RecoveryCodes helps teams prevent account lockouts by mapping every MFA dependency that lives outside their identity provider.
Most companies believe their multi-factor authentication is under control because Okta, Entra ID, Google Workspace, or JumpCloud sits in front of the apps that matter. That belief holds right up until someone drops their phone in a canal, leaves the company on short notice, or loses the one YubiKey that happened to be the only registered factor on the root billing account. At that point the team discovers an uncomfortable truth: the identity provider only governs the accounts that were actually federated. Everything else, and there is always an everything else, is protected by factors that nobody has documented.
RecoveryCodes is the system of record for that gap. It gives you a live map of which accounts depend on which phone, which security key, which authenticator app, and which employee, so that when a device disappears you already know the blast radius instead of discovering it one locked account at a time.
The problem it solves Every growing company accumulates accounts that never make it into SSO. Domain registrars, DNS providers, payment processors, app store consoles, cloud root accounts, ad platforms, bank portals, code signing certificates, and dozens of SaaS tools on plans where SSO is priced as an enterprise upsell. Each of these gets protected with TOTP or a hardware key by whoever set it up, usually in a hurry, usually on their personal device, usually without telling anyone.
The result is a quiet single point of failure. One engineer's phone holds the second factor for the production DNS account. One founder's security key is the sole registered credential on the payment processor. One departed contractor still appears as the recovery contact on an ad account that spends five figures a month. None of this is visible in the identity provider dashboard, because none of these accounts were ever connected to it.
When the device goes missing, the cost is not the device. The cost is the days spent grinding through vendor account recovery flows, notarised identity documents, support tickets that take a week per round trip, and in the worst cases, an account that is simply unrecoverable. Meanwhile DNS cannot be updated, payouts cannot be released, and the app cannot ship.
RecoveryCodes exists to make that failure mode visible before it happens rather than after.
How it works You register the things that actually hold your factors. A phone, a laptop, a hardware security key, an authenticator app profile, a backup key stored in a safe. Each of these becomes a device in RecoveryCodes, owned by a person.
You then register the accounts that depend on them. For each account you record which devices carry a working factor, which method each device uses, who owns the account, and what recovery paths exist if every registered factor is lost. This mapping is the core of the product. Everything else is built on top of it.
Once the map exists, RecoveryCodes continuously answers the questions that used to require a company-wide Slack thread:










