Skip to content

Sharing recovery codes safely without extra risk

P
PassTransfer
Published July 7, 20254 min read

What are recovery codes and why do they matter?

When you enable two-factor authentication (2FA) on an account, you typically receive a set of recovery codes. These are one-time backup codes that let you regain access to your account if your primary 2FA device is unavailable — if your phone is lost, stolen, or broken, or if you're locked out of your authenticator app.

Recovery codes are, in security terms, equivalent to having no 2FA at all. They bypass the second factor entirely. Anyone who possesses a recovery code can use it to access your account. This means they need to be stored and handled with at least as much care as the account password itself — arguably more.

The storage problem

The recommended practice is to store recovery codes offline — printed and kept in a secure physical location, or stored in a password manager. What many people actually do is save them in a notes app, a text file on their desktop, a cloud document, or (commonly) email them to themselves.

None of these are catastrophic, but they all involve the codes sitting in a relatively accessible digital location. If that location is compromised, the recovery codes can be used to bypass 2FA on all the accounts they belong to.

When recovery codes need to be shared

There are legitimate scenarios where recovery codes must be shared:

Shared organisational accounts If your team has a shared account for a service, multiple people may need the recovery codes as a backup. Not just one person — because if that person is unavailable in a crisis, the team is locked out.

Successor handover When someone responsible for a critical account leaves the organisation, they may need to transfer recovery codes to their successor. This must happen securely.

IT or support access In some organisations, IT teams hold recovery codes for critical accounts as a safety net. Those codes need to be transmitted to the IT team securely.

How to share recovery codes safely

The worst way to share recovery codes is to email or message them directly. They're long, alphanumeric strings that look technical rather than sensitive, which makes people careless with them. But they function as master keys.

The right approach is to treat them exactly like a password:

  1. Use a one-time encrypted link — paste the recovery codes into PassTransfer, generate a link, and send that to the recipient. They retrieve the codes once, the link expires, and nothing persists in either inbox.

  2. Send them as a set — if you have ten recovery codes, send them all in one link. This reduces the number of transfer events and keeps them together.

  3. Confirm receipt — follow up to ensure the recipient stored the codes properly (ideally in a password manager or secure offline storage).

  4. Invalidate and regenerate after sharing — if you've shared recovery codes with someone and the relationship ends, consider regenerating the codes (which invalidates all previous ones) and securely delivering fresh codes to current holders.

Recovery codes and 2FA hygiene

It's worth noting that recovery code management is part of broader 2FA hygiene. If you enable 2FA and then store the recovery codes in a less secure location than the account password, you've added friction without proportional security benefit. The security of a 2FA setup is only as strong as its weakest component.

Conclusion

Recovery codes are sensitive credentials that bypass your strongest authentication factor. Treat them accordingly. When they need to move from one person to another, use the same secure channel you'd use for any other high-value credential — a one-time encrypted link that leaves no trace after delivery.

Try PassTransfer for free →

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password