๐ Backup Code Generator
* Generated codes are lost when you leave this page โ store them somewhere safe if you need them.
Generate a batch of random backup codes, similar to the recovery codes issued for two-factor authentication (2FA). Uses a character set with ambiguous characters removed (like 0/O and 1/I) so the codes are easier to read and re-type accurately.
How to use
- Enter how many codes to generate.
- Click "Generate" to see a list of random backup codes.
- Use the "Copy" buttons to copy an individual code or all of them โ store them somewhere safe.
How the calculation works
This tool generates codes in the form XXXX-XXXX using the browser's cryptographically secure random generator (crypto.getRandomValues). It uses 32 characters: the uppercase letters and digits minus the easily confused 0 and O, and 1 and I (ABCDEFGHJKLMNPQRSTUVWXYZ23456789). That reduces mistakes when codes are copied by hand or read aloud. Because there are exactly 32 characters (2 to the 5th power), selecting characters from random numbers introduces no bias towards any of them. Each character carries 5 bits, so an 8-character code has 5 ร 8 = 40 bits โ about 1.1 trillion possibilities.
Worked example
One possible set of generated codes K7RM-4XPN H2WD-9QAB โฆ Each code is one of 32โธ = 1,099,511,627,776 possibilities (about 1.1 trillion), so guessing one at random has no realistic chance of success.
Things to be aware of
- Codes made here are not registered with any service. Issue two-factor backup codes from each service's own settings.
- They are suitable for recovery codes in your own systems, one-time redemption codes and the like.
- Codes disappear when you close the page; store any you need somewhere safe.
- Backup codes are usually kept separately from passwords, for example printed on paper.
FAQ
Are the generated codes saved on this site?
No. Generation happens entirely in your browser and nothing is ever sent or stored anywhere. Results disappear when you reload the page, so copy them somewhere safe while they're displayed if you need them.
Can I use these in place of an actual service's 2FA backup codes?
No โ codes generated here aren't registered with any real service's system, so they won't work for that service's authentication. Use this for generating your own standalone backup codes or for testing purposes.
Why are ambiguous characters excluded?
Characters that are easily confused when handwritten or printed โ like the digit 0 vs. the letter O, or the digit 1 vs. the letter I โ are excluded to reduce typos when entering a code manually.