Storing recovery codes safely
When you enable two-factor authentication, Ziber Team gives you a set of 10 recovery codes. These codes are your emergency backup — they let you log in when you no longer have access to your authenticator app (for example if your phone breaks or gets lost).
This is important: recovery codes are shown only once, during setup. If you lose them and also lose access to your authenticator app, no one — not even Ziber support — can recover your account. Take a moment to store them properly.
What are recovery codes?
- You receive 10 codes of 10 digits each during 2FA setup.
- Each code can be used only once. Once you've used a code to log in, that code is spent.
- They're shown only once and can't be retrieved afterward.
- Read Logging in with a recovery code for how to use them when needed.
How do you store them safely?
Option 1: Save them in your password manager (recommended)
Using a password manager like 1Password, Bitwarden, or your browser's password manager? Save your recovery codes there. They'll be encrypted and easy to find when you need them.
Option 2: Print them out
Print the codes and keep the paper in a safe place — a locked drawer, a safe, or wherever you keep other important documents. This works well as an extra backup, even if you also store them digitally.
Option 3: Save them as a file in a secure location
Store the codes as a text file in a safe place, such as an encrypted USB drive or a secured cloud folder. Avoid a loose file on your desktop or in an unsecured folder.
What you'd better not do
- Don't skip storing them. You only see the codes once.
- Don't keep them only on your phone — if you lose the phone, you lose both your authenticator app and your codes.
- Don't take a screenshot. Screenshots often sit unsecured in your photo library or get automatically synced to the cloud.
- Don't share them with others. Recovery codes give full access to your account.
Almost out of codes?
Used a few already? Generate a new set before you run out. Read Regenerating recovery codes. Note: all previous codes become invalid when you do.