2 min read
Overview
When you set up two-factor authentication you're given single-use recovery codes. They exist for one job: to let you back in if the device holding your authenticator is lost or replaced. Without them, a lost phone can mean a slower, identity-verified recovery. With them, you're back in seconds.
What to do
- Best: save them in your password manager, which is encrypted and separate from your phone.
- Also good: print them and keep them with your important company documents.
- Avoid: storing them only on the same phone as your authenticator, or in an unprotected note.
See recovery codes and account recovery.
Related reading

Recovery codes
Recovery codes are one-time backup codes generated when you set up two-factor authentication, used to sign in…
Read →
Setting up an authenticator app for two-factor authentication
Two-factor authentication adds a second step to sign-in: after your password you enter a six-digit code from…
Read →
Using a password manager for your business
A password manager generates and stores a unique, strong password for every site, so you only remember one…
Read →
Recovering access if you're locked out
Being locked out is almost always recoverable. Work through it in order: reset your password, use a recovery…
Read →Funding for UK limited companies
Credit Corp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.