What it means
A two-factor recovery code is a one-time alternative if the normal second factor is unavailable. An active GitHub session is a device or browser already authenticated to the account. Keeping a laptop signed in is useful during phone migration but is not a substitute for stored recovery methods: the session can expire, be revoked or be lost with the laptop. A recovery code stored on that same laptop can disappear in the same accident.
A real-world example
A phone with the authenticator is lost. The user still has GitHub open in a work browser, but the browser is about to be reset. Without recovery codes, passkey or another eligible method, account recovery may become difficult or impossible.
What to do
While signed in, configure at least two independent authentication or recovery methods, save the recovery codes securely away from the main device and test a new login. Review account email and known devices. Do not share a recovery code with someone claiming to be GitHub Support.
The distinction that matters
A session grants access now; a recovery code may restore access later. Neither proves that the device holding it is safe. GitHub warns that Support cannot guarantee restoration when all two-factor credentials and recovery routes are gone, so preparation matters more than relying on an open tab.
GitHub recovery setup Lost-factor policy