What Google backup codes are and why they matter
Google backup codes are one-time recovery codes for account access when you cannot use your usual second factor, such as a phone prompt, authenticator app, or security key.
They are part of Google Account two-step verification and are especially useful during travel, device loss, SIM issues, or app reinstallation.
Because each code can usually be used only once, old sets become less useful over time.
That is why many people search for how to regenerate Google backup codes after using a few, losing the printed sheet, or wanting a fresh set for better security.
Can you regenerate Google backup codes?
Yes.
Google lets you generate a new set of backup codes from your Google Account security settings.
When you create a new batch, the previous codes are typically invalidated, which helps prevent old printed or saved codes from being reused.
This is important if you think a backup code may have been exposed.
Regenerating the codes is a simple security reset, and it is one of the fastest ways to reduce risk without changing your entire account setup.
How to regenerate Google backup codes
The exact layout may vary slightly by device, but the process is the same across most browsers and modern Google Account interfaces.
- Sign in to your Google Account.
- Open Security in the account menu.
- Find 2-Step Verification under the “How you sign in to Google” section.
- Authenticate again if Google asks you to confirm your identity.
- Scroll to Backup codes.
- Select Get backup codes or Show codes.
- Choose Regenerate codes if you want a new set.
After regeneration, save the new codes in a secure place.
If you printed the old set, destroy it.
If you stored them in a password manager, overwrite the old entry so there is only one current set.
When should you regenerate backup codes?
Regenerating backup codes is not something most people need to do often, but there are clear situations where it makes sense.
- You used one or more codes and want a full replacement set.
- You lost the paper copy or saved file.
- You suspect someone else saw the codes.
- You shared an older device that may have stored them.
- You want to align your recovery plan after changing phones or security keys.
For users who manage multiple devices, regeneration can also be part of a broader Google account hardening routine, alongside updating recovery email, recovery phone, and two-step verification methods.
What happens to old codes after regeneration?
When you generate new Google backup codes, the older set usually stops working.
That design is intentional, because it prevents a mix of active and stale codes from circulating in email threads, notes apps, screenshots, or printed documents.
If you have shared access with a trusted family member, office administrator, or IT team, tell them immediately that the previous codes are no longer valid.
Otherwise, they may try to use an expired code during an emergency and assume the account is broken.
Where should you store new backup codes?
Storage matters as much as generation.
Backup codes are meant to be available during an emergency, but they should not be easy for an attacker to find.
- Password manager: A strong option if you already trust the vault and protect it with a master password plus two-step verification.
- Printed copy: Useful if you want offline access, but keep it in a secure location such as a locked drawer or safe.
- Encrypted note or secure file: Better than plain text on a desktop, though still less ideal than a password manager.
Avoid storing backup codes in screenshots, cloud notes without encryption, shared drives, or email drafts.
Those places are often easier to compromise than the Google account you are trying to protect.
How many Google backup codes do you get?
Google typically provides a limited set of one-time backup codes, often enough for emergency access but not daily use.
The exact number can vary by interface and account flow, but the key point is that they are finite and meant to be replaced when needed.
That is why it is smart to treat them like a temporary recovery asset rather than a permanent login method.
If you are using them more than occasionally, it may be a sign that your primary second factor needs improvement.
How to keep access without relying on backup codes too often
Backup codes are a safety net, not the main security plan.
If you find yourself depending on them regularly, strengthen your account with better recovery options.
- Use the Google Prompt on a trusted phone.
- Enable an authenticator app such as Google Authenticator or a compatible TOTP app.
- Add a hardware security key that supports FIDO2 or WebAuthn.
- Keep your recovery phone number current.
- Review recovery email access and update it if needed.
Google’s two-step verification works best when you have at least two reliable methods.
A security key plus authenticator app, for example, is often more resilient than relying on SMS alone.
What if you cannot sign in to regenerate the codes?
If you are already locked out, you may not be able to regenerate Google backup codes until you regain account access.
In that case, use another sign-in method first, such as a trusted device, security key, Google Prompt, or recovery process.
If none of those are available, Google’s account recovery flow may ask questions or verify prior device use.
This process can take time, especially if your recovery details are outdated or you are logging in from a new location.
Common mistakes to avoid
People often run into avoidable problems when managing backup codes.
These are the most common ones.
- Saving codes in an unsecured text file.
- Printing codes and leaving them in an obvious location.
- Forgetting that regenerated codes invalidate the old set.
- Using backup codes as a routine login method instead of an emergency backup.
- Failing to update recovery options after changing phones or emails.
Keeping a simple inventory of your recovery methods can prevent confusion.
A note that lists your security key location, authenticator app status, and backup code storage place is often enough.
Best practices for 2026 account security
In 2026, phishing, SIM swap attacks, and credential theft remain major account risks, so recovery planning should be deliberate.
Google backup codes are still useful, but they work best inside a larger security model that assumes devices can be lost and prompts can be spoofed.
For stronger protection, consider a layered setup:
- Primary sign-in with a password manager-generated password.
- Two-step verification using a security key or authenticator app.
- Backup codes stored offline or in a secure vault.
- Current recovery phone and email details.
- Periodic review of active sessions and signed-in devices.
If you are managing a business or shared household environment, document who controls the recovery methods and where the backup codes are stored.
Clear ownership reduces downtime when someone loses a device or changes contact information.