DocsAccount AccessTwo-Step Login

Get My Recovery Code

If you activate any two-step login methods, it's important to understand that losing access to your secondary device(s) (for example, a mobile device with an installed authenticator, a security key, or a linked email inbox) has the potential to lock you out of your Bitwarden vault.

To protect against this, Bitwarden generates a recovery code that can be used with your master password to deactivate any enabled two-step login methods from outside your vault.

tip

You should get your recovery code immediately after activating any two-step login method. Additionally, get a new recovery code every time you use it, as it will change with each use.

In addition to securing recovery codes, users may wish to create an export to backup vault data prior to activating two-factor authentication.

Get your recovery code

To get your recovery code:

  1. Log in to the Bitwarden web app.

  2. Select the SettingsSecurityTwo-step login from the navigation:

    Inloggen in twee stappen
    Inloggen in twee stappen

  3. Select the View recovery code button near the top of the screen. You will be prompted to enter your master password, which will open a recovery code panel:

    Sample Recovery Code
    Sample Recovery Code

Save your recovery code in the way that makes the most sense for you. Contrary to popular belief, printing your code and keeping it somewhere safe is one of the best ways to ensure that the code isn't vulnerable to theft or inadvertent deletion.

note

When does a recovery code change?

Neither deactivating and re-activating two-step login, nor changing your master password will change your recovery code. Your recovery code will only change when you use it. After you use a recovery code, immediately get a new one and save it in the way that makes the most sense for you.

Use your recovery code

To regain access to your account with its recovery code:

  1. Go to the recovery page for your account's server location:

  2. Enter your email address, master password, and recovery code.

  3. Select Submit.

Once your account details are successfully authenticated:

  • You are fully logged in to your vault.

  • All two-step login methods are deactivated.

  • The recovery code used to log in is no longer valid.

  • Your device is considered recognized for new device login protection.

Once used, get a new recovery code, as it changes after each use. You should also at this point re-activate any two-step login methods you want to use in the future.

note

Recovery codes will not deactivate Duo for organizations. If you are locked out of your vault by an organizational Duo prompt, reach out to the Duo administrator at your company for help bypassing the prompt.

If you're not sure whether the Duo prompt is setup personally or by your organization, try using the Use another two-step login method button.