Recovery codes are emergency credentials. Anyone holding one may be able to bypass your normal multi-factor authentication, so treat each code like a password.

Keep codes away from the account password

Do not store a password and its recovery codes in the same unprotected note. A compromise of that one location would remove both layers of protection.

A reputable password manager can store encrypted notes, but protect the manager itself with a strong, unique password and a separate authentication method. For especially important accounts, an offline paper copy in a physically secure location can provide another recovery route.

Label without oversharing

Record which service issued the codes and when you generated them. Avoid adding unnecessary account details to a paper copy. If several people share responsibility for a business account, document who is authorised to access the recovery material.

Replace codes after use or exposure

Most services let you regenerate a complete set. Generate new codes after using one if the provider recommends it, and always regenerate them if a copy may have been viewed by someone else. Destroy superseded paper copies and delete old digital copies.

Test the recovery plan safely

Check that you know where the codes are and that authorised people can reach them during an emergency. Do not test by deliberately locking yourself out. Instead, review the provider's recovery instructions and confirm your normal multi-factor methods are current.

Never send a recovery code to support staff, advisers, or someone contacting you unexpectedly. Official support may help you navigate a recovery process, but it should not ask you to disclose a code that grants account access.