<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How can users regenerate MFA recovery codes on hosted account pages?]]></title><description><![CDATA[<p dir="auto">We want to allow users to self-service the regeneration of their MFA recovery codes. The API endpoint for generating recovery codes (<code>POST /api/user/two-factor/recovery-code/{userId}</code>) exists, but there appears to be no way to invoke it from the hosted theme pages.</p>
<p dir="auto">Specific issues:</p>
<ul>
<li>The hosted account pages have no route for recovery code regeneration</li>
<li>There is no corresponding template in the theme set to customize</li>
<li>The generate endpoint requires API key authentication only (no JWT option), so it cannot be called directly from the browser</li>
</ul>
<p dir="auto">Placing this functionality on our own website doesn't seem ideal since all other MFA management lives on the FusionAuth hosted pages. We considered using a custom block on the hosted two-factor page, but this requires workarounds that could introduce security concerns.</p>
<p dir="auto">Are there any current or planned solutions for:</p>
<ol>
<li>Recovery code regeneration within hosted account pages (ideally as a themeable template alongside existing <code>accountTwoFactor</code> templates)?</li>
<li>A JWT-authenticated variant of the generate recovery codes endpoint to simplify browser-based implementation?</li>
</ol>
]]></description><link>https://fusionauth.io/community/forum/topic/3155/how-can-users-regenerate-mfa-recovery-codes-on-hosted-account-pages</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 04:45:55 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3155.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Sep 2026 16:06:19 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How can users regenerate MFA recovery codes on hosted account pages? on Mon, 28 Sep 2026 16:06:31 GMT]]></title><description><![CDATA[<p dir="auto">Currently, FusionAuth does not support recovery code regeneration within the hosted account pages, and there are no plans on the public roadmap for this feature.</p>
<p dir="auto">Regarding your specific questions:</p>
<ol>
<li>
<p dir="auto"><strong>Hosted account page support</strong>: There is no current support for recovery code regeneration as a themeable template in the hosted account pages. Recovery codes are only generated and displayed when a user first enables an MFA method. As of version 1.68.0, recovery codes are hashed at rest using <code>salted-pbkdf2-hmac-sha256</code> and cannot be retrieved after initial generation—they can only be regenerated through the API. This would need to be submitted as a feature request.</p>
</li>
<li>
<p dir="auto"><strong>JWT authentication for the generate endpoint</strong>: The generate recovery codes endpoint (<code>POST /api/user/two-factor/recovery-code/{userId}</code>) currently only supports API key authentication. There is no JWT authentication variant available, and nothing in the current documentation or public roadmap indicates one is planned.</p>
</li>
</ol>
<p dir="auto"><strong>Recommended approach</strong>: Submit feature requests for both capabilities through the <a href="https://github.com/FusionAuth/fusionauth-issues" rel="nofollow ugc">FusionAuth GitHub Issues repository</a>. These features could be valuable for self-service MFA management scenarios. Note that feature requests, if accepted, do not have guaranteed timelines for implementation.</p>
<p dir="auto"><strong>Current workarounds</strong>: You would need to implement this functionality in your own application with server-side code that uses an API key to call the generate recovery codes endpoint, though this moves the functionality outside the hosted pages where other MFA management occurs. When new codes are generated, all existing recovery codes are invalidated and replaced with a new set of 10 codes.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/multi-factor-authentication#recovery-codes" rel="nofollow ugc">Multi-Factor Authentication (MFA) - Recovery Codes</a> - Overview of how recovery codes work in FusionAuth</li>
<li><a href="https://fusionauth.io/docs/apis/two-factor/generate-recovery-codes" rel="nofollow ugc">Generate Recovery Codes API</a> - API endpoint documentation for programmatic recovery code generation</li>
<li><a href="https://fusionauth.io/docs/lifecycle/manage-users/account-management/" rel="nofollow ugc">Self-Service Account Management</a> - Documentation on the hosted account pages and available features</li>
<li><a href="https://fusionauth.io/docs/lifecycle/manage-users/account-management/customizing-account-management" rel="nofollow ugc">Customizing Self-Service Account Management</a> - Guide for customizing hosted account page templates</li>
<li><a href="https://fusionauth.io/docs/apis/authentication" rel="nofollow ugc">API Authentication</a> - Documentation on API key and JWT authentication methods</li>
<li><a href="https://fusionauth.io/blog/announcing-fusionauth-1-68#hashed-recovery-codes" rel="nofollow ugc">FusionAuth 1.68 Release Notes - Hashed Recovery Codes</a> - Information about recovery code hashing security enhancement</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8648</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8648</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Mon, 28 Sep 2026 16:06:31 GMT</pubDate></item></channel></rss>