You are here: start » en » Internal Documentation » faq » Authenticator lost or phone broken – recovering your account

Authenticator lost or phone broken – recovering your account

This page is readable without signing in, because otherwise it would be out of reach at exactly the moment it is needed. One entry per symptom; the setting is in each case an account in this wiki with two-factor authentication set up, unless stated otherwise.

Which entry applies to you is decided by a single question — whether a signed-in session is still open anywhere:

Your situation What you need Entry
Still signed in on another device (laptop, tablet) Nothing. You do it yourself “You are still signed in on another device”
Not signed in anywhere any more A request to the administrators — you can raise it without signing in “You cannot get in anywhere”
You are looking for a spare or backup code The same route as above — there are none “Are there recovery codes or backup codes?”
The app shows codes, the wiki rejects them Usually just the right time of day “The code from the app is rejected”

Resetting your password does not help here. It exchanges the password and nothing else; the second factor is left untouched. After a password reset, signing in still asks for the code you currently cannot produce. See the entry “Password reset, and the code prompt still appears”.

You are still signed in on another device

Setting: an account with an authenticator app set up; a valid, signed-in session still exists on a second device.

Cause: the second factor is bound to the secret held in the app, not to the account as a whole. If the app is gone, the secret is gone — the existing session is unaffected by that, because it has already proven the factor.

Solution: you replace the factor yourself while that session is alive. The procedure has two stages, because the set-up button only appears once no factor is left:

  1. On the device that is still signed in, open User Profile (address doku.php?do=profile).
  2. In the Two-factor authentication (TOTP) section, tick the box Disable two-factor authentication under the Authenticator app entry.
  3. Fill in the Confirm (old password) field and click Save. The old factor is now removed.
  4. The button Set up two-factor authentication now appears on the same page. Click it.
  5. Scan the QR code with the authenticator app on the new device — or type in the text key shown underneath it by hand.
  6. Enter the six-digit code currently displayed into Confirmation code and click Confirm and enable.

Only this last step stores the new secret. A QR code that has been scanned but not confirmed activates nothing.

Do not sign out before the new factor is confirmed. Between step 3 and step 6 the account holds no second factor. Signing out inside that window is recoverable — signing in is then a single step — signing out before it is not.

You cannot get in anywhere

Setting: an account with a second factor set up; no signed-in session on any device; the device holding the authenticator app is lost, broken or has been reset.

Cause: there is deliberately no self-service route around a factor that has been set up. Such a route would be a second, weaker sign-in beside the first — and therefore the abolition of the factor, not its recovery.

Solution: an administrator of this wiki resets the enrolment. The full sequence, so that both sides know what is coming:

  1. You raise the request at doku.php?do=wkrequest&type=MFA_RESET_REQUEST. This form is reachable without signing in — that is precisely what it is built for. Enter your login name, an address to reply to, and what happened. You receive a request number. If you cannot or would rather not use the form, contact whoever runs this wiki by your usual route instead; from there the sequence is the same.
  2. The administrators verify that it is you — by a route that does not depend on the lost device. A call back on a number already known, an appearance in person, confirmation by your line manager. Email alone is not enough: whoever has taken over the mailbox writes the same email.
  3. The administrators reset it (the exact step is in Identity: overview, and in full detail in Troubleshooting (German only) under “A user has lost their authenticator device”).
  4. You sign in again — now in a single step, with user name and password alone. The code prompt no longer appears.
  5. You set the factor up again, see the entry “Setting it up again after a reset”.

Only the second factor is reset. Your password, your account, your permissions and your pages are unchanged; nobody learns your password in the process.

Never enter a password, a one-time code or an access token into the request. They are not needed, they are removed before the request is stored, and nobody from the administration will ever ask you for one. A request is also not a permission: it names a login, it does not prove one — which is why identity verification stands as a step of its own in the list.

Identity verification is the actual protection, not the click. A reset on request turns two-factor authentication into a question put to the administrators — and it is then answered by whoever sounds more convincing.

Are there recovery codes or backup codes?

Setting: every version of this wiki.

Cause: no, there are none — neither printed nor displayed, neither at set-up nor later. There is nothing to look up, nothing to search for and nothing you have failed to keep. Should you find a version of this documentation that mentions “ten printed spare codes” or similar: that statement was wrong and has been removed.

Solution: the case that spare codes would be for does have an answer — it simply goes by another name. If you are still signed in somewhere, you replace the factor yourself; if you are not, an administrator resets it. Both are further up this page.

Two terms are regularly confused, and the confusion costs time:

What is meant What it is for Does it exist?
One-time code (email, eight characters, e.g. K7QM-3B9X) Setting a password anew: forgotten password, registration, invitation Yes
Spare / backup / recovery code (issued in advance, to be kept) Replacing a lost second factor No

The one-time code in the first row does not take you past the code prompt — it only sets the password. See the next entry.

Password reset, and the code prompt still appears

Setting: an account with a second factor set up; “forgotten password” has been completed and a new password successfully set.

Cause: password and second factor are two separate proofs. The reset writes a new password and nothing else; the factor's enrolment remains part of the account and is not touched. Signing in afterwards asks for both — exactly as it did before.

Solution: do not pursue this route any further; it cannot replace the factor. Follow “You cannot get in anywhere” instead.

The same holds in reverse: resetting the second factor does not change your password. If you have lost both, that is two separate procedures — first the factor through the administrators, then the password via “forgotten password” or likewise through the administrators.

The code from the app is rejected

Setting: the authenticator app displays codes, the account is set up, every code entered is refused. The device is present — this is not a loss.

Cause: two causes, in this order of likelihood:

  • The clock is wrong. The code is calculated from the current time. If your phone's clock differs from the server's by more than about half a minute, the app systematically calculates codes other than the ones the server expects.
  • The entry in the app does not belong to this account. After several set-up attempts the app holds several similarly named entries; only the one confirmed last is valid.

Solution:

  1. Switch on automatic time synchronisation on the phone (Android: Settings → System → Date and time → Automatic; iOS: Settings → General → Date & Time → Set Automatically).
  2. Wait for the next code — it changes every 30 seconds — and enter it again.
  3. With several entries in the app: use the one created last.
  4. If it stays that way, it is not a clock problem. Contact the administrators; for them, the isolation procedure is in Troubleshooting (German only) under “Every code is rejected”.

After five failed attempts the waiting sign-in is discarded and you start again at user name and password. That is not a lock on the account: you can begin again immediately.

Setting it up again after a reset

Setting: the second factor has been reset; signing in is a single step again.

Cause: a reset removes the factor, it does not replace it. Until you set up a new one, the account is protected by the password alone — and areas of this wiki that require a factor stay closed to you, with a corresponding note on the refusal page.

Solution:

  1. Sign in with user name and password.
  2. Open User Profile (doku.php?do=profile).
  3. In the Two-factor authentication (TOTP) section, click Set up two-factor authentication.
  4. Scan the QR code with the authenticator app, or type in the text key by hand.
  5. Enter the six-digit code displayed into Confirmation code, then Confirm and enable.

The detailed instructions with every intermediate step are in Setting up two-factor authentication.

The code by email — what it is and what it is not

Setting: accounts for which the administrators have released the email method.

Cause: the code by email is a second factor in its own right, set up on the profile page like the authenticator app — not an emergency exit that steps in by itself when the app is lost. At sign-in, the button Send code by email appears only if that factor is set up for your account. If only the authenticator app is set up, that button does not exist.

Solution: both factors may be held at the same time, and one of the two is then enough at sign-in. That is exactly what makes the email method a usable fallback — but only if you set it up beforehand, while you still have access. After the fact, with the app lost, it cannot be done.

Set it up on the profile page under Set up by email. If that button is missing, the method has not been released for your account — ask the administrators.

The code by email is the weaker factor: it arrives in the same mailbox through which passwords are usually reset as well. Whoever takes over the mailbox thereby holds both halves. As a complement to the app it is sensible; as the sole factor it is only the second-best choice.


wiki 2fa totp authenticator lost recovery signin

en/wiki/faq/lost-authenticator.txt · Last modified: by 127.0.0.1