Resource icon

Prepare GitHub two-factor recovery before a phone is lost

GitHub requires many contributors to use two-factor authentication. If the only authenticator disappears and no recovery route remains, GitHub warns that Support may be unable to restore the account. A recovery code file, passkey, security key or verified-device route can help, but each has different dependencies. Preparing before phone migration is much easier than proving ownership after lockout.

Before you start​

Use a trusted, already signed-in device. Identify the account's verified email addresses and protect the mailbox separately. Decide where recovery codes can live without being exposed in a public repository, shared chat or unencrypted screenshot. Keep a second physical device available until the new authenticator works.

Do it step by step​

  1. Open Settings, Password and authentication, and review currently enrolled second factors. Add a second authenticator or security key where supported; verify the new method before removing the old one.
  2. Download or regenerate the recovery codes file from GitHub's two-factor recovery settings. Store it in a protected password manager or encrypted offline location, separate from the only phone used to sign in. Regenerating codes can invalidate the earlier set, so replace old copies.
  3. Review passkeys, verified devices and SSH keys as additional recovery factors. GitHub documents that availability of a particular factor can vary; do not assume an SSH key will always qualify simply because a key exists in a laptop folder.
  4. Perform a fresh sign-in from a separate browser using the new authenticator or passkey while your current session remains open. Verify the account name and email before completing any prompt. Do not deliberately spend a one-time recovery code merely for a routine test if another method suffices.
  5. Record where the recovery file is stored and how a trusted person can find it if appropriate, without sharing the codes themselves. If this is an organization account, ensure repository continuity does not depend on a single person's inaccessible login.
  6. Only after all tests pass should you remove an old phone, authenticator or security key. Review active sessions and credential lists after the change, and retain the official recovery guidance in your personal checklist.

Check the result​

A new-device sign-in succeeds, the account has at least two recovery paths with different failure modes, and the recovery file remains accessible after the old phone is retired.

If something goes wrong​

If you already lost every second factor, start GitHub's official recovery flow. It may use a previously verified device, SSH key or token and can take time; GitHub says Support cannot guarantee restoration. Avoid anyone offering to bypass 2FA for a fee or asking you to send recovery codes.

Know the limit​

A recovery method is a credential and must be protected like one. A passkey can satisfy password and 2FA on GitHub, but losing its only copy without another route can still be a problem. GitHub's current eligibility rules, not an old screenshot, determine which method works during recovery. GitHub recovery methods GitHub lost-factor process
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack