🗂️ 2FA Backup Code Validator
Paste your two-factor authentication backup/recovery codes (one per line) to check their format consistency, count and for duplicates before you save or print them. This runs entirely in your browser — nothing is uploaded anywhere.
What the four rows are counting
Lines are trimmed, blanks dropped, and each remaining line reduced to a shape:
lowercase becomes a, uppercase A, digits 0,
anything else stays as itself. Length is counted after punctuation is stripped:
1a2b-3c4d -> shape 0a0a-0a0a, length 8
AB12 CD34 -> shape AA00 AA00, length 8
Typical Length and Typical Format are simply the most frequent of each, so a set is flagged as inconsistent the moment two shapes appear. On a tie the shorter length is reported.
Getting a clean read
- Paste codes only. List numbering, a heading or a trailing note each become their own line and will show up as an odd shape.
- The duplicate test compares whole lines, case-insensitively. Two copies of the same code written differently - one with the hyphen, one without - are not caught, because the strings differ.
- Punctuation is ignored for length but kept in the shape - which is how a misplaced hyphen is spotted even though both halves still count as 8.
Frequently asked questions
Can this tell me whether my backup code still works?
No. Validity lives on the provider's server, and a one-time code is proven good only by using it. All this confirms is that you transcribed a complete, consistent set with no repeats.
What does a 2FA backup code normally look like?
Most providers use either an 8-digit block or two five-character alphanumeric groups split by a hyphen, and issue eight to sixteen of them at once. Whatever the shape, every code in one set matches the others exactly.
Is it safe to paste recovery codes into a web page?
Here yes, because there is no network call and nothing is retained. It is still a habit worth keeping rare: elsewhere a pasted set can be logged server-side, and these codes bypass your second factor entirely.