RAZIBINTERNET INDEX Suggest a resource

Account security

How to Store Recovery Codes Without Creating a New Risk

Build a recovery-code backup you can find when your phone is lost, without leaving sensitive account access in shared folders.

A recovery code is useful only if you can reach it when your normal sign-in method stops working. Saving every code on the phone that generates your login codes creates an obvious problem when that phone goes missing. Leaving a readable copy in a shared folder creates a different one.

You need two things: protection from people who should not see the codes, and a realistic way for you to retrieve them. The right balance depends on your devices and living arrangements. A protected printout can be more useful than an elaborate encrypted backup whose password exists only inside the locked account.

Know what kind of recovery material you have

Providers use similar names for different things. A one-use backup code may replace a second authentication step. A recovery key might be a longer credential used in a separate account-recovery process. An authenticator setup secret can generate future codes and deserves particularly careful handling.

Do not assume all three are interchangeable. Record the provider's label and the help-page location alongside your private inventory. Keep actual secrets out of an ordinary spreadsheet used to track which accounts you have reviewed.

Google's backup-code documentation, for example, says each code becomes inactive after use and generating a new set invalidates the old set. GitHub's recovery guide describes its own recovery methods. Read the instructions for the service you are protecting instead of applying one provider's rules everywhere.

Avoid a circular recovery plan

Draw the dependency in plain words. “My email codes are in my password manager. My password-manager recovery code is in an encrypted file. The file's password is only in my email.” That arrangement returns you to the same locked door.

You do not need a complicated diagram. Ask what you would do using a replacement phone and a computer you trust, with none of your existing sessions available. Identify the first credential or protected document you would need.

Keep that starting point somewhere independent. For some people this is a sealed printout in a secure physical location. For others it is an encrypted removable drive plus a separately protected way to unlock it. The important detail is independence, not the number of copies.

Our password-manager setup guide uses the same principle: recovery for the vault cannot depend entirely on opening that vault.

Use a small, clearly labelled recovery packet

A paper copy does not need to include a full personal biography. Include the service name, the relevant account identifier, the date the set was created and any essential instructions. Avoid printing unrelated passport details, home addresses or financial information on the same page.

Use your own printer when possible. A shared office or shop printer may keep a queue or leave pages in an output tray you do not control. When using a printer outside your control is unavoidable, consider whether a different recovery method would be more appropriate.

Store the packet away from casual access and away from the device it is intended to recover. “Safe place” should mean somewhere you can identify, not a random drawer you hope to remember. Choose storage suited to the people who can enter your home.

If using a provider's prepared document, follow its instructions. 1Password's Emergency Kit is one example of a structured recovery document, not a universal format for other services.

Protect digital copies deliberately

An encrypted vault note can be a sensible place for another account's backup codes. Check whether you can still unlock that vault if your phone is missing. For highly important accounts, you may want a separate protected fallback rather than making one app the only dependency.

Do not assume that a file is encrypted just because it is stored in a cloud drive. Cloud transport, provider-side storage protection and an independently encrypted file are different arrangements. Read the product's description of what is protected and who can recover access.

Avoid naming a readable file “all-passwords-and-backup-codes” and leaving it in Downloads. More importantly, avoid leaving the readable contents there at all. Temporary downloads can also be copied into synchronization folders, backup sets or recent-file lists.

If you use an encrypted export, test that you know the software and password needed to open it. See encrypted backups and recovery for a practical restore check.

Test one route before you need it

Keep an existing trusted session open. Start a fresh sign-in to the real service and choose its documented backup method. Do not use a link from a message that claims your codes need verification.

After a successful test, mark a one-use code as consumed or replace the set according to the provider's instructions. Do not keep a tested code at the top of the page without noting its status. During an actual lockout, that creates avoidable confusion.

Record that the route worked and the date of the test in your non-secret inventory. You do not need to repeatedly exercise recovery just for reassurance. Recheck when the account changes, the device changes or the stored material is replaced.

Replace exposed or obsolete copies

If someone who should not have access may have seen a code set, generate replacements using the account's official security page. Merely deleting your local screenshot does not invalidate a copy someone else has already made.

After replacement, update every legitimate stored copy. Mark old printouts as obsolete and destroy them appropriately. Remove stale digital copies you control, while recognizing that historical backups may remain. The account-side invalidation is the important security action.

Do the same after using codes during a real recovery incident. Also review active account sessions and sign-in methods, because new recovery material does not automatically end someone else's existing access.

Keep sharing narrow and intentional

You do not need to give a family member all your recovery codes to prepare for emergencies. Some services offer recovery contacts, shared administrative roles or other limited arrangements. Start with those and agree what help is actually wanted.

A recovery packet can contain instructions to find the authorized route rather than unrestricted credentials. Family account recovery planning separates routine household access from access to private personal accounts.

At your next device change, check three things: the packet is still where you expect, the codes belong to the current account setup and the first recovery step does not depend on the lost device. That is a stronger plan than accumulating more screenshots.

Sources and further reading

  1. Google: Backup codes and replacement sets Consulted 28 September 2026.
  2. GitHub: Configure two-factor recovery methods Consulted 28 September 2026.
  3. 1Password: Emergency Kit storage Consulted 28 September 2026.

Consult the linked documentation for current details. Settings, availability and interface labels may change.

Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.