Security

Lost Your Two-Factor Device

If you cannot produce a six-digit code at sign-in, a recovery code will get you back in. Read this page before you need it, because the single most useful step happens while you still have access.

The Fast Answer

At the two-factor prompt, headed "Verify Your Identity", there is a link below the code box reading Use a Recovery Code.

  1. Enter your email address and password as usual.
  2. On the verification screen, click Use a Recovery Code.
  3. Type one of the recovery codes you saved when you enabled two-factor authentication. They look like two groups of five characters separated by a hyphen.
  4. Click Verify.

The two-factor verification screen in KPanel with the recovery code option

You are signed in. The code you used is consumed immediately and can never be used again.

You get twelve recovery codes when you enable two-factor authentication. Each is single use. Using one does not disable two-factor authentication or change anything else about your account.

Read This Before You Sign In With a Recovery Code

There is an important limitation, and knowing it changes what you should do next.

Turning two-factor authentication off, and generating a fresh set of recovery codes, both require a current code from your authenticator app. Your password and a recovery code are not enough for either.

So if your phone is genuinely gone for good, signing in with a recovery code gets you into the panel, but it does not let you clear two-factor authentication or mint new codes. You will need support for that.

This leads to a simple rule:

If you can still reach your authenticator app anywhere, on a backup device, in a password manager, or on an old phone in a drawer, restore access to it before you burn through your recovery codes. Once the codes are gone and the app is gone, only support can help.

If You Still Have the Authenticator

You have simply left your phone somewhere. Sign in with a recovery code, then, as soon as you have the app in front of you again:

  1. Go to Settings, then Security.
  2. Find the Recovery codes section.
  3. Click Regenerate, enter your password and a current authenticator code.
  4. Save the new twelve codes somewhere safe. The panel warns that your previous codes are invalidated immediately.

If the Authenticator Is Gone for Good

The app is deleted, the phone is lost, the device is wiped. If you can still sign in with a recovery code, do that first: an account you are inside is much easier to help with.

Then open a support ticket and explain that you have permanently lost your two-factor device. Quote your Support Key from Settings, then Account, so your account can be found straight away.

If you cannot sign in at all, email support@kapsulehost.com from the address on the account.

Support will verify your identity before changing anything about your two-factor setup. That is the whole point of two-factor authentication: an account it could be talked off over email would not be protecting anything. Expect the process to take longer than a password reset, and do not treat it as an emergency route.

Set Up a Second Factor Now

Kapsule supports more than one kind of second factor, and having two means losing one is an inconvenience rather than a crisis. All of them live on Settings, then Security, under Two-factor authentication.

Passkeys. The panel describes them as allowing "fast, passwordless sign-in using your device biometrics." Add one with Add passkey. A passkey synced through your operating system or password manager survives losing a single device.

SMS two-factor. Where it is available, click Enable, enter your mobile number including the country code, and confirm the code that arrives.

Trusted devices. Ticking "Remember this device for 30 days" at the two-factor prompt records the browser as trusted so it can skip the code. Trusted devices are listed on the Security page and can be untrusted individually.

A password manager that stores both your password and your two-factor secret, synced across devices, removes this whole failure mode. So does adding a passkey on a second device today. Either takes two minutes.

When the Code Is Rejected but You Have the Right App

Not every rejection means your device is lost.

"Invalid code. Check your authenticator app and device clock." Time-based codes depend on your phone's clock being accurate. If it has drifted, every code will be wrong. Turn on automatic time setting on the device, or use your authenticator app's own time-correction option, then try again.

"This code was already used. Enter the current code from your authenticator." Each code is accepted once. Wait for the app to roll over to a new code and enter that. Codes rotate every 30 seconds.

"Too many failed attempts. Please sign in again." After five failed attempts the sign-in session is discarded. Go back to the login page and start again from your email and password.

"Session expired. Please sign in again." The verification step has a time limit. Start again from the login page.

Which Screen Am I On?

Two different verification screens exist and they need different things.

The two-factor screen is headed "Verify Your Identity" and asks for a code from your authenticator app, with the recovery code link underneath. That is the screen this page is about.

A new device check may email you a code instead, when you sign in from a browser we have not seen before. That code arrives in your inbox and is not a two-factor code. If you cannot receive it, the problem is your email rather than your authenticator, and Lost Access to Your Account Email is the page you want.

After You Are Back In

Whichever route you took, tidy up:

  • Regenerate your recovery codes and store them somewhere you will still have in a year: printed and filed, or in a password manager. Not in the same phone that holds the authenticator app.
  • Check your active sessions on Settings, then Security, and sign out anything you do not recognise.
  • Check the login history on the same page for failed attempts that were not you.
  • Check the audit log for changes you did not make.

If any of that looks wrong, treat it as a compromise rather than a lockout and work through Account Security.

Troubleshooting

The recovery code is rejected. Enter it exactly as saved. The hyphen is optional and case does not matter, but a code from an older set will not work: regenerating invalidates every previous code.

I have no recovery codes and no authenticator. Contact support. There is no self-service path, by design.

I never saved my recovery codes. They are only shown once, at setup. If you still have the authenticator, sign in and regenerate a set today.

Two-factor is on and I did not enable it. Someone else may have. Contact support urgently and treat the account as compromised.

I removed the Kapsule entry from my app by mistake. The secret is gone with it. Sign in with a recovery code, and if you cannot regenerate without a code, contact support.

Still need help?

Email us at support@kapsulehost.com or open a chat in KPanel.

Open KPanel