When you turn on two-factor authentication, most services hand you a short list of codes and tell you to “store them somewhere safe”. Most people then do one of three things: screenshot them, paste them into a notes app, or ignore them.

Every one of those fails for the same reason, and once you see it the right answer is obvious.

Ask what the codes are for

Recovery codes (also called backup codes) are a spare key. Each one works once, in place of your authenticator app or security key. You will use them on exactly one kind of day:

the day your phone — and the authenticator on it — is gone. Lost in a taxi, dropped in the sea, stolen, wiped, or simply replaced without moving the authenticator across.

So the only question that matters about any hiding place is: does it still work on that day?

The day you need themyour phone — and its authenticator — is goneso ask of every hiding place: does it survive that day?Fails on exactly that dayNotes app on the same phonelost with itThe inbox of the account they recoverthat is the account you are locked out ofA vault you can only unlock with that phonethe key to the codes is the thing you lostA screenshot in the camera rollsyncs to the cloud; phones read text in imagesSurvives itPrinted, kept with your important papersboring, offline, and does not needany device to readEncrypted on a different device —or split across several placesopened by something you still haveRule: store them somewhere thatsurvives the loss they exist to fix.
The test every hiding place has to pass. Most of the obvious ones fail it on the one day that counts.

The places that fail on that day

The notes app on the same phone. It goes where the phone goes.

The email account the codes are for. If these are your email account’s recovery codes, the inbox is precisely what you are locked out of. People do this surprisingly often: they email the codes to themselves.

A password manager you can only open with that phone. Putting codes in a password manager is fine in general — but check the chain. If unlocking the manager needs the authenticator on the phone you lost, you have locked the spare key inside the house it opens. And never keep a password manager’s own recovery or emergency kit inside that same vault.

A screenshot in the camera roll. It is on the device you are protecting against losing, it usually syncs to a cloud photo library, and phones now recognise and index the text inside images. It is the least-bad of the bad options, and still bad.

The places that work

Printed, with your important papers. Unfashionable and excellent. It needs no device, no battery and no password to read, and a burglar looking for valuables does not read your filing. Keep it with your passport or your deeds.

A password manager — for other services’ codes. Your bank’s or your cloud storage’s codes sit perfectly well in a password manager, as long as the manager itself can be opened without the phone you might lose (a strong master password you know, plus a second factor that is not only on that phone).

Encrypted, on a different device — or split. An encrypted copy on a laptop, a tablet or a family member’s device survives the loss of your phone. For the most important accounts, splitting the codes across several places means no single loss, and no single discovery, is enough.

Not all codes deserve the same care

Put your effort where the damage is. Three accounts can reset most of the others:

  1. Your primary email. Almost every other account’s “forgot password” link goes here.
  2. Your Apple or Google account. It usually holds your contacts, your photos, your device backups and often your saved passwords.
  3. Your password manager. It holds everything else.

Those three sets of codes deserve the paper copy and a second, separate copy. The code for a forum you visit twice a year can live in your password manager and nowhere else.

Better than codes, where you can get it

More services now let you register a second passkey or a second hardware security key. Where that is available it is the stronger backup: a second key in a drawer at home cannot be phished or read off a screen, and it works immediately. Treat recovery codes as the last resort behind it, not the only one.

Housekeeping that catches people out

  • Each code works once. Cross it off, or regenerate the list when you are running low.
  • Regenerating usually invalidates the old list. On most services the moment you generate new codes, every old copy is dead — so replace the printed copy and the digital one at the same time, or you will discover the mismatch on the worst possible day.
  • Moving to a new phone? Transfer the authenticator before you wipe the old one, and keep the codes to hand while you do it.

Where StegoSafe fits — and the mode to avoid

StegoSafe is built for exactly this kind of small, high-value secret: it encrypts the codes on your device with AES-256-GCM, keeps the original photo untouched, writes a separate protected PNG, and needs no account and no server.

But note the trap, because it is the same trap as the rest of this page. StegoSafe’s strongest mode binds a secret to this device and its Face ID or Touch ID. For recovery codes, that is the wrong choice if the device is the phone you are protecting against losing — you would be storing the spare key in the house it opens.

For recovery codes, use one of these instead:

  • portable password mode, and keep the protected PNG on a different device — your Mac, a family iPad, an external drive; or
  • split the codes across several photos kept in different places, so that any three of five — together with your passphrase — recover them, and one or two reveal nothing. The mechanics are in Five Photos, Any Three.

Keep the PNG as a file: messengers recompress images and destroy hidden data, as How to Hide Text in an Image explains. And for a crypto recovery phrase rather than account codes, the wider comparison is in Where to Store Your Seed Phrase Safely.

The short version

  1. Recovery codes are for the day your phone is gone — so store them somewhere that survives that day.
  2. Never in the notes app on that phone, the inbox they recover, or a vault that only that phone can open.
  3. Print the codes for your email, your Apple or Google account and your password manager, and keep a second copy somewhere separate.
  4. Add a second passkey or security key where you can, and treat codes as the last resort.
  5. Regenerate means replace every copy, the same day.

Frequently asked questions

What are 2FA recovery codes?
A short list of one-time codes a service gives you when you turn on two-factor authentication. Each works once, in place of your authenticator app or security key, so you can still sign in if that second factor is lost, broken or stolen. They are, in effect, a spare key to the account.
Where should I store my 2FA backup codes?
Somewhere that survives losing your phone, because that is the day you will need them. A printed copy kept with your important papers works well. So does an encrypted copy on a different device, or a password manager — provided you can still open that password manager without the phone you lost.
Is it safe to keep recovery codes in my password manager?
For most accounts, yes. The one exception is the password manager’s own recovery kit or emergency kit: keeping it inside the vault it unlocks is circular. Keep that one printed or somewhere entirely separate, and make sure opening the manager does not depend on the phone you are protecting against losing.
Should I take a screenshot of my recovery codes?
It is better than nothing and worse than almost anything else. A screenshot usually syncs to a cloud photo library, modern phones recognise and index the text in images, and it sits on the very device you are guarding against losing. If you do take one, move it off the phone and delete it from the camera roll and the recently-deleted album.
What if I have lost both my phone and my recovery codes?
Then you fall back to the service’s own account-recovery process, which is deliberately slow and asks you to prove who you are in other ways. Some services can recover an account this way after a waiting period; some cannot recover it at all. That is exactly why the codes are worth ten minutes today.

Keep reading

  • What Happens to Your Crypto When You Die?If nobody can reach your keys, nothing happens — it stays locked forever. How to let your family recover it without handing anyone the keys today.
  • How to Hide Text in an Image: Two Ways, and When Each One BreaksClassic steganography writes your encrypted text into the pixels — perfect offline, destroyed the moment a chat app recompresses the photo. A robust watermark survives WhatsApp but only carries a few bytes. Here is how both work, what each is good for, and how to choose.
  • How to Split a Seed Phrase into 3 Parts — SafelyCutting a recovery phrase into thirds feels safe and is not: lose one piece and the wallet is gone, and the popular 2-of-3 word-overlap trick leaves a 12-word phrase within reach of a brute-force attack. Here is the arithmetic, and the proper way to do it — Shamir's Secret Sharing, where a single share reveals nothing.

StegoSafe is a private recovery vault for seed phrases, recovery codes and private keys, encrypted inside ordinary photos. Protect them with Face ID or Touch ID, or split one secret across several photos so no single copy is enough. iPhone, iPad and Mac — one purchase, no account, no cloud.

Buy StegoSafe — $49.99