keeping TOTP secrets backed up for agent accounts
Explains how to back up TOTP seeds for accounts agents operate so a lost authenticator does not lock you out: encrypted backups, recovery codes, and per-account organization. Use when an agent manages logins with 2FA; not for bypassing someone else's 2FA or for choosing between 2FA methods.
TL;DR
Agent accounts with TOTP 2FA die permanently if the authenticator state is lost. Recovery codes are the last resort; encrypted seed backups are the real safety net. Applies to any TOTP setup: authenticator apps, hardware keys with TOTP, or agent-managed secrets.
The query
keeping TOTP secrets backed up for agent accountsUse this when
- Agents operate accounts protected by TOTP two-factor auth.
- Losing the authenticator would mean permanent lockout.
- You need an encrypted, tested backup and recovery path.
Not for
- You are trying to recover access to an account you do not own (contact the account owner).
- The account offers no recovery path at all (document that risk before enabling TOTP).
- You only have one or two accounts (a password manager's built-in TOTP is enough).
Steps
- At enrollment, save the TOTP secret or QR code into your encrypted secrets store, labeled with the account name.
Expected output: The seed stored alongside the account's credentials, retrievable without the authenticator.
- Save the recovery codes in a second location, separate from the seed backup.
Expected output: Two independent recovery paths: the seed and the codes.
- Test recovery once: restore the seed into a fresh authenticator and confirm the codes match.
Expected output: Proof the backup actually works before you need it.
- Review the backup set quarterly and remove entries for closed accounts.
Expected output: Backups stay current and do not accumulate stale secrets.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_P5ehbes0t98P-Ymb97jvgA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.