Two-Factor Authentication (TOTP) enrollment is mandatory in StateWarden: every account configures an authenticator app at first login, before accessing the Dashboard. If you lose that device - a lost phone, a hardware failure, a deleted authenticator app - the six-digit codes are gone with it.
This article describes the two recovery paths: signing in with a Recovery Code (self-service), and an assisted MFA reset through Support.
1. Recovery Codes: The Self-Service Path
When you activated Two-Factor Authentication, StateWarden generated 10 single-use Recovery Codes (format XXXXX-XXXXX) and displayed them exactly once, with an instruction to save them immediately. Only cryptographic hashes of the codes are stored - they cannot be displayed again later.
Recovery Codes are the only self-service recovery mechanism. There is no "forgot your second factor?" reset link, by design. If you did not save your codes, proceed to Section 4.
2. Signing In with a Recovery Code
- Open the StateWarden login screen and sign in with your e-mail and password as usual.
- When the Security Check screen asks for your authenticator code, enter one of your Recovery Codes into the same input field instead of a six-digit TOTP code. The hint below the field ("Lost your device? Enter a Recovery Code above.") refers to this option.
- The system recognizes the Recovery Code format automatically and completes the sign-in.
Constraints:
- Each Recovery Code is single-use. Once accepted, it is permanently invalidated.
- Using a Recovery Code signs you in, but it does not pair a new authenticator device. The Dashboard does not offer self-service re-enrollment: after regaining access, contact your Realm administrator or open a Support ticket to have your MFA reset, so that the Setup 2FA screen appears at your next login and you can enroll the replacement device.
- If you are running low on unused codes, generate a fresh set as described in Section 3.
3. Regenerating Recovery Codes
You can replace your Recovery Code set at any time while you still have access to your authenticator app:
- Go to Settings → Two-Factor Authentication.
- In the Emergency Access panel, click REGENERATE CODES.
- Confirm your identity by entering a current code from your authenticator app (a six-digit TOTP code - a Recovery Code is not accepted here).
- StateWarden generates and displays 10 new Recovery Codes. Save them immediately - they will not be shown again.
Regenerating invalidates the entire previous set, including any unused codes. Do this after you have consumed codes, or whenever you suspect a stored copy may have been exposed.
4. No Device and No Recovery Codes
If you have lost both the authenticator device and all Recovery Codes, self-service recovery is not possible. In this case:
- Open a Support ticket (see Contacting Support: Ticket System) and report a lost 2FA device.
- Be prepared for an identity-verification step (for example, a video call): Support performs an identity-verification procedure before any MFA reset, and all resets are recorded in the audit trail.
- After the reset, the Setup 2FA screen appears at your next login, allowing you to enroll a new authenticator device - and to generate a fresh set of Recovery Codes.
5. Prevention
- Store Recovery Codes offline - a password manager entry, a printed copy in a secure location, or an encrypted backup. Any of these survives a lost phone.
- Regenerate codes after use (Section 3). Ten codes deplete quickly if you rely on them; a fresh set keeps the safety net intact.
- Keep your authenticator enrollment transferable. Where your authenticator app supports it, use its export or cloud-transfer feature so the TOTP enrollment can be moved to a replacement device without a reset.
- Act early. If you still have the old device, migrate your authenticator before decommissioning it - recovery is a fallback, not a routine procedure.
StateWarden: Resilience Engineered.