MFA recovery codes
When two-factor authentication (MFA) is activated, Schoolysoft generates 8 single-use recovery codes. These codes are your safety net if you lose access to your authenticator (TOTP) app.
They are shown only once, at the moment they are generated: during the MFA step of institution creation, or when MFA is activated on an existing account.
Recommended storage
Important: store these codes somewhere safe, away from your usual computer or phone. Anyone who obtains these codes can access your account.
Storage options:
- Paper printout in a safe or locked drawer.
- Password manager (1Password, Bitwarden, etc.).
- Encrypted file on a backup drive.
Do not store them in your e-mail inbox or in an unencrypted document on your computer.
What these codes are for
A recovery code proves your identity if you lose access to your authenticator app (lost phone, app uninstalled, etc.). Entering a recovery code is not currently available on the login page. If you lose access to your authenticator, contact support or your institution’s administrator, who can start the account recovery process.
Each code can only be used once.
Regenerating recovery codes
From My account, in the Recovery codes section:
- Click the regenerate button and confirm.
- The previous codes are invalidated immediately — a new batch of 8 codes is generated.
- Save the newly displayed codes (a download option is available) before leaving the page: they will never be shown again afterwards.
There is no remaining-codes counter in the interface: regenerate your codes as soon as you are no longer sure you have a valid one left, or right after using one.