August 8, 2026
How to back up your authenticator app safely
Authenticator codes are generated from secret keys stored on your device. That's what makes them secure — but it also means that if the device is lost, stolen, or wiped without a backup, those accounts go with it. A little planning prevents a lot of lockouts.
The safe ways to back up
- Save every service's backup codes. This is the simplest, most universal safety net. When you enable 2FA, each service hands you backup codes — store them in a password manager or printed somewhere safe.
- Add each account to a second device. During setup, you can scan the same QR code on a second phone or tablet. Now either device produces valid codes. Keep the spare somewhere secure.
- Use your app's encrypted export/sync, if it offers one. Some authenticators can back up or sync your accounts. If yours does, protect that backup with a strong password — it contains your secret keys.
The risky ways to avoid
- A screenshot of the QR code in your camera roll. Anyone who gets into your photos gets your 2FA. See common setup mistakes.
- A plain note or chat message holding your setup keys.
- Only one device, no backup codes. That's the setup that ends in a lost-phone lockout.
The minimum everyone should do
At the very least: save your backup codes the moment you turn on 2FA, somewhere separate from your phone. Everything else is a bonus.