RecoveryCodes · MFA continuity for accounts outside your IdP

RecoveryCodes

5 min read Original article ↗

FOR ACCOUNTS OUTSIDE YOUR IDP

The MFA inventory your IdP doesn't have.

Okta and Entra cover federated apps. Your vault stores secrets. Neither maps the root accounts, registrars, banks, and vendor portals to the devices and recovery codes that unlock them.

14 DAY FREE TRIAL · NO CREDIT CARD REQUIRED

Made and hosted in EU

All data stored in the EU

KMS wrapped encryption keys

No TOTP seeds stored

00  THE PROBLEM

Your IdP and password manager only see part of MFA.

Okta and Entra cover federated apps. Your password vault stores secrets. Neither tells you which bank portal, registrar, root account, founder account, or vendor portal depends on a specific phone or security key.

01

Unmanaged accounts sit outside reports

Root accounts, registrars, banks, vendor portals, and founder accounts rarely live in the same identity report. The map exists in memory, chat, and old tickets.

02

A password vault is not an MFA map

Your vault stores secrets. It does not tell you what a lost YubiKey unlocks, or which services depend on one phone.

03

Offboarding leaves blind spots

A departing employee may hold the only authenticator for accounts the company owns. Revoking access before you transfer MFA can create the outage you were trying to avoid.


01  WHAT IT DOES

Accounts, authenticators, recovery codes, and evidence in one inventory.

ACCOUNTS & ENROLLMENTS

Every account, with the authenticators assigned to it.

Add the services that matter outside your identity provider and see which authenticators protect each one. One account can have several authenticators, and one authenticator can protect many accounts.

  • ✓ Unlimited accounts, authenticators, and assignments
  • ✓ Best practice default: 2 MFA devices per domain, adjustable
  • ✓ Clear status: protected, one device risk, or no 2FA yet
  • ✓ Record upstream identity providers and SSO chains

RECOVERY CODES

Recovery codes without shared TOTP seeds.

RecoveryCodes stores recovery codes for a domain. It does not store TOTP seeds or generate shared login codes, so it is an inventory and emergency record, not another team authenticator app.

  • ✓ Codes stay separate from the password vault
  • ✓ Share selected domains with approved workspace members
  • ✓ Every reveal requires step-up authentication and audit logging

DEVICES & REVERSE LOOKUPS

Replacing security key 1? These are the 14 accounts to enroll again.

Each authenticator has a name, kind, owner, and optional physical location. When a phone, hardware key, or backup phone leaves service, you get the exact list of accounts to fix before you disable it.

  • ✓ Personal authenticators for one person, shared authenticators for the whole team
  • ✓ Reverse lookup: every account an authenticator protects, in one click

02  THE AUDIT

Evidence for the accounts your IdP cannot report.

Security reviews and ISO 27001 audits ask how you manage MFA outside the identity provider. What protects each account? What happens when someone leaves? Where do recovery codes live, and who accessed them? Export inventory and audit evidence instead of assembling it from memory.


03  TRUST

How the recovery material is protected.

Recovery codes can bypass MFA, so the product has to be explicit about what it stores, what it does not store, and what you can take with you.

SIGNING IN

Access to the tool is protected the same way.

Start in seconds with social login and passkeys. When you are ready to centralize identity, organization SSO is available.

All plans

Social login & passkeys

Sign in with Google, GitHub, or GitLab. Or use a passkey on every device.

Google GitHub GitLab Passkey login Face ID / Touch ID Hardware key

Compliance Enterprise

Organization SSO

Connect OIDC on Compliance. Enterprise customers can discuss SAML, SCIM, or LDAP requirements.

OIDC SAML SCIM LDAP


04  PRICING

Pricing by capability.

Free for 14 days · No credit card · No charge when your trial ends

Inventory

Billed annually

Everything operational: see your exposure and stop improvising.

Start free trial

  • ✓ Unlimited account and authenticator inventory
  • ✓ Reverse lookup for every authenticator
  • ✓ Track recovery codes per domain
  • ✓ Status labels: protected, one device risk, no 2FA
  • ✓ Social login & passkey login
  • ✓ Authenticator ownership tracking
  • ✓ Workspace with member roles
  • ✓ Domain and authenticator sharing across the workspace
  • ✓ Coverage and risk report as an in-app view
  • ✓ Audit log (90 days)

For evidence

Compliance

Billed annually

Everything evidentiary: export what auditors and clients ask for.

Start free trial

  • Everything in Inventory, plus
  • ✓ Dated, exportable offboarding attestation
  • ✓ Dated, exportable coverage and risk reports
  • ✓ Extended audit retention
  • ✓ Offboarding workflow before access is removed
  • ✓ OIDC SSO
  • SOON
  • ✓ Email and webhook alerts for risks and sensitive access

Enterprise

Let's talk

Custom contract

Everything contractual: security, deployment, and policy terms.

Contact us

  • Everything in Compliance, plus
  • ✓ Customer managed encryption keys through KMS
  • ✓ SAML, SCIM, and LDAP enforcement
  • ✓ Self hosting option
  • ✓ Defined SLA
  • ✓ Custom data retention policies

All prices exclude tax.

When an authenticator changes, know what to fix.

Start mapping the accounts your IdP cannot explain, the authenticators that protect them, and the recovery codes that get you back in.