Yes, this is intentional behavior in FusionAuth.
When a user provides a recovery code to disable an MFA method — whether through the hosted pages or the API — FusionAuth removes all MFA methods from the account. The hosted pages use the same underlying MFA API, so the behavior is consistent across both interfaces.
Why does this happen?Recovery codes are designed as a last-resort mechanism. The assumption is that if a user must resort to a recovery code to disable MFA, they may have lost access to all their authentication factors. Removing all MFA methods ensures the user can regain access and re-enroll fresh methods.
When a recovery code is used for disabling MFA:
All MFA methods are removed from the user's account, regardless of which specific methodId was targeted All remaining recovery codes are invalidated at the same time If the user later adds a new MFA method, a brand new set of recovery codes will be generated Why is login different?When a user logs in with a recovery code (instead of a verification code), FusionAuth only consumes that specific recovery code without removing MFA methods. This is because login is not an administrative action — the user is simply authenticating, not managing their MFA configuration.
Current limitationsUnfortunately, there is currently no way to configure FusionAuth to remove only the targeted MFA method when a recovery code is used. This is a known design constraint.
Workaround considerationsIf this behavior is problematic for your use case, you could:
Provide clear messaging to users before they use a recovery code to disable MFA Implement a custom flow outside the hosted pages that uses the API with tighter control over which methods are removed Encourage users to contact support or use an alternative recovery flow that doesn't rely on recovery codes for MFA managementFeedback on this behavior has been passed along to the FusionAuth Product team for future consideration.
Related Documentation Multi-Factor Authentication (MFA) - Disable MFA Guide - Explains the behavior when using recovery codes vs. verification codes to disable MFA Disable Multi-Factor API - API documentation for disabling MFA methods Recovery Codes Overview - Information about MFA recovery codes and when they're generated Self-Service Account Management - Documentation on the hosted account management pages including MFA management