Losing a phone is a poor time to discover that your Discord authenticator was the only route into the account. Discord supports several multi-factor methods, including an authenticator app, passkeys or security keys, and backup codes. The safest setup is not simply switching one on: it is registering methods you control, saving recovery codes outside the phone and testing the recovery path while you can still sign in. Discord Support says it cannot remove MFA for you if you lose all recovery methods.
Before you start
Sign in on a device you trust and update Discord first. Secure the email address behind the account with its own unique password and MFA; email access can be central to recovery. Have an authenticator or supported security key ready, plus a secure place to store backup codes, such as a reputable password manager or a protected offline record. Never send codes to a friend, bot or purported Discord employee.Do it step by step
- Open User Settings, then the account security or MFA section. Review which methods are already active. If an old phone or key is listed, do not remove it until a replacement method has been added and verified.
- Add a passkey or security key if your device supports it, or set up an authenticator app using Discord's current on-screen flow. The QR setup code is a secret: scan it only into your own authenticator and never share a screenshot of it.
- Finish enrollment by entering the requested verification code. Return to the settings page and confirm the method appears as enabled. A code merely appearing in the authenticator does not prove Discord accepted enrollment.
- Generate or view Discord backup codes and store them in a separate secure place you can reach without the phone being replaced. Treat each code like a password, note that a code may be single-use, and refresh your saved copy if you regenerate the set.
- If you are about to change phones, transfer or re-enroll the authenticator through its supported process while the old phone is still available. Add the new method, sign out of a harmless secondary session, and test a normal sign-in before wiping the old device.
- Review the list again for a method you no longer control. Remove it only after the new sign-in path and backup-code access have been proven. Check email and password security at the same time so MFA is not protecting an otherwise exposed account.