๐Ÿงฐ Handy ยท Updated October 8, 2026 ยท 7 min read

How to Store 2FA Backup Codes and Setup Keys Safely

backup codes stored safely ๐Ÿ”

To store 2FA backup codes safely, keep two copies in two different places: one offline, such as a printed sheet in a home safe or file folder, and one encrypted, such as a password manager entry or an encrypted file. Do the same with the setup key, the long string or QR code shown when you first turn on an authenticator, because it can rebuild your codes on a new phone. Then test the backup once, so you know it works before the day your phone falls in a lake. Disclosure: this guide includes affiliate links to NordPass. If you buy through them, GrabCast may earn a commission at no extra cost to you. Every step here also works with free tools. How we handle affiliate links.

๐Ÿ” Try 2FA Code Generator now โ€” freeOpen โ†’
2FA Code Generator with a saved ExampleMail setup key producing a live code and the next code in the browser
A saved ExampleMail setup key producing live codes, entirely in the browser.
๐Ÿ’ก Two-step verification is only as good as its recovery plan

Two-step verification stops most account takeovers, but it creates a new way to lose access: the device that makes the codes. Phones get lost, stolen, reset and replaced, and support teams at large services often cannot, or will not, bypass two-step checks quickly, precisely because attackers try to talk their way past them. The single-use backup codes and the original setup key are your own recovery path. People who lose accounts after a phone swap almost always skipped saving them, or saved them somewhere that disappeared with the phone.

What to save when you turn on 2FA

The setup screen shows several things for only a minute. Capture all of them.

Where 2FA backup codes should live, and where not

Good places keep the codes away from the phone and away from casual eyes:

Poor places: a screenshot in your camera roll, which syncs everywhere and is easy to leak; an unencrypted note titled 2FA; your email inbox, since email is often the account you are trying to recover; and only on the phone that generates the codes.

Test your backup before you need it

A backup you have never tried is a hope, not a plan. Here is a quick test that does not touch the account itself. Paste the saved setup key or otpauth link into a TOTP generator and compare the six-digit code with the one your phone shows at the same moment. If they match, the saved key is correct and complete.

GrabCast's 2FA Code Generator does this entirely in your browser: the key is never uploaded. If you prefer extra caution, load the page, disconnect from the internet, then paste the key. Close the tab afterwards. For backup codes, the only true test is signing in with one, so consider doing that on a low-stakes account and crossing the code off your list.

Keeping codes in a password manager: convenience versus separation

Many password managers can now generate two-step codes themselves, and they can autofill them. That is convenient and still blocks attackers who only have a leaked password. The trade-off is that the password and the second factor now sit in one vault, so the vault's own protection matters even more: a long master passphrase, and two-step verification on the manager itself using a separate device or security key.

A sensible split for most people: let the manager handle codes for everyday accounts, and keep your primary email, your bank and the password manager itself on a separate authenticator app or a hardware key, with paper backups at home.

Sponsored option ยท affiliate link

NordPass. NordPass Premium includes an authenticator that stores two-step codes next to the login and autofills them in the browser extension after biometric confirmation, and the vault can also hold passkeys. Premium also supports file attachments, which is one way to keep an encrypted copy of a backup-code sheet.

See NordPass Premium โ†’

Free options work as well: most authenticator apps now offer an encrypted backup or sync, and the paper method costs nothing.

Step-by-step

1234
1When you turn on 2FA, save the backup codes and the setup key or otpauth link before you close the setup screen.
2To test the saved key, open the 2FA Code Generator and paste it in; the tool shows which service and account it belongs to.
otpauth setup link pasted into the 2FA Code Generator and read as ExampleMail, demo@example.com, 6 digits, 30s, SHA-1
Paste the setup key or otpauth link you saved when you turned on 2FA.
3Compare the code on screen with your phone's authenticator at the same moment; if they match, your backup is correct.
Live six-digit 2FA code from the saved ExampleMail key with a countdown bar and the next code shown
If this code matches your phone's code right now, your backup copy is good.
4Print or copy the codes to paper for home, add an encrypted copy to your vault, then close the tab.

Common mistakes to avoid

โš ๏ธSaving backup codes only on the phone that generates the codes, so both vanish together.
โš ๏ธKeeping a screenshot of the QR code in a photo library that syncs to several devices.
โš ๏ธEmailing the codes to yourself, which ties the recovery of your email to your email.
โš ๏ธUsing backup codes over time without noting which are spent, then finding none left.

Pro tips

โœ“Generate a fresh set of backup codes after using several; most services invalidate the old ones.
โœ“Label every sheet with the service, username and date created.
โœ“Add a second authenticator device or a security key where the service allows more than one.
โœ“Put a yearly reminder in your calendar to check recovery email and phone numbers.

Frequently asked questions

Where is the safest place to store 2FA backup codes?

Two places at once: an offline paper copy at home and an encrypted digital copy, such as a password manager entry. Avoid screenshots, email and storing them only on the phone that generates your codes.

What is a 2FA setup key?

It is the shared secret behind your authenticator codes, shown as a QR code and usually as a line of letters and numbers. Any TOTP app with that key produces the same codes, which is why it works as a backup and why you must guard it.

Can I store 2FA codes in the same password manager as my passwords?

You can, and it is convenient. It still stops attackers with only a leaked password, but the vault becomes a single point of failure, so protect it with a strong master passphrase and a separate second factor. Many people keep email and banking on a separate authenticator.

What if I already lost my phone and have no backup?

Use the service's account recovery process, which may involve a recovery email, identity checks or a waiting period. It is slower but often works. Our guide on losing a 2FA device walks through the options.

Is it safe to paste my setup key into a website?

Only into a tool that runs locally. GrabCast's 2FA Code Generator computes codes in your browser and does not upload the key; you can even disconnect from the internet before pasting. Never paste keys into a site that sends them to a server.

๐Ÿ“Œ Bottom line

Save both backup codes and setup keys when you enable two-step verification, keep one copy on paper and one encrypted, and test the key once against your phone. Ten minutes now saves days of account recovery later.

Open 2FA Code Generator โ†’

Related guides

Browse more: all all guides ยท 2FA Code Generator