How to back up your two-factor authentication codes
A password alone barely protects anything anymore — two-factor authentication is what actually keeps strangers out of your accounts. But it comes with a quiet cost: every code now lives on one phone. This guide covers why that phone is a single point of failure, how to export your authenticator codes as QR images, and how to keep that copy somewhere losing a device — or a life — can't reach.
The second lock on every door
Passwords stopped being enough a long time ago. They leak in breaches, get reused across sites, and can be guessed, phished, or bought. Two-factor authentication is the fix that actually works: even with your password in hand, an attacker still needs the six-digit code your phone regenerates every thirty seconds. If you care about an account, it should have that second lock.
But the second lock concentrates everything into one device. The secret keys behind those codes usually live only in the authenticator app on your phone. Lose the phone, break it, or die with it locked, and the codes are gone — and a wall built to keep attackers out works just as well against you and, later, against your family. Even someone holding your passwords can't get past it.
Where the usual backups fall short
No backup at all
Most people scan a QR code once at setup and never think about it again — which leaves every protected account one dropped phone away from being unreachable.
Falling back on SMS
Text-message codes are the weakest second factor, and they're tied to a phone number — one that can be hijacked while you're alive and is cancelled or recycled after you're gone.
Backup codes in a stray file
The one-time codes a service offers at setup end up screenshotted in a downloads folder or emailed to yourself — unencrypted, hard to find years later, and only good for that single account.
Trusting cloud sync
Some authenticator apps sync to the cloud, but recovery often hinges on the same phone number or another already-signed-in device — exactly the things you just lost.
How to export your codes
Find the export option
In Google Authenticator it's Settings, then Transfer accounts, then Export accounts. In 2FAS and Aegis, look under settings for backup or export. A few apps — Authy is the best-known — offer no export at all; there, the app's own multi-device sync is the closest substitute.
Generate the QR codes
The app renders one or more QR codes that encode the secret keys for every account you select. They're designed for moving to a new phone — which is exactly what makes them a complete backup.
Screenshot each code
Take a screenshot of every QR code the app shows, on that same phone. Together, those images are a full, restorable copy of your second factor.
Restoring is just a scan
Whenever the copy is needed — by you with a new phone, or by family holding what you left behind — installing any authenticator app and scanning the images brings every code back.
Treat the screenshots like live keys
Stay on your own device
Export and screenshot only on hardware you control — never on a work machine or someone else's phone. Anyone holding these images can generate your codes.
Move them immediately
The screenshots shouldn't sit in your camera roll for an afternoon. Put them where they're going the moment you take them.
Delete every trace
Remove the images from your photo library, then from Recently Deleted, and check any cloud photo sync that may have already picked them up.
Re-export when things change
Every account you add to your authenticator makes the old export stale. When you set up a new account, export again and replace the copy.
A place built to hold them
Where the screenshots end up matters as much as taking them. The copy needs to be encrypted, stored next to the passwords it pairs with — a code without its password opens nothing, and increasingly the reverse is true too — and able to reach the right person one day without being readable by anyone today.
That's what a PostMortem message box is for. Add the exported QR images as attachments alongside the account details and passwords they belong to. Everything is encrypted on your device — unreadable to everyone, including PostMortem — and released to your chosen recipients only if you stop responding to check-ins. And since the box is yours, the same copy is waiting for you the day you're setting up a replacement phone.
Your codes shouldn't die with your phone
Keep your two-factor exports in an encrypted message box — unreadable to anyone today, delivered to the people you choose when it matters.
Available on mobile