Skip to content
Security and sign-in6 min read

Backup codes

You get 8 single-use codes in the form XXXXX-XXXXX, shown once. They are your way in when the phone is gone.

Browse topics

What it is

Backup codes are single-use replacements for the six-digit code from your authenticator app. When your phone is lost, broken, wiped, or simply not with you, a backup code gets you in.

You get 8 of them. They are generated once, when you finish enabling two-factor authentication, and shown to you exactly once.

Each code looks like this:

A7K2M-9QX4P

Eleven characters: five, a hyphen, five, all uppercase letters and digits. Codes are not case-sensitive when you type them — the hyphen is part of the code, so include it.

When you would use it

  • Your phone is lost, stolen, or broken.
  • You wiped the phone and forgot to move the authenticator across.
  • You are travelling without your phone and need the dashboard.
  • Your authenticator app is on a device you cannot reach right now.

You do not use them for anything routine. They are the emergency route.

Where to find it

Open Dashboard → Settings → Security.

The only time you can see backup codes is at the moment they are generated: at the end of enabling two-factor authentication, or when you regenerate them.

Steps

Saving the first set:

  1. Finish enabling two-factor. The codes appear as the final step, with the instruction "Save these backup codes somewhere safe. Each can be used once if you lose access to your authenticator. They won't be shown again."
  2. Select Copy codes or Download codes.
  3. Store them somewhere you can reach without your phone. This is the whole test of a good hiding place.
  4. Tick "I've saved my backup codes somewhere safe."
  5. Select Done.

Using one to sign in:

  1. Sign in with your email and password as usual.
  2. When the Authentication code field appears, type a backup code instead of the six-digit app code. The field takes either — its placeholder says "6-digit code or backup code".
  3. You are in. That code is now spent. It will never work again.
  4. Cross it off your saved list, and note how many you have left.

Getting a fresh set:

  1. Go to Dashboard → Settings → Security.
  2. Select Regenerate backup codes.
  3. Enter your password and a current authenticator code.
  4. A new set of 8 appears. Save it the same way.
  5. Every code from the previous set stops working immediately, used or unused.

What you will see

The backup-code step is a list of eight codes with Copy codes and Download codes buttons and a confirmation checkbox. After you confirm, the codes are gone from the screen and cannot be recalled — there is no archive, no "show again", and no way for support to read them back to you, because Agentency does not keep readable copies.

Regenerating uses the same password-plus-code form as disabling two-factor.

Where to keep them

Good:

  • A password manager, stored as a secure note next to your Agentency entry. Best option for almost everyone.
  • Printed and kept somewhere physically safe — a locked drawer, a home safe.
  • Written down and stored somewhere separate from your laptop.

Bad:

  • A note app on the same phone that holds the authenticator. If you lose the phone you lose both, which defeats the entire purpose.
  • An unencrypted file called codes.txt on your desktop.
  • An email to yourself. Your mailbox is the thing an attacker goes for first.
  • A team chat channel. Backup codes are yours, not the workspace's.

The question to ask about any hiding place: if my phone falls in a river right now, can I still reach this? If the answer is no, pick somewhere else.

Running low

Nothing warns you when you are down to your last code. Eight is generous for real emergencies but is not infinite, and each use is permanent.

The healthy habit is: if you ever use one, plan to regenerate soon. Once you have your authenticator working again — new phone set up, app restored — go to Security, regenerate, and save the fresh set of eight. That costs you two minutes and resets you to full.

Regenerating is also the right move if you suspect the list has been seen by someone else, or if you cannot remember where you put it.

Limits and plan notes

  • You get 8 codes, in the format XXXXX-XXXXX.
  • Each code works once. There is no way to reuse or un-spend one.
  • Regenerating replaces the whole set. Unused codes from the old list die with it, so never keep two lists.
  • Codes are stored in a form Agentency cannot read back. Support genuinely cannot recover them for you.
  • If you skip the save and close the page, the only route to a new list is to regenerate — which requires your password and a current authenticator code. That means it only works while you still have your authenticator.
  • Backup codes work anywhere a code is asked for, including the confirmation dialog for deleting your account.
  • Backup codes belong to your login, not to a workspace. They cover every workspace you can open.

Common problems

I closed the tab before saving.

Regenerate from Settings → Security while you still have your authenticator. The first list is unrecoverable.

A backup code was rejected.

Either it has already been used, or you regenerated since it was issued, or you mistyped it. Include the hyphen, and check for a 0 read as an O or a 1 as an I. Try the next unused code.

I have tried several codes and now I am locked out.

Failed codes count toward the same lockout as failed passwords. Wait about 15 minutes and come back with a code you are confident is unused.

I lost my phone and my codes.

You cannot sign in yourself. Contact support with proof of account ownership — see Contact Support. Expect a real identity check; anything less would be a way in for an attacker.

Can I get more than eight?

No. Eight is the set size. Regenerate for a fresh eight when you are running low.

Do backup codes expire?

They do not expire on a clock. They stop working when they are used, or when you regenerate the set.

Should I share them with my co-founder?

No. They are your personal second factor. If a colleague needs access to the workspace, invite them properly — see Invite and manage members.

Common questions

How many codes do I get, and what do they look like?

Eight. Each is eleven characters in the form XXXXX-XXXXX — uppercase letters and digits with a hyphen in the middle. Include the hyphen when you type one.

Can I see the codes again later?

No. They are shown exactly once. Agentency does not keep readable copies, so support cannot recover them either — regenerating is the only route to a new list.

Where should I store them?

Anywhere you can reach without your phone: a password manager, or printed and locked away. Never in a note on the phone that holds the authenticator.

What happens to unused codes when I regenerate?

They stop working immediately. Regenerating replaces the whole set of eight, so never keep two lists side by side.

I lost my phone and my codes. What now?

You cannot sign in yourself. Contact support with proof of account ownership and expect a genuine identity check — anything less would be a way in for an attacker.

Was this article helpful?

Ready to try it on your own content?

Create a free workspace, add a document, and ask the questions your team is tired of answering.