Updated on 10 December, 2025 by Joel Barbara
What are the 2FA backup codes?
2FA, short for two-factor authentication, drastically improves login security. The idea behind it is simple: anyone logging in must provide a secondary authentication method to prove they are who they say they are. In doing so, even if credentials get misplaced (or stolen), the user account and the WordPress website remain safe from bad actors.
Two-factor authentication has become a de facto login security method. However, many administrators may be hesitant to deploy it on their WordPress website. One common, if unwarranted, fear is that of user lockouts. Many fear the unavailability of the 2FA method, such as a phone running out of battery, can leave users unable to access their accounts. Although itโs uncommon, it can (and does) happen. This is where 2FA backup codes come in.
If you’re still sitting on the fence about adding 2FA to your WordPress websites, or you’re looking for more information on 2FA backup codes, then this article is for you.
Table of contents
What are backup codes?
As the name suggests, backup codes are used as a backup 2FA authentication method whenever the primary method is unavailable. They work as a stand-in replacement for the primary 2FA method and are completely independent of it. This means that if the user or customer loses access to their phone completely, they will still be able to log in.
All backup codes are pre-configured, which means users need to generate backup codes in advance. As they are not tied to any particular device, any user can use backup codes anywhere.
Since backup codes are a type of OTP (One-Time Passcode), each backup code can only be used once. This reduces the risk of valid backup codes falling into the wrong hands.
It’s important to note that backup codes are not recovery codes; they cannot be used to recover a lost key. Their only purpose is to act as a temporary access code in the case of an emergency.
When to use backup codes
Backup codes can be used whenever the primary 2FA method is unavailable. Whether you got a new phone, your phone ran out of battery, or you simply lost access, backup codes ensure you can still access your WordPress account.
How to use a backup code
As mentioned previously, backup codes need to be generated beforehand. The process is easy when using WP 2FA – Melapress’ very own WordPress 2FA plugin. The plugin provides users with ten new, 16-digit long backup codes at a time, ensuring users have sufficient options to access their account.
To use a backup code, first provide your WordPress username and password, following the normal procedure. At the point where you need to enter your Authentication Code, click on Or, use a backup code instead.

How to give WordPress users access to 2FA backup codes
WP 2FA offers backup codes as a secondary 2FA authentication method.
During the initial configuration wizard
When setting up 2FA for the first time, the initial configuration wizard will ask you whether you would like to set up an alternative 2FA method for your users. This option is available in both free and premium editions. The premium edition, however, also includes e-mail one-time codes as an alternative to backup codes.

To allow users to configure backup codes, simply make sure that Backup codes are enabled, as shown in the screenshot above during the WP 2FA configuration wizard process.
From the 2FA policies page
If you have already set up 2FA for your users but did not provide access to backup codes, you can do so any time from the 2FA policies page.
First, navigate to WP 2FA > 2FA Policies. Next, scroll down to the Secondary 2FA methods section and tick the Backup codes checkbox.

Once ready, scroll down to the bottom of the page and click on Save Changes.
How to configure backup codes
Provided that your WordPress administrator has made backup codes available to you, 2FA backup codes can be configured during the initial 2FA configuration process or at any point after that. In this section, we will be covering both methods
During 2FA configuration
If you’re in the process of setting up 2FA, you can configure backup codes as part of the 2FA configuration process.
Once you’ve configured the primary method, you’ll be asked whether you want to set up backup codes.

Tick the Login with a backup code option and then click on CONFIGURE BACKUP 2FA METHOD. The plugin will then automatically generate backup codes for you.

Once generated, you have a few options to save the codes:
- Copy and paste the codes to a safe and secure location, like an encrypted drive
- Download the codes as a text file to your computer by clicking the DOWNLOAD button
- Print the codes by clicking the PRINT button
- Receive the codes in your inbox by clicking this SEND ME THE CODES VIA EMAIL button
Confirm you have a copy of the codes and click the I’M READY, CLOSE THE WIZARD button to finish the process.
Geek note: Backup codes should be saved in a secure location such as an encrypted drive. Many password managers also offer secure vaults where you can store sensitive data. It is advisable to delete any copy of the backup codes stored in an unsecured location.
Post 2FA configuration
If you have already configured WordPress 2FA but didn’t configure backup codes, you can still do so from your WordPress account.
Once you have logged in to your WordPress account, navigate to your WordPress account page by clicking on your username in the top-right corner of the page. Next, scroll down until you reach the 2FA configuration section.

Next, click on Generate list of backup codes, and the WP 2FA plugin will automatically generate them for you.
Generating additional backup codes
WP 2FA generates ten backup codes at a time. Using WP 2FA, you can generate a new set of backup codes at any point – ensuring you never run out of codes. Generating new backup codes does not affect your existing backup codes – any unused codes remain valid. As such, you can ensure you never run out of valid codes to use in an emergency.
To generate new codes:
- Navigate to your WordPress user profile page by clicking on your username in the top-right corner of the page
- Scroll down until you reach the 2FA configuration
- Click on Generate list of backup codes
Here you can also see how many unused backup codes you still have a handy feature for ensuring you never lose access to your WordPress account.
Backup codes – a friend in need is a friend indeed
Two-factor authentication is a great and easy way to boost the security of your WordPress website. With backup codes, you can ensure users will still be able to log in should their primary method become unavailable, whether they’re using an authenticator app, email, or any of the other available methods.
Since backup codes work independently of the primary 2FA method, they are as reliable as can be. Setting them up takes but a few minutes of your time and will help you put your mind at rest so that users can still log in without needing helpdesk support.

Add two-factor authentication and increase security with multiple methods to choose from.
Frequently Asked Questions
What is 2FA?
2FA is a secure method for logging in websites, apps, and services including WordPress. It uses a secondary authentication factor besides the regular username and password. Options include OTP from an authenticator app such as Google Authenticator or email, push notifications, and authentication keys, among others.
How do I get my 2FA backup code?
Getting your 2FA backup codes is easy. If you already have two-factor authentication set up, simply go to your WordPress profile page, scroll down to the 2FA configuration section, and click on Generate list of backup codes.
On the other hand, if you’re setting up two-factor authentication for the first time, the configuration wizard will ask you whether you want to set up the codes right after you finish configuring your primary method.
How do I keep my backup codes secure?
You should always store your 2FA backup codes in a safe place, such as an encrypted hard drive or a secure vault, such as those offered by many password managers. Do not leave a copy of your codes in your email and if you print your backup codes, make sure you destroy the paper once you have copied them to a safe location.
