Get a free website with any plan

See how
ACCOUNT & SECURITY

Two-factor recovery codes

Last updated

IN SHORT

Two-factor recovery codes are 8 single-use backup codes Flashcloud generates when you turn on two-factor authentication. Each one signs you in once if you lose your phone or authenticator app. They're shown only once, right after enrollment, so save them immediately.

Recovery codes are your backup plan if you lose your phone or can't access your authenticator app. We generate 8 single-use codes when you turn on two-factor authentication, and each one can sign you in once.

Where to find them

We show your recovery codes once, on the screen right after you finish enrolling in two-factor authentication. After that, we can't show them to you again — they're hashed in our database, the same way passwords are.

If you didn't save them at enrollment time, that's fine — just regenerate a fresh set.

How to save them

Pick whichever fits your habits:

  • Password manager — paste them into 1Password, Bitwarden, the iCloud Keychain, etc. Most password managers have a dedicated "secure note" field.
  • Print them — old-school but reliable. Stick the printout in a drawer or your wallet.
  • Write them down — same idea. Just put them somewhere you'll remember.

What you don't want to do: leave them in plain text in your email, in a Slack message, or in cloud storage that doesn't require a separate sign-in. Recovery codes bypass two-factor — treat them like a backup of your password.

Using a recovery code to sign in

When the portal asks for your two-factor code, you can paste a recovery code in the same field instead. We accept it with or without dashes — abcd-efgh-ij and abcdefghij both work.

Each code works exactly once. After you use it, it's burned — you can't use the same code twice. That's by design: if a code is leaked, it can only ever be used once before it's worthless.

Regenerating codes

If you lose your saved codes, used too many of them, or just want a clean set, you can regenerate from Account → Security.

  • We'll ask you to confirm with a current code (TOTP from your authenticator, or one of your remaining recovery codes).
  • The old set is invalidated — even unused codes from the previous batch stop working.
  • A fresh set of 8 is shown to you. Save them.

Lost both authenticator and recovery codes

If you lose your phone and you didn't save your recovery codes, you can't sign in on your own. Open a ticket with our support team — we'll verify your identity through other means (invoice history, payment method last-4, account details) and reset two-factor for you.

This is the worst-case scenario, and it's why saving recovery codes is worth the 30 seconds when you enroll.

How they're stored

Recovery codes go through bcrypt hashing before they're written to our database, the same hash function used for passwords. Even with full database access, an attacker can't read your codes back — they can only verify when you submit one. We chose this on purpose: the codes are sensitive, and their plaintext shouldn't exist anywhere on our infrastructure once you've saved them.

Common questions

Where do I find my two-factor recovery codes?

We show them once, right after you finish enrolling in two-factor authentication. After that we can't display them again since they're hashed in our database like passwords, so save them at enrollment time or regenerate a fresh set from Account, Security.

What happens if I lose my recovery codes?

If you still have your authenticator app, regenerate a new set from Account, Security. If you've lost both your phone and your codes, open a support ticket and we'll verify your identity through invoice history, payment method last-4, or account details to reset two-factor for you.

Can I use a recovery code more than once?

No. Each code works exactly once, and it's burned right after you use it. That's intentional: a leaked code is only ever worth one sign-in before it's useless.

Do I need the dashes when I enter a recovery code?

No. We accept the code with or without dashes, so abcd-efgh-ij and abcdefghij both work in the two-factor field.

Is it safe to keep my recovery codes in an email or Slack message?

No. Recovery codes bypass two-factor entirely, so treat them like a backup password. Use a password manager's secure note, or print or write them down and keep them somewhere private instead.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.