Auth0 Docs home page
Search...
⌘K
Ask AI
Log In
Contact Sales
Sign Up
Sign Up
Search...
Navigation
Multi-Factor Authentication
Configure Recovery Codes for MFA
Documentation
Quickstarts
API Reference
SDKs
Secure
Make sure only the right people can access your applications
Secure
Protect Your Application
Application Credentials
Attack Protection
Continuous Session Protection
Highly Regulated Identity
Auth0’s Mobile Driver's License Verification Service
Multi-Factor Authentication
Multi-Factor Authentication (MFA)
Enable Multi-Factor Authentication
Multi-Factor Authentication Factors
WebAuthn as Multi-Factor Authentication
Configure Cisco Duo Security for MFA
FIDO Authentication with WebAuthn
Adaptive MFA
Auth0 Guardian
Customize MFA
Authenticate Using ROPG Flow with MFA
Step-Up Authentication
Configure Recovery Codes for MFA
Manage Authentication Factors with APIs
Reset User Multi-Factor Authentication and Recovery Codes
Multi-factor Authentication Developer Resources
Security Center
Security Guidance
Sender Constraining
Tokens
Protect Your Tenant
Tenant Access Control List
Compliance
Data Privacy and Compliance
On this page
How it works
Enable recovery codes
Learn more
Protect Your Application
Multi-Factor Authentication
Configure Recovery Codes for MFA
Copy page
Copy page
A recovery code is a unique code, generated by Auth0, allowing a user to regain account access. So if a user cannot access the device or account used for
multi-factor authentication
(MFA) enrollment, they can use a recovery code to authenticate.
How it works
When using
Universal Login
with recovery codes enabled:
A user starts MFA enrollment.
Auth0 generates a recovery code.
During MFA enrollment the user is shown the recovery code prompt.
The user saves the recovery code and completes the enrollment process.
Now the user can complete MFA with the recovery code they saved if they lose access to their device or account they enrolled for MFA.
When using Universal Login with recovery codes disabled:
Users will not see the recovery code prompt during MFA enrollment.
Users cannot authenticate with a recovery code.
Enable recovery codes
Recovery codes are disabled by default. You can enable recovery codes by going to
Dashboard > Security > Multifactor Auth
.
Learn more
Challenge with Recovery Codes
Was this page helpful?
Yes
No
Configure Step-up Authentication for Web Apps
Previous
Manage Authentication Factors with APIs
Next
Assistant
Responses are generated using AI and may contain mistakes.