Security

MFA Recovery Code Generator

Generate cryptographically random single use recovery codes for multi factor authentication, with the hashing scheme they should be stored under and a policy checklist.

Last reviewed by the Radiatus Cloud team

Codes appear here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

The account recovery path is the weakest link

Multi factor authentication is only as strong as the process for getting back in when the second factor is lost. If that process is a phone call to a support desk who verify a date of birth, the whole scheme reduces to social engineering. Single use recovery codes, generated at enrolment and stored by the user, close that gap: they are a second factor the user already holds, they need no support interaction, and each one works exactly once.

How the service must store them

Recovery codes are credentials with the same power as the second factor they replace, and a database of plaintext recovery codes is a database of authentication bypasses. They must be hashed before storage. Because they come from a cryptographically random generator with high entropy, they do not need a slow password hash: a single SHA-256 with a per user salt is sufficient and much faster to verify. Each code must be marked used on redemption and never accepted again, and using one should notify the account owner.

How the user should store them

The realistic threat is losing them, not having them stolen. A printed copy kept somewhere physically secure survives a lost phone, a wiped laptop and a locked password manager. Storing them inside the same password manager that holds the password defeats the purpose if that vault is what you lose access to. Generating a fresh set and invalidating the old one after any suspected exposure is the standard rotation, and using a code should prompt the user to regenerate the remainder.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

How many recovery codes should be issued?

Between eight and ten is the common practice at major providers. Enough that losing a few does not matter, few enough that they can realistically be stored on one printed sheet.

Should recovery codes be hashed?

Yes. They authenticate exactly as the second factor does, so plaintext storage means a database compromise yields working authentication bypasses. Because the codes are high entropy random values, a single SHA-256 with a per user salt is adequate; a slow password hash is unnecessary.

Where should a user store them?

Printed and kept somewhere physically secure, or in a separate password manager from the one holding the account password. Storing them alongside the password means losing access to that vault loses both factors at once.

What happens when a code is used?

It must be marked used and never accepted again. The service should notify the account owner, because an unexpected recovery code login is a strong indicator of compromise, and prompt the user to regenerate the remaining set.

Are these codes generated securely?

They come from the browser crypto.getRandomValues API, which is a cryptographically secure source, and nothing is transmitted. For production use, generate them server side at enrolment: codes that pass through a browser tab have been exposed to the browser environment.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose a code format and count, then generate a set of recovery codes with storage instructions.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.