Factor Authentication Enabled)
Most credential managers and identity platforms — including 1Password — allow you to set up recovery code access directly in their mobile or desktop apps. This is the recommended path for individual profile and family holders. Follow these steps to create backup codes through the app:
- Open and unlock the app on your device, using your login credentials or passkey.
- Select your profile or collection at the top of the sidebar, then tap Manage Accounts.
- Choose the profile you want to protect, then select Sign-in & Recovery.
- Tap Set up recovery code and follow the onscreen instructions to complete the setup.
- When the codes are displayed, immediately save a copy — download them, print them, or save to your credential vault.
- Store your recovery code in a safe and accessible place so you can always regain access to your profile.
Important: Do not use your recovery code immediately after creating it. Wait at least one hour. If you attempt a recovery after a recently signed in session, the recovery attempt will be blocked and the code will be unusable — you may need to wait 24 hours before trying again. This is a built-in protection mechanism against unauthorized access recovery attempts.
Generating Backup Codes on the Web (Profile Recovery via Browser)
If you prefer to create backup codes through a web browser — for example via your Google Account or 1Password.com — the process is equally straightforward. The profile management portal gives you full control over your codes, including the ability to generate a new set, download, print, or delete them. For Google-style profile recovery, the steps are:
- Log in to your profile and navigate to Security & sign-in settings.
- Under How you sign in, click 2-step verification. You may be prompted to confirm your credentials.
- Scroll to the Backup codes section and click Continue.
- To add codes, click Get backup codes. To generate a fresh set and inactivate old ones, click Refresh.
- Click Download Codes to save the file to your computer, or click Print to print a physical copy.
- The downloaded file will be named:
Backup-codes-username.txt— for example, if your username is google123, search forBackup-codes-google123.txtif you need to locate it later.
When you generate a new set, the old set automatically becomes inactive — this is by design. The number of codes generated is typically ten codes per batch. For github style integrations, a similar refresh workflow applies. Do not share your backup codes with anyone. No legitimate service will ever ask for a code outside of the standard login flow.
How to Sign In with Backup Codes and Manage Profile Recovery
Knowing how to access your profile with backup codes when you're locked out is just as important as generating them. This section covers the credential-recovery process, how to replace or delete codes, and what to do if you think your codes were stolen or compromised. Multi-factor login relies on your ability to complete a second step — and backup codes exist precisely to make that possible even without your primary authentication device.
Profile Recovery: Logging In When You Can't Access Your Authentication Device
If you can't log in through your normal 2FA route — for example, after a phone loss or device loss — follow these steps to use a backup code as your second step:
- Open your browser and navigate to the login page for your profile (e.g., 1Password.com or your platform's login portal).
- Enter your username and credentials as usual.
- When prompted for a one-time code, look for the link that says Having trouble signing in? or Try another way.
- Select Use recovery code or click Enter one of your 8-digit backup codes (the exact label varies by platform).
- Enter one of your unused backup codes from your downloaded file or printed copy, then click Next.
- If an email check is required, enter the confirmation token sent to your email address, then click Next. If you don't receive it, click Send new token.
- Once confirmed, create a new strong login credential and download a copy of your Emergency Kit if prompted — this will include your new secret key for signing back in on all your devices.
Worked Example — Profile Lockout Scenario: Imagine you've lost your phone and can't receive codes by text. You navigate to your profile's login page, click Having trouble signing in?, and select Use recovery code. You retrieve your printed codes from the folder where you store critical papers, locate the first unused code, and enter it. Your credential check succeeds, you set a new strong login passphrase, and you download the emergency kit to complete recovery. You can now sign back in across all your registered devices. After completing recovery, generate a fresh new set of secure backup codes immediately — any single-use codes that were consumed are now inactive.
Tips: After using a backup code to log in, regenerate codes right away. As each code is used once, using your tenth code means you'll be prompted to download a new list before you can use backup codes again. Don't wait until you run out of codes — generate new ones proactively to maintain continuous backup access.
Managing Your Recovery Code: Replace, Delete, and Find Lost Codes
Good profile management means keeping your backup codes current and under your control. If you suspect compromised codes or simply want to refresh them, you have three management options available in both the app and on the web portal:
- Replace recovery code — Generates a new code and automatically invalidates the previous code. You must save a copy of your new recovery code immediately after replacement, since the old one is no longer usable. This is essential if codes were stolen or if you've used several codes and want a refresh. Use this option as part of your access control routine after any suspected compromise.
- Delete recovery code — Clicking Delete will remove and automatically inactivate all your existing backup codes. Use this option if you're certain you no longer need this access, or if you're transitioning to a different login method such as security keys or a passkey. Be aware: if you delete your recovery code, you won't be able to recover your profile should you lose your login details.
- Find your lost backup code — If you can't locate your codes, search your computer for the filename
Backup-codes-username.txt(substituting your actual username). If you haven't downloaded backup codes to your computer, check your credential vault, your printed copies filed with key documents, or any encrypted file storage you set up at the time of generation.
Worked Example — Code Refresh After Multiple Uses: A user has worked through eight of their ten codes over several months of profile lockouts. Rather than waiting until the tenth code is used, they navigate to Manage Account → Sign-in & Recovery, click the ellipsis next to their existing code set, and choose Replace recovery code. A fresh batch is generated via the client-side backup codes generator, the old set is inactivated, and the user saves the new Backup-codes-google123.txt file to their credential vault. The previous code list is now invalid — deactivation is immediate and automatic.
For platforms like 1Password that support family profiles: if your family organizer initiates a recovery for your profile, your existing recovery code will be deactivated. After completing that recovery, you can generate new access codes immediately. If you upgrade your individual profile to a team or business tier, your recovery code will also be deactivated as part of the upgrade process — generate a new one once the transition is complete. Note that codes for team and business profile types may require administrator assistance rather than self-service recovery.
One important protection mechanism to be aware of: if you've recently logged in to your profile and then immediately attempt a recovery, the attempt will be automatically aborted. Similarly, if you've entered your credential check token incorrectly too many times, or if you've started a recovery and then logged in mid-process, the system will block the aborted recovery and require you to wait 24 hours. This prevents brute force attacks and unauthorized access attempts — a critical layer of cybersecurity that protects even your backup access pathway.
Best Practices for Storing and Downloading Secure Backup Codes
Your backup codes are one-time use codes that represent your last resort for profile access when all other login methods fail. Treat recovery codes with the same level of care as your most sensitive credentials — ideally with even greater caution, since they bypass your normal sign-in safeguards entirely. This section outlines the safest storage methods, what to avoid, and how to maintain multi-device credential recovery readiness.
Safe Storage Methods for One-Time Codes and Offline Access
When you download backup codes or print your backup codes, you're creating an offline copy that lives outside any cloud system. That's both the strength and the vulnerability of this approach as an accessible option. Here are the recommended ways to store them safely:
- Print them and store the physical copy in a secure location — alongside key papers like your passport or in a locked drawer. This gives you offline access without any digital footprint. Print a copy only to a printer you trust and control.
- Save to a credential vault — A reputable credential manager with encryption provides safe, multi-device access to your codes. This is the most convenient option for most users, combining offline storage with easy retrieval.
- Save to an encrypted file on your local device or an encrypted external drive. Encryption ensures that even if someone gains physical access to your storage, they cannot read the codes without your decryption key.
- Store them in a physically accessible place you will remember — a fireproof safe, a home office filing cabinet, or a location you treat with the same seriousness as financial documents.
What to Avoid: Keeping Backup Codes Out of Vulnerable Channels
Because backup codes are printed or written down by necessity, they become vulnerable to theft and phishing if handled carelessly. The following storage methods put your profile safety at risk and should be avoided entirely:
- Never store backup codes in plain text files on an unsecured desktop or shared folder.
- Never save them to an unencrypted cloud note app (e.g., an unsecured note in a basic notes application) — these are a common target for credential theft.
- Never email your backup codes to yourself through unsecured email. Email is not designed as a safe option for sensitive credentials and is vulnerable to interception.
- Never share your backup codes with another person. No legitimate support team — including Google's — will ever ask for a backup code outside of the standard login prompt.
- Never store them somewhere that isn't both private and accessible — you need them to be in a safe place that you can reach when you're already locked out of your profile.
Tips: Treat your backup codes like a physical key to your digital profile. Store your backup codes somewhere safe — the same drawer where you keep your passport or financial records is an ideal location. If you think codes are compromised at any point, regenerate codes immediately: create a new set, which will delete and automatically inactivate the old ones. Remember that unused backup codes on a stolen list are just as dangerous as a stolen passphrase. For password recovery situations, having a printed copy stored securely can be the difference between regaining access and being permanently locked out.
The downloaded file will always follow the naming convention Backup-codes-username.txt — for example, Backup-codes-google123.txt for a user with the username google123. If you ever need to find your lost backup code and believe it was downloaded to your computer, search your computer for this filename pattern. If you printed or written down your codes and the paper is misplaced, check all secure physical storage locations before concluding the codes are lost.
Once you've exhausted your set of ten codes or suspect the set has been compromised, use the Get backup codes or Refresh option in your profile's Security & sign-in section to create backup codes immediately. Generating a new set and inactivating old ones is the fastest way to restore your profile's safety posture after a suspected breach. The old set automatically becomes inactive the moment you generate a fresh one — no additional steps needed to remove the previous version.
Finally, remember that backup codes represent one layer within a broader cybersecurity strategy. They complement — rather than replace — stronger login methods such as hardware security keys, passkeys, or authenticator apps. For most individual and family profile holders, combining a credential vault for code storage with printed copies filed alongside key documents — and using a reliable client-side backup codes generator for security backup purposes — gives you the best balance of protection, emergency access control, and data resilience across all your registered devices.
Frequently Asked Questions
- What format are these codes in?
- Each code is two 5-character alphanumeric groups separated by a hyphen (e.g. "a3f9k-7bq2m") -- the same general shape used by Google, GitHub, and most other services' account-recovery backup codes.
- Can I use these codes with my Google/GitHub/etc. account?
- No -- these are standalone, cryptographically random codes for you to store as your own recovery mechanism (e.g. alongside a self-hosted 2FA setup, a password manager, or any system that lets you register custom backup codes). They aren't linked to any specific service's account -- only that service's own "generate backup codes" feature produces codes it will actually accept.
- How should I store these codes?
- Somewhere separate from the device that normally provides your 2FA codes -- printed and kept in a safe place, saved in a password manager's secure notes, or written down and stored with other important documents. If they're stored on the same device as your authenticator app, losing that device loses both your primary and backup access at once.
- Does each code work more than once?
- That depends on the system you register them with -- most 2FA implementations treat backup codes as single-use, marking each one as spent after it's used, which is why this tool generates a full set of 10 by default rather than just one.
- Are the generated codes sent anywhere?
- No. They're generated entirely in your browser using the Web Crypto API's cryptographically secure random number generator -- nothing is transmitted to a server or stored once you navigate away, so make sure to save them somewhere before leaving this page.