Lost Your 2FA Device? Account Recovery

2fa
mfa
recovery
security

Lost Your 2FA Device? Account Recovery

Two-Factor Authentication (TOTP) enrollment is mandatory in StateWarden: every account configures an authenticator app at first login, before accessing the Dashboard. If you lose that device - a lost phone, a hardware failure, a deleted authenticator app - the six-digit codes are gone with it.

This article describes the two recovery paths: signing in with a Recovery Code (self-service), and an assisted MFA reset through Support.


1. Recovery Codes: The Self-Service Path

When you activated Two-Factor Authentication, StateWarden generated 10 single-use Recovery Codes (format XXXXX-XXXXX) and displayed them exactly once, with an instruction to save them immediately. Only cryptographic hashes of the codes are stored - they cannot be displayed again later.

Recovery Codes are the only self-service recovery mechanism. There is no "forgot your second factor?" reset link, by design. If you did not save your codes, proceed to Section 4.

2. Signing In with a Recovery Code

  1. Open the StateWarden login screen and sign in with your e-mail and password as usual.
  2. When the Security Check screen asks for your authenticator code, enter one of your Recovery Codes into the same input field instead of a six-digit TOTP code. The hint below the field ("Lost your device? Enter a Recovery Code above.") refers to this option.
  3. The system recognizes the Recovery Code format automatically and completes the sign-in.

Constraints:

  • Each Recovery Code is single-use. Once accepted, it is permanently invalidated.
  • Using a Recovery Code signs you in, but it does not pair a new authenticator device. The Dashboard does not offer self-service re-enrollment: after regaining access, contact your Realm administrator or open a Support ticket to have your MFA reset, so that the Setup 2FA screen appears at your next login and you can enroll the replacement device.
  • If you are running low on unused codes, generate a fresh set as described in Section 3.

3. Regenerating Recovery Codes

You can replace your Recovery Code set at any time while you still have access to your authenticator app:

  1. Go to Settings → Two-Factor Authentication.
  2. In the Emergency Access panel, click REGENERATE CODES.
  3. Confirm your identity by entering a current code from your authenticator app (a six-digit TOTP code - a Recovery Code is not accepted here).
  4. StateWarden generates and displays 10 new Recovery Codes. Save them immediately - they will not be shown again.

Regenerating invalidates the entire previous set, including any unused codes. Do this after you have consumed codes, or whenever you suspect a stored copy may have been exposed.

4. No Device and No Recovery Codes

If you have lost both the authenticator device and all Recovery Codes, self-service recovery is not possible. In this case:

  1. Open a Support ticket (see Contacting Support: Ticket System) and report a lost 2FA device.
  2. Be prepared for an identity-verification step (for example, a video call): Support performs an identity-verification procedure before any MFA reset, and all resets are recorded in the audit trail.
  3. After the reset, the Setup 2FA screen appears at your next login, allowing you to enroll a new authenticator device - and to generate a fresh set of Recovery Codes.

5. Prevention

  • Store Recovery Codes offline - a password manager entry, a printed copy in a secure location, or an encrypted backup. Any of these survives a lost phone.
  • Regenerate codes after use (Section 3). Ten codes deplete quickly if you rely on them; a fresh set keeps the safety net intact.
  • Keep your authenticator enrollment transferable. Where your authenticator app supports it, use its export or cloud-transfer feature so the TOTP enrollment can be moved to a replacement device without a reset.
  • Act early. If you still have the old device, migrate your authenticator before decommissioning it - recovery is a fallback, not a routine procedure.

StateWarden: Resilience Engineered.

Was this article helpful?