GitHub requires many contributors to use two-factor authentication. If the only authenticator disappears and no recovery route remains, GitHub warns that Support may be unable to restore the account. A recovery code file, passkey, security key or verified-device route can help, but each has different dependencies. Preparing before phone migration is much easier than proving ownership after lockout.
Before you start
Use a trusted, already signed-in device. Identify the account's verified email addresses and protect the mailbox separately. Decide where recovery codes can live without being exposed in a public repository, shared chat or unencrypted screenshot. Keep a second physical device available until the new authenticator works.Do it step by step
- Open Settings, Password and authentication, and review currently enrolled second factors. Add a second authenticator or security key where supported; verify the new method before removing the old one.
- Download or regenerate the recovery codes file from GitHub's two-factor recovery settings. Store it in a protected password manager or encrypted offline location, separate from the only phone used to sign in. Regenerating codes can invalidate the earlier set, so replace old copies.
- Review passkeys, verified devices and SSH keys as additional recovery factors. GitHub documents that availability of a particular factor can vary; do not assume an SSH key will always qualify simply because a key exists in a laptop folder.
- Perform a fresh sign-in from a separate browser using the new authenticator or passkey while your current session remains open. Verify the account name and email before completing any prompt. Do not deliberately spend a one-time recovery code merely for a routine test if another method suffices.
- Record where the recovery file is stored and how a trusted person can find it if appropriate, without sharing the codes themselves. If this is an organization account, ensure repository continuity does not depend on a single person's inaccessible login.
- Only after all tests pass should you remove an old phone, authenticator or security key. Review active sessions and credential lists after the change, and retain the official recovery guidance in your personal checklist.