Two-factor authentication, often shortened to 2FA, requires a second piece of proof beyond your password — usually a code from an app on your phone, or a text message. This is one of the single most effective things you can do to protect an account from being broken into. The tradeoff most people don't think about is what happens if the phone that generates those codes is lost, broken, or simply inaccessible to whoever needs to get into the account.
When you set up 2FA on most services, you're given a set of one-time backup codes — usually 8 to 10 of them — meant to be used if you ever lose access to your normal authentication method. Each code works once. Without them, regaining access typically means going through a slower account recovery process, which can take days and isn't always guaranteed to succeed.
Why this matters more for inheritance than day-to-day use
Most people set up 2FA, save the backup codes somewhere at the time, and never think about them again — which is fine for personal use, since you'll rarely need them. But for someone helping manage your accounts after you're gone, the backup codes may be the only practical way into an account that has 2FA enabled, especially if your phone itself is locked or no longer accessible.
Where to store backup codes
Your password manager, if it supports secure notes
Many password managers let you attach a note to each saved login — this is a convenient place to store backup codes alongside the account they belong to, though it does mean they're protected by the same master password as everything else.
A physical, secure location
Printed or written backup codes stored in a fireproof safe add a layer of separation from your digital accounts — useful if you're specifically trying to avoid a single point of failure.
Alongside your broader digital inheritance documentation
If you're already documenting accounts for your family, noting which ones have 2FA enabled — and where the backup codes for each are stored — keeps everything in one referenceable place.
What to avoid
Don't rely on a screenshot alone. A screenshot on the same phone that provides 2FA becomes useless the moment that phone is the problem.
Don't let codes go stale without checking. If you've used several of your original codes over the years, it's worth confirming how many remain — running out at the wrong moment defeats the purpose.
Don't store codes only in an account that itself uses 2FA. This creates a circular problem — needing access to get the thing that grants access.
Free Tool
Track which accounts have 2FA and where the codes live
The Digital Assets Inheritance Planner gives you a place to note which accounts use two-factor authentication and where backup codes are stored, alongside the rest of your digital estate documentation.
Common questions
What if I lose my 2FA device and don't have backup codes?
Are backup codes the same as a password?
Can I regenerate 2FA backup codes if I use some of them?
Is it safe to store 2FA backup codes in a password manager?
This article is for general informational purposes only. Backup code formats, storage options, and account recovery processes vary by service and may change over time — check your specific provider's current security settings for exact details.