Currently, FusionAuth does not support recovery code regeneration within the hosted account pages, and there are no plans on the public roadmap for this feature.
Regarding your specific questions:
Hosted account page support: There is no current support for recovery code regeneration as a themeable template in the hosted account pages. Recovery codes are only generated and displayed when a user first enables an MFA method. As of version 1.68.0, recovery codes are hashed at rest using salted-pbkdf2-hmac-sha256 and cannot be retrieved after initial generation—they can only be regenerated through the API. This would need to be submitted as a feature request.
JWT authentication for the generate endpoint: The generate recovery codes endpoint (POST /api/user/two-factor/recovery-code/{userId}) currently only supports API key authentication. There is no JWT authentication variant available, and nothing in the current documentation or public roadmap indicates one is planned.
Recommended approach: Submit feature requests for both capabilities through the FusionAuth GitHub Issues repository. These features could be valuable for self-service MFA management scenarios. Note that feature requests, if accepted, do not have guaranteed timelines for implementation.
Current workarounds: You would need to implement this functionality in your own application with server-side code that uses an API key to call the generate recovery codes endpoint, though this moves the functionality outside the hosted pages where other MFA management occurs. When new codes are generated, all existing recovery codes are invalidated and replaced with a new set of 10 codes.
Related Documentation Multi-Factor Authentication (MFA) - Recovery Codes - Overview of how recovery codes work in FusionAuth Generate Recovery Codes API - API endpoint documentation for programmatic recovery code generation Self-Service Account Management - Documentation on the hosted account pages and available features Customizing Self-Service Account Management - Guide for customizing hosted account page templates API Authentication - Documentation on API key and JWT authentication methods FusionAuth 1.68 Release Notes - Hashed Recovery Codes - Information about recovery code hashing security enhancement