Find and use your account backup codes
Backup codes are credentials saved before an ordinary verification method becomes unavailable. They are not a universal password for all your accounts. Each service defines its own format, use, and replacement rules, so begin by matching the record to the account that is actually locked.
Use this guide only for your own recovery records. The general two-factor guide covers the larger decision tree when a phone or authenticator is missing. If you never generated a code, searching an app's settings while locked out may not let you create one retroactively.
1. Search the places where you saved recovery material
Google's backup-code article describes downloading or printing its codes, while Discord's MFA guidance identifies the saved Discord backup-code file. Check your password manager, secure documents, Downloads folder, and private printed records using normal access to your own devices.
Search by the service and account email, not just the word “code.” A folder may contain old sets, different family members' records, or codes for more than one account. Compare the label and creation context before entering anything at a sign-in screen.
Keep a found list private. Do not paste it into a chat to ask whether it is valid, and do not upload it to a recovery website. A photograph of a printed list can become another exposed copy if it automatically enters a shared photo library.
2. Use the code through the matching service
At the official sign-in, choose the alternative for a backup or recovery code when offered. Google's instructions explain using a backup code for its second verification step. That code is not a replacement password for an unrelated service using Google Authenticator.
Discord's instructions describe its own backup codes and the limits when they are lost. Match the account as well as the brand. Two Discord accounts do not share a code list simply because they used the same phone.
Enter an unused current code with the formatting the service expects. If it fails, check whether you already consumed it or generated a replacement set. Do not keep retrying every record without checking the account identity and the code's history.
3. Distinguish a recovery key from a list of one-time codes
Microsoft's account-recovery-code article describes a 25-digit account recovery code. This differs from Google's set of backup codes and from a BitLocker drive key. A record labeled only “Microsoft key” needs closer identification before you use it.
GitHub's recovery documentation explains its own recovery codes and alternate credentials. Follow the relevant service's process rather than treating the length or appearance of a code as proof of where it belongs. An authenticator setup secret, a device PIN, and a recovery code serve different purposes.
For Apple Account recovery material, use the Apple account guide and the official route it links. For disk encryption, use BitLocker recovery. Do not enter those secrets into a generic backup-code field or give them to a person who claims all recovery codes are interchangeable.
4. Generate replacements only from legitimate access
Google's backup-code guidance says a code becomes inactive after use, and generating a new set invalidates the old set. Microsoft's recovery-code instructions likewise explain replacing its account recovery code rather than retrieving an existing saved copy from nowhere.
If you can still sign in through another method, use the service's security settings to create current recovery material. Save it securely and mark obsolete copies so they do not confuse a later emergency. Test your normal and alternate access before discarding useful records.
If you cannot sign in at all, use the provider's remaining recovery process. Some services, including those documented by GitHub and Discord, cannot restore access when all required two-factor and recovery credentials are gone. A support request is not a guarantee that new codes can be issued.
A legitimate code belongs to a specific account and was created or delivered by that service. A person selling replacement backup codes cannot turn public knowledge of your username into authorized access.
After you regain access
Refresh compromised or exhausted recovery material through the account's security settings. Label it with the service, account identity, and date, then store it somewhere reachable without the same phone or vault it is meant to rescue. Keep the storage private and limit unnecessary copies.
Login.com's comparison of 2FA and two-step verification helps explain why these fallback methods differ from an ordinary password. Maintain a short inventory of which accounts have backup codes and where their records are kept, without putting the actual codes in a broadly shared checklist.
Instructions checked against vendor guidance on 24 September 2026.