Backup Codes Generator
Make a set of one-time codes that get you back into an account when your phone is gone, ready to print or save as a file. They are drawn on your device and never leave your browser.
Backup codes are the way back into an account when the second factor is gone — the phone that held the authenticator, the key left in a drawer. Each one works once. Make a set, put it somewhere you can reach without the missing device, and forget about it until you need it.
Your backup codes
Strength: Strong, 46 bits per guess
Save them somewhere safe
A set of codes is only worth having if you can reach it without the device you have lost. Print it, or save the file somewhere that is not the phone holding your authenticator.
Customize
Each code is spent when it is used, so the set has to outlast the emergency. 10 is what most services issue. More codes also mean more values that open the account, which the strength figure accounts for.
The setting that decides how hard a code is to guess. It is also the one you pay for by hand, since somebody locked out has to type these — which is why the dashes below exist.
Characters used
abcdefghjkmnpqrstuvwxyz23456789
These 31. No 0, 1, l, i or o, because somebody reading a code off a printout should never have to guess which one they are looking at.
How hard one is to guess
Any of your 10 codes opens the account, so a guesser has 10 targets rather than one. That is the difference between the two numbers, and the second is the honest one.
Recent sets
Nothing here yet. Sets you generate are kept on this device only, so you can pick one up again if you close the tab before saving it.
Why these are worth getting right
A backup code is a full replacement for your second factor. Whoever has one and your password is in, exactly as if they had your phone — so a set of codes deserves the same care as the password itself, not the care you would give a note about where you parked.
These are guessed differently from a password, though, and the numbers reflect it. A code goes into a login form, where the server counts attempts, slows them down and locks the account. There is no offline stage: the server keeps a hash and nobody gets a signature to test against. That is why 46 bits is comfortable here, when the same figure would be far too low for a signing key. The floor is around 20 bits, which is what NIST asks of a rate-limited recovery secret.
Where you keep them is the part that actually goes wrong. A set stored on the same phone as the authenticator is gone with the phone; a set screenshotted into a photo library is in whatever backs that library up. Printed and in a drawer works. A password manager on another device works. An email to yourself does not — that is the account most likely to be the one you are locked out of.
Each code is spent when it is used, and a set is replaced as a set: the moment you generate new ones, register the whole list with the service and destroy the old copy. A stray old page is a live key to the account, and it does not stop being one just because it has been superseded here.
Nothing generated here is registered with anyone. These codes only mean something once a service accepts them, so making another set costs nothing at all before that point.
Everything happens on your device. Your backup codes never leave this browser.