2FA Backup Codes Generator
Generate one-time recovery codes for account 2FA setup — plus their SHA-256 hashes, ready to store server-side
0/O and 1/I — characters people commonly mistype when copying a code by hand. Everything is generated with crypto.getRandomValues and never leaves your browser.About this tool
The ToolNinja 2FA Backup Codes Generator creates a set of one-time recovery codes — the standard fallback mechanism offered alongside TOTP/authenticator-app 2FA, used when someone loses access to their primary authenticator. Each code is drawn from a 32-character alphabet that deliberately excludes visually ambiguous characters (0/O, 1/I) to reduce transcription errors when a user copies a code by hand. Alongside the plaintext codes, it computes a SHA-256 hash of each one — the form you should actually be storing server-side. Backup codes are exactly as sensitive as a password: storing them in plaintext means a database breach exposes a working 2FA bypass for every affected account, the same reasoning that's kept password hashing standard practice for decades. Everything runs 100% in your browser using crypto.getRandomValues for generation and the Web Crypto API for hashing — nothing is sent anywhere.
When to use it
- →Generating a realistic set of backup codes to test a 2FA recovery flow during development
- →Understanding what a production backup-codes system should actually store (hashes, not plaintext)
- →Prototyping the UI for a 2FA setup wizard's backup-codes step
- →Learning the standard format and character set conventions real backup codes use
Tips
- ◆Store only the SHA-256 hash of each code server-side, exactly like a password — never the plaintext, and never reversibly encrypted either.
- ◆Mark each code as used immediately after successful redemption so the same code can't be replayed by someone who intercepted it once.
- ◆Show codes to the user exactly once, at generation time, with a clear prompt to save them somewhere safe — there's no secure way to display them again later if they're only stored hashed.
Frequently asked questions
Why generate 8-16 codes instead of just one?
Multiple single-use codes mean losing or using one doesn't lock the user out — they simply have fewer remaining. It also lets a user who's used several codes know it's time to regenerate a fresh batch, rather than discovering their only recovery code is already spent.
Why exclude 0/O and 1/I from the code alphabet?
These character pairs are easily confused in many fonts, especially when a user is copying a code by hand from a printed page or a screenshot rather than copy-pasting. Removing them from the alphabet eliminates an entire category of 'the code doesn't work' support issues caused by a single mistyped character.
Should backup codes expire?
Most real systems don't put a time expiry on backup codes — they're meant to work whenever the primary 2FA method is unavailable, which could be months after generation. Instead, the security model relies on each code being single-use and on prompting the user to regenerate a fresh batch once they've used most of the current one.