← All guides

Recovery

Lost your authenticator? Use this recovery order

A calm, security-conscious sequence for regaining account access without handing credentials to fake support channels.

7 minute read Reviewed 25 July 2026

Do not rush into the first search result

Losing access to an authenticator creates urgency, and attackers exploit that urgency with fake support numbers, sponsored search results, and fraudulent recovery forms. Begin from the service's known app or a domain you have verified independently.

If the missing phone may have been stolen, use your platform's official lost-device controls to lock it. Change the password for the primary email or identity account if you believe the unlocked device exposed active sessions.

Recover in the least disruptive order

Check whether you are still signed in on another trusted device. Many services allow an authenticated session to add a new factor after confirming the password or another recovery method. Next, look for encrypted authenticator backups, a second enrolled security key, backup codes, or a recovery contact.

Avoid disabling two-factor authentication permanently just to regain convenience. Once access returns, enrol the replacement device, confirm that it works, generate a fresh set of recovery codes, and remove the missing device from the account.

  • Trusted existing session
  • Authenticator's encrypted backup or transfer
  • Second security key or alternate factor
  • Single-use backup code
  • Service's verified account-recovery process

If official support is the only option

Use the support path linked from the service's own domain. A legitimate support agent should not ask for your current password, a complete backup-code set, a 2FA setup secret, or remote control of your device.

Identity verification can take time because bypassing a second factor is intentionally difficult. Provide only information requested through the official workflow, keep a record of the case, and treat unsolicited messages about the request as suspicious.