Back up your 2FA codes — and switch phones without panic

Guide · updated August 2026

Two-factor authentication protects your accounts right up until the phone holding the codes is lost, stolen, or dead — then it locks you out. Most people discover this at the worst possible moment. It is entirely preventable with two minutes of setup.

Option 1 — An encrypted backup file you own

KeyNesta exports your whole vault as a single encrypted file: every secret, name, group, and note, sealed with AES-256-GCM under a key derived from your passphrase. The encryption happens before the file exists, so it is safe to store anywhere — a drive, your notes, cloud storage — because without the passphrase it is indistinguishable from random noise.

Option 2 — Zero-knowledge sync

Enable sync and your vault lives on every device you sign in on, kept consistent automatically. Each entry is encrypted on your device before upload; the server stores ciphertext plus sync bookkeeping (IDs, versions, timestamps) and nothing else. Your vault passphrase never leaves your devices — which also means a synced copy is not a weaker copy.

Moving to a new phone, step by step

  1. Before the old phone goes anywhere: make a fresh encrypted backup, or confirm sync is on and green.
  2. Install KeyNesta on the new phone (or just open the web app).
  3. Restore the backup file, or sign in to sync — then unlock with your vault passphrase.
  4. Spot-check codes against the old device for your critical accounts.
  5. Wipe the old phone as you normally would. Done — no account-recovery marathons.

The one rule that matters

Zero-knowledge means nobody can reset your passphrase — not support, not anyone. That is what makes the backups trustworthy, and it makes the passphrase itself the thing to protect: keep it in a password manager, or written down somewhere genuinely safe. Everything else is recoverable.

Try KeyNesta free — the web app needs no sign-up.

Open the web app All platforms