← Back to Blog
Account Security2026-10-01·Digital Footprint Health Team

X Two-Factor Backup Codes: Where to Keep Them and What to Do When They're Gone

two-factor authenticationbackup codesaccount securityX/Twitteraccount recovery

Plenty of people enable two-factor authentication. Far fewer save the backup codes. That gap is the most common single point of failure in account security: once your usual verification method stops working, the account is out of reach, and the list of reasons it stops working is longer than most people expect. A new phone, a reinstalled authenticator, a deactivated number, a dead device.

This piece covers the backup codes alone: what they solve, how to store them, how they get spent, and the order of operations when they are lost.

The problem backup codes solve

Normal two-factor authentication depends on something you carry: a rotating code in an authenticator app, or an SMS message. That design assumes the device stays with you and stays functional. When the assumption fails, the normal path disappears.

Backup codes are the escape hatch for exactly that situation. They are a set of one-time codes, one per line, and any unused code completes verification. They need no network and no phone, only a copy you can reach.

Note the phrase one-time. Each code retires after use, which makes it a consumable credential that needs a periodic inventory check.

Where to put them

You generate them inside the account security settings, usually alongside the other verification methods. After generation you pick a storage method. Three approaches, ordered by reliability:

MethodStrengthRisk
A dedicated entry in a password managerEncrypted, synced across devices, hard to loseDepends on the master password; lose that and everything goes
Handwritten on paper, stored in one fixed placeNo electronics involvedFire, moving house, someone finding it
Encrypted file held locallyFull controlYou must manage the passphrase and the backups yourself

Any of the three works. What matters is picking one and actually doing it. The common anti-pattern is taking a screenshot and leaving it in the camera roll, where it disappears along with the phone. The password manager route assumes you already have that habit in place, covered in setting up a password manager.

Every use spends one

Signing in with a backup code consumes it. If you lean on them several times in a row, the stack shrinks faster than expected. Put a check of the remaining count into your periodic maintenance list, alongside the settings you review in enabling two-factor authentication.

Regenerate once you are below half. On most platforms regenerating invalidates the old set at the same time, so save the new codes immediately rather than leaving it for later.

When the codes are gone

Two cases, and they call for completely different sequences.

Case one: you can still sign in

This is the easy one. Open security settings, generate a fresh set, store them, and the old ones are void. The whole thing takes minutes.

One detail is easy to miss. If you came looking because of a story you heard from someone else, take the opportunity to review all verification methods at once: the phone number, the authenticator, and any hardware key. The check is cheap and the payoff arrives at the worst possible moment.

Case two: you are already locked out

Recovery at this point has nothing to do with backup codes. It runs through the registration email, the linked phone number, or a support appeal. This is also why a deactivated number hurts so much: it breaks two paths at once, verification and recovery.

If someone else took over the account, shift the order again. Recover the account first, then address the security settings. The steps are in recovering a hijacked account.

How the three methods relate

MethodDepends onTypical failure
SMS codesA phone number and carrier networkDeactivation, number change, SIM swap
Authenticator appAn app and a local secret on the deviceDevice swap without migration, hardware failure, app reset
Backup codesThe copy you storedMisplaced, never generated, exhausted

The failure modes do not overlap, which is the whole point. They also show that SMS is the weakest of the three. SIM swap attacks target it specifically, as covered in how a SIM swap locks an account.

A storage routine that holds up

  • Save within ten minutes of generating. Do not defer it.
  • Keep one copy in a password manager with a clear entry name.
  • Keep an offline paper copy for the case where the master password is also lost.
  • Add a remaining-count check to your quarterly maintenance list.
  • Confirm the old set is void after regenerating. Do not run two sets at once.

That last point trips people up. With two sets in hand, you can easily try codes from the wrong one, fail a few times, and conclude the whole thing is broken.

digital-footprint-health.shop folds account security settings into its public-exposure assessment. To see the overall picture for your account, start a free check from the homepage. Common account questions are collected on the FAQ page, and bulk cleanup plans sit on the pricing page.

Frequently Asked Questions

Where do I generate backup codes on X?

In the account security settings, alongside the other two-factor methods. Save them right away, since regenerating normally invalidates the previous set.

How many times can a backup code be used?

Each code works once and is void afterwards. A set contains several, and you regenerate when they run out. Check the remaining count periodically and regenerate below half.

Can I use backup codes and an authenticator app together?

Yes, and you should. Their failure modes differ, and the codes exist for the moment the authenticator is unavailable. Using one code voids only that code.

What if I have used every backup code?

If you can still sign in, generate a new set from security settings. If you cannot, recovery runs through the registration email, linked phone number or an appeal, not through backup codes.

Is it safe to store backup codes in a password manager?

It is the most reliable of the three options, provided the master password is strong and memorable. Keep an offline paper copy as well for the case where the master password is also lost.

Check your own X/Twitter footprint

Free on-device scan. Your archive never leaves your computer.

Start Free Check

Related Reads

Published on 2026-10-01. Last updated 2026-10-01.