FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    How can users regenerate MFA recovery codes on hosted account pages?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    mfa recovery-codes hosted-pages two-factor jwt
    1
    2
    50
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      We want to allow users to self-service the regeneration of their MFA recovery codes. The API endpoint for generating recovery codes (POST /api/user/two-factor/recovery-code/{userId}) exists, but there appears to be no way to invoke it from the hosted theme pages.

      Specific issues:

      • The hosted account pages have no route for recovery code regeneration
      • There is no corresponding template in the theme set to customize
      • The generate endpoint requires API key authentication only (no JWT option), so it cannot be called directly from the browser

      Placing this functionality on our own website doesn't seem ideal since all other MFA management lives on the FusionAuth hosted pages. We considered using a custom block on the hosted two-factor page, but this requires workarounds that could introduce security concerns.

      Are there any current or planned solutions for:

      1. Recovery code regeneration within hosted account pages (ideally as a themeable template alongside existing accountTwoFactor templates)?
      2. A JWT-authenticated variant of the generate recovery codes endpoint to simplify browser-based implementation?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        Currently, FusionAuth does not support recovery code regeneration within the hosted account pages, and there are no plans on the public roadmap for this feature.

        Regarding your specific questions:

        1. Hosted account page support: There is no current support for recovery code regeneration as a themeable template in the hosted account pages. Recovery codes are only generated and displayed when a user first enables an MFA method. As of version 1.68.0, recovery codes are hashed at rest using salted-pbkdf2-hmac-sha256 and cannot be retrieved after initial generation—they can only be regenerated through the API. This would need to be submitted as a feature request.

        2. JWT authentication for the generate endpoint: The generate recovery codes endpoint (POST /api/user/two-factor/recovery-code/{userId}) currently only supports API key authentication. There is no JWT authentication variant available, and nothing in the current documentation or public roadmap indicates one is planned.

        Recommended approach: Submit feature requests for both capabilities through the FusionAuth GitHub Issues repository. These features could be valuable for self-service MFA management scenarios. Note that feature requests, if accepted, do not have guaranteed timelines for implementation.

        Current workarounds: You would need to implement this functionality in your own application with server-side code that uses an API key to call the generate recovery codes endpoint, though this moves the functionality outside the hosted pages where other MFA management occurs. When new codes are generated, all existing recovery codes are invalidated and replaced with a new set of 10 codes.

        Related Documentation

        • Multi-Factor Authentication (MFA) - Recovery Codes - Overview of how recovery codes work in FusionAuth
        • Generate Recovery Codes API - API endpoint documentation for programmatic recovery code generation
        • Self-Service Account Management - Documentation on the hosted account pages and available features
        • Customizing Self-Service Account Management - Guide for customizing hosted account page templates
        • API Authentication - Documentation on API key and JWT authentication methods
        • FusionAuth 1.68 Release Notes - Hashed Recovery Codes - Information about recovery code hashing security enhancement

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Hidden
        • danD dan moved this topic from Q&A
        • danD dan moved this topic from Frequently Asked Questions (FAQ)
        • danD dan moved this topic from Q&A
        • First post
          Last post