Save your two-factor authentication (2FA) backup or recovery codes somewhere private that you can still reach if you lose your phone. Depending on the service, you may be able to download, print, or copy them into a secure password manager. The exact steps and rules differ by provider, so use the account’s own security settings and follow its guidance.
How to save your 2FA backup codes
- Open the account’s official security settings. Look for the two-factor authentication, 2-Step Verification, or recovery methods section. Choose the option to view, create, or generate backup or recovery codes.
- Save the codes promptly. Use an option the provider offers, such as downloading or printing them, or copying them into a secure password manager if supported.
- Keep the saved copy private and accessible without your usual second factor. Store a printout with important documents or keep a digital copy in a protected password manager. Consider whether you could reach it if your phone or primary device were lost.
- Replace the saved copy when you generate a new set. A replacement set may invalidate every code in the old set. Securely discard or delete the outdated copy.
These codes are a recovery route for when your usual second factor is unavailable, not a substitute for keeping your account credentials private. Do not share them with anyone. If you think a code has been exposed, use the provider’s security settings to invalidate or replace the set.
Where should you store backup codes?
Choose a place that is both protected from other people and usable if the device you normally use to sign in is unavailable. A secure password manager is one option when the provider supports it; a printed copy stored with important documents is another. Google Account Help says: “To store your backup codes somewhere safe, like where you keep your passport or other important documents, you can print a copy of them.”
There is no single storage method that fits every service. Check whether the provider gives specific instructions, and avoid relying only on a copy saved on the phone or computer that could be lost along with your normal authentication method.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Provider-specific steps and rules
Google Account
Google’s instructions for signing in with backup codes direct users to the account’s 2-Step Verification settings to create, download, or print codes. Google describes its own set as 10 codes, each 8 digits; those details apply to Google and should not be assumed for other services. A code that has been used becomes inactive, and creating a new set makes the previous set inactive. Google says not to share codes and that it will ask for one only at sign-in.
GitHub
GitHub’s recovery-method instructions offer options to download recovery codes, print a hard copy, or copy them into a password manager. GitHub recommends a secure password manager and says not to share or distribute the codes. A used code cannot be reused; generating a new set invalidates the previous set. GitHub also recommends setting up multiple authentication or recovery methods. Its separate two-factor authentication setup guidance covers enabling those methods.
Rank #2
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Microsoft account
Microsoft’s account recovery code guidance concerns a distinct 25-digit recovery code for regaining access if you forget your password or your account is compromised. Microsoft says to print it and keep it somewhere safe, and specifically warns not to store it on a device used to sign in. Creating a new one invalidates the previous code. This Microsoft feature is not interchangeable with another service’s 2FA backup codes.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Before you rely on a saved set
- Confirm the codes were saved completely and are readable.
- Keep them somewhere you can access without the phone, authenticator app, or device you might lose.
- After generating replacements, update every saved copy and securely remove the old set.
- Follow the provider’s current directions: names, options, and code behavior vary by service.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




