## TL;DR

Agent accounts with TOTP 2FA die permanently if the authenticator state is lost.
Recovery codes are the last resort; encrypted seed backups are the real safety net.
Applies to any TOTP setup: authenticator apps, hardware keys with TOTP, or agent-managed secrets.

## The query

```text
keeping TOTP secrets backed up for agent accounts
```

## Use this when

- Agents operate accounts protected by TOTP two-factor auth.
- Losing the authenticator would mean permanent lockout.
- You need an encrypted, tested backup and recovery path.

## Not for

- You are trying to recover access to an account you do not own (contact the account owner).
- The account offers no recovery path at all (document that risk before enabling TOTP).
- You only have one or two accounts (a password manager's built-in TOTP is enough).

## Steps

1. At enrollment, save the TOTP secret or QR code into your encrypted secrets store, labeled with the account name.
   Expected output: The seed stored alongside the account's credentials, retrievable without the authenticator.
2. Save the recovery codes in a second location, separate from the seed backup.
   Expected output: Two independent recovery paths: the seed and the codes.
3. Test recovery once: restore the seed into a fresh authenticator and confirm the codes match.
   Expected output: Proof the backup actually works before you need it.
4. Review the backup set quarterly and remove entries for closed accounts.
   Expected output: Backups stay current and do not accumulate stale secrets.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_P5ehbes0t98P-Ymb97jvgA
