Ydenticator logo

How to back up 2FA secrets and recover your authenticator app

Switching phones, losing a device, or resetting your computer is the moment most people discover how fragile their authenticator setup is. This guide explains how to back up TOTP seeds safely, why recovery matters, and how Ydenticator's device-bound model makes backup both harder and more secure.

Why backing up 2FA secrets is a top pain point

Authenticator apps are designed to prove that a specific device is in your possession. When that device disappears, the proof disappears with it. Unlike a password you can reset by email, a TOTP seed is usually only stored on your phone. If the phone is gone, you are locked out of every account that did not have an alternative recovery path.

This is why searches like "authenticator app backup" and "recover authenticator app" are so common. The industry has trained users to enable 2FA, but rarely teaches them how to keep it recoverable.

The safest ways to back up TOTP seeds

Not all backups are equal. A backup stored in the same cloud as your password manager is better than nothing, but it is still one breach away from being stolen. The best backups are offline, redundant, and physically separate from your daily-use device.

  • Save original QR codes or text secrets — when you enable 2FA on a site, it usually shows the original QR code and the underlying secret. Screenshot or print the setup page and store it in a safe place, such as a locked drawer, a safe, or a secure off-site location.
  • Use encrypted exports — some authenticator apps allow you to export an encrypted file containing all your seeds. Protect the export with a strong passphrase and store it on an encrypted drive or offline storage. Avoid emailing exports to yourself or leaving them on an unencrypted cloud drive.
  • Write down backup codes — most services give you one-time recovery codes when you enable 2FA. These are the fastest recovery path. Print them, store them in a password manager, and keep a physical copy in a different location from your phone.
  • Keep a secondary device — if you have an old phone or a tablet, you can scan the same QR code into a trusted secondary device. Treat that device as backup hardware: it should stay at home, be encrypted, and not travel with you daily.

What to avoid

A backup that is convenient is often a backup that is insecure. The following habits weaken the very protection 2FA is supposed to provide:

  • Storing seeds in plain text — a screenshot of a QR code in your phone's photo album is readable by any app with gallery access. If you must keep a photo, move it to an encrypted vault immediately.
  • Auto-syncing to unencrypted cloud storage — cloud-synced authenticators are convenient, but they centralize every secret an attacker would need. If the cloud account is phished, all your 2FA codes are compromised at once.
  • Emailing secrets to yourself — email accounts are high-value targets and are often restored with weaker proof than your authenticator app. A TOTP seed in your inbox is one password reset away from being stolen.
  • Relying on a single backup — if your only backup is on the same phone you are trying to replace, it is not a backup. Maintain at least one copy that is physically separate from your daily device.

How to recover an authenticator app after device loss

  1. Try the service's backup codes first — sign in to the service on the web and use one of the recovery codes. Once inside, disable 2FA and re-enable it with your new device.
  2. Restore from an encrypted export — if you exported your seeds from a standard authenticator, install the same app on the new device and import the file. You will need the passphrase you set during export.
  3. Re-scan the original QR codes — if you saved the original secrets, open each service's 2FA settings and re-scan them into the new authenticator app. You may need to disable and re-enable 2FA if the service does not show the old secret again.
  4. Contact the service's support — if you have no backup, some services allow account recovery through identity verification, though this can take days and may not be available for all accounts.

Ydenticator's device-bound backup model

Ydenticator does not sync TOTP seeds to the cloud. Instead, each device stores its own encrypted payload using a non-extractable AES-GCM-256 key derived from hardware-backed WebAuthn PRF (Windows Hello, iOS Face ID / Touch ID). This means the seeds are not simply copied from one place to another; they are re-sealed to a specific device.

This design intentionally raises the bar for backup convenience. Because the key cannot be exported, the classic "export my seeds and move them to a new phone" workflow does not apply. Instead, Ydenticator supports two recovery paths:

  • Enroll a new device from an existing one — from the dashboard on a device that already has your key, use the Add phone flow to generate a signed, short-lived QR code. Scan the code with the new device to transfer the same encrypted identity and provider seeds without ever storing them in the cloud.
  • Administrator reset — if all your devices are lost, an administrator can reset your account. You will need to re-verify your email and phone, answer the 30 questions again, and re-register each provider. This is slower than a cloud restore, but it is also far more resistant to seed theft.

Best practices for Ydenticator users

  • Enroll at least one trusted secondary device — a phone or tablet that stays in a safe location gives you a recovery path without relying on cloud backup.
  • Save every service's backup codes — Ydenticator protects your codes, but each online service should also provide its own recovery codes. Store those codes outside Ydenticator.
  • Keep the device operating system up to date — hardware-backed keys depend on the OS's security model. Prompt security updates protect the non-extractable key from local attacks.
  • Use the same email on every enrolled device — Ydenticator links all enrolled devices to the same email address, making it easier to recognize and recover your identity.

Backup vs. recoverability trade-off

There is a real tension between easy recovery and strong security. Cloud-synced apps are easy to recover but expose all secrets to a single account breach. Device-bound apps are harder to recover but resist mass seed theft. Ydenticator chooses the device-bound side of the trade-off and uses the Add phone enrollment flow to make recovery manageable without weakening the model.

© 2026 Ydenticator