<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with recovery-codes]]></title><description><![CDATA[A list of topics that have been tagged with recovery-codes]]></description><link>https://fusionauth.io/community/forum/tags/recovery-codes</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 00:12:48 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/recovery-codes.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[How can users regenerate MFA recovery codes on hosted account pages?]]></title><description><![CDATA[<p dir="auto">Currently, FusionAuth does not support recovery code regeneration within the hosted account pages, and there are no plans on the public roadmap for this feature.</p>
<p dir="auto">Regarding your specific questions:</p>


<p dir="auto"><strong>Hosted account page support</strong>: There is no current support for recovery code regeneration as a themeable template in the hosted account pages. Recovery codes are only generated and displayed when a user first enables an MFA method. As of version 1.68.0, recovery codes are hashed at rest using salted-pbkdf2-hmac-sha256 and cannot be retrieved after initial generation—they can only be regenerated through the API. This would need to be submitted as a feature request.</p>


<p dir="auto"><strong>JWT authentication for the generate endpoint</strong>: The generate recovery codes endpoint (POST /api/user/two-factor/recovery-code/{userId}) currently only supports API key authentication. There is no JWT authentication variant available, and nothing in the current documentation or public roadmap indicates one is planned.</p>


<p dir="auto"><strong>Recommended approach</strong>: Submit feature requests for both capabilities through the <a href="https://github.com/FusionAuth/fusionauth-issues" rel="nofollow ugc">FusionAuth GitHub Issues repository</a>. These features could be valuable for self-service MFA management scenarios. Note that feature requests, if accepted, do not have guaranteed timelines for implementation.</p>
<p dir="auto"><strong>Current workarounds</strong>: You would need to implement this functionality in your own application with server-side code that uses an API key to call the generate recovery codes endpoint, though this moves the functionality outside the hosted pages where other MFA management occurs. When new codes are generated, all existing recovery codes are invalidated and replaced with a new set of 10 codes.</p>
Related Documentation

<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#recovery-codes" rel="nofollow ugc">Multi-Factor Authentication (MFA) - Recovery Codes</a> - Overview of how recovery codes work in FusionAuth
<a href="https://fusionauth.io/docs/apis/two-factor/generate-recovery-codes" rel="nofollow ugc">Generate Recovery Codes API</a> - API endpoint documentation for programmatic recovery code generation
<a href="https://fusionauth.io/docs/lifecycle/manage-users/account-management/" rel="nofollow ugc">Self-Service Account Management</a> - Documentation on the hosted account pages and available features
<a href="https://fusionauth.io/docs/lifecycle/manage-users/account-management/customizing-account-management" rel="nofollow ugc">Customizing Self-Service Account Management</a> - Guide for customizing hosted account page templates
<a href="https://fusionauth.io/docs/apis/authentication" rel="nofollow ugc">API Authentication</a> - Documentation on API key and JWT authentication methods
<a href="https://fusionauth.io/blog/announcing-fusionauth-1-68#hashed-recovery-codes" rel="nofollow ugc">FusionAuth 1.68 Release Notes - Hashed Recovery Codes</a> - Information about recovery code hashing security enhancement

]]></description><link>https://fusionauth.io/community/forum/topic/3155/how-can-users-regenerate-mfa-recovery-codes-on-hosted-account-pages</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3155/how-can-users-regenerate-mfa-recovery-codes-on-hosted-account-pages</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>