← All guides

Setup safety

2FA secret key: find and protect it

Find a 2FA secret key during account setup, copy it without errors, and protect it like a password so no one else can generate your codes during sign-in.

5 minute read Reviewed 3 August 2026

The secret key is not the six-digit code

A 2FA secret key is the private setup value behind an authenticator entry. It is often encoded as Base32 text and embedded in the QR code shown while you enrol an authenticator app. The short code changes regularly; the secret key can generate all of those future codes.

Treat the secret like a password and a backup key combined. A person who obtains it may be able to create valid codes until the account's 2FA setup is reset, even if they never see your phone.

Copy it accurately during setup

The safest route is usually to scan the QR code directly with a trusted authenticator. If you must use the manual key, copy it from the service's authenticated setup screen and preserve any accompanying algorithm, digit, and period settings.

Avoid typing a secret from a photograph or forwarding it between devices in a chat. A single missing character or an incorrect setting can produce codes that look normal but do not match the service.

  • Use only the service's verified security settings to obtain a replacement key.
  • Do not reuse a secret from one account for another account.
  • After setup, close or delete any temporary local copy you created solely to transfer it.

Use recovery methods instead of re-sharing a secret

If you lose access to an authenticator, do not ask someone to send you an old setup QR code or secret key. Start with a trusted signed-in device, an encrypted backup, a second security factor, or the service's recovery flow.

Once access is restored, enrol a replacement authenticator, confirm it works, and generate fresh backup codes. Replacing the secret through the service is safer than keeping uncontrolled copies indefinitely.