Treat backup codes as working credentials
A recovery code can provide access when the normal second factor is unavailable. It is not an ordinary account note. Anyone holding a usable code and the other required information may be able to sign in. The objective is to keep codes accessible to the authorised owner during an interruption while protecting them during normal use.
Use the provider's genuine security page to generate or inspect codes. Do not request them from an unsolicited support caller or send them to a person claiming to verify your account.
Choose storage for the failure you expect
- Identify what might be lost: the primary phone, a laptop, internet access or access to your password vault. Pick a storage method that does not depend entirely on that same failure point.
- If using an encrypted vault, verify you can unlock a recoverable copy without the missing device. If using paper, choose a physically secure location and keep it out of photographs, shared printers and visible desk drawers.
- Save the account name and date with the codes so you know which service they belong to. Avoid placing an unprotected password and all backup factors together in a shared document.
- Record the location in your private recovery map. Do not record the actual codes in a public inventory or send them by ordinary email just for convenience.
Run a controlled test
If the provider permits backup-code sign-in, use one code for a normal login on your own trusted device. Mark it used, since many services issue single-use codes. Confirm that your main authenticator still works. Do not repeatedly regenerate codes while other authorised users rely on the previous set.
Handle replacement carefully
Generating a new set commonly invalidates the earlier set, but check your provider's current behaviour. Replace stored copies consistently and dispose of old paper through an appropriate confidential-waste process. A blurred screenshot can still expose a code; avoid screenshots entirely when they are unnecessary.
Make the recovery route understandable
Review the storage after replacing equipment or changing account factors. Trusted emergency access should follow the account owner's wishes and the service's rules. Storing codes securely helps with availability; it does not replace a unique password, a protected device or awareness of fake account-recovery messages.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.