B Binance · The world's largest crypto exchange — sign up and claim your benefits Sign up → AD
na.to.
📚 All keywords › 🧰 Free Web Tools › Setting up two-step verification and keeping recovery codes
KO EN JA
🔐

Setting up two-step verification and keeping recovery codes

Two-step verification protects an account even after a password leaks. How the methods differ, which accounts to start with, and how to store recovery codes so a lost phone does not lock you out.

📚 Free Web Tools · 12/12· ⏱ About 4min read ·Information updated 2026-10-01

📋 Key facts

Principle
Add something you have (phone, security key) to something you know (password)
Methods
Authenticator apps resist phishing better than texts; security keys and passkeys better still
Start with
Your email account, the reset route for every other account
Recovery codes
Keep them offline, somewhere other than your phone
Never
Approve a prompt you did not request or read a code out to anyone

Why a password alone is not enough

However long and complex a password is, once it is known it is useless as protection. It can leak from another site, be typed into a fake login page, or be captured by malware. Two-step verification adds a second requirement, something you have such as a phone or a security key, on top of something you know. Even if the password leaks, an attacker still struggles to log in without your device. Creating and managing passwords is covered in separate articles; this one focuses on choosing the second step, turning it on, and making sure you never lock yourself out.

How the methods differ

Not all two-step methods protect equally. When a service offers several, pick one further down this list.

  • Text message codes: easiest, but weak against number hijacking such as SIM swaps or porting, and against phishing
  • Authenticator app codes: usually change every 30 seconds and are generated on the phone, so safer than texts
  • Push approval: convenient, but attackers can send repeated prompts until someone taps approve by mistake
  • Security keys and passkeys: they check the address of the site, so they do not work on fake sites and resist phishing best

Which accounts to start with

Trying to change every account at once is exhausting. Turn it on one by one, starting where a break-in would hurt most. Email comes first: almost every service sends password reset links there, so losing email can mean losing everything else in turn. Next come banks, brokerage and payment accounts, then your phone maker's or cloud account, then the messaging and social accounts you use most. Even where only text codes are offered, turning them on is far better than leaving the account without. Look in settings for items named security, sign-in, or two-step verification.

Setting up an authenticator app

Authenticator setup usually follows these steps. The QR code and secret key shown during setup are themselves a key that can generate codes, so never screenshot them to send to someone or leave them in a shared folder.

  • Choose the authenticator app option in the account's security settings
  • Scan the QR code on screen with the authenticator app
  • Enter the numeric code the app shows to confirm the link
  • Save the recovery codes that appear next, straight away
  • Log out and back in to confirm it really works

Recovery codes: separate and offline

Recovery codes are the emergency key for getting into an account when the phone is lost or the authenticator app is wiped. Typically you receive several codes that each work once. The most common mistake is keeping them only as a photo or a note on the phone; lose the phone and you lose both the second step and the spare key at once. Print them or write them down and keep them somewhere safe at home, or store them in a password manager you can open without that phone. Mark each code as you use it, and if you have used most of them or suspect exposure, generate a new set so the old codes stop working.

When you change phones

Changing phones is the moment people most often get locked out. Before resetting the old phone, move the authenticator accounts to the new one. Some authenticator apps can export accounts or sync them; if yours cannot, you have to register the new phone with each service. So move them one at a time while you still have both phones, confirm you can log in with the new one, and only then wipe the old device. For accounts that use text codes, switch them to the new number before your phone number changes.

Do not be talked into approving or sharing

Two-step verification fails if you open the door yourself. A prompt you did not trigger means your password has already leaked, so deny it and change the password first. Do not approve just because the prompts keep coming. A call or message claiming to be your bank or a help desk and asking you to read out a code you just received is something legitimate services do not do. Some fake login pages capture both password and code and enter them on the real site instantly, so only type codes into the official app or an address you opened yourself.

A checklist so you never get locked out

Once setup is done, run through this list. Account recovery differs by service and can take days, so preparing before you are locked out is far easier.

  • Recovery codes are stored somewhere other than the phone
  • A backup method, such as a second security key or a spare phone number, is registered
  • The account's recovery email and phone number are ones you still use
  • You know how to move your authenticator app when changing phones

🌍 Search the web for this

Each button runs this keyword on that search engine

🔗 More in this category

🧰 Related tools