A password manager is useful only while you can reach it and understand what happens when a device, authenticator or master passphrase is unavailable. Recovery planning separates several different problems so that one missing item does not lead to rushed guesses or unsafe sharing.
Start here
Separate the recovery questions
Write a non-secret plan for what you would do if you lost the device, the authenticator, the master passphrase or access to the account email.
Name each dependencySeparate the master passphrase, account email, multi-factor method and device access instead of treating them as one recovery item.Read this part
Store recovery material sensiblyKeep important recovery information available outside the vault and never share it casually.Read this part
Rehearse without resettingPractise finding the provider's official instructions and checking your device-change plan without locking yourself out.Read this part
Separate the parts
The master passphrase unlocks the manager, while the account email identifies the account. Multi-factor authentication adds another check, often through an authenticator app, security key or other method. Access to the phone or computer is a separate dependency again.
Write down a non-secret description of these dependencies and the provider you need to contact. Do not put the master passphrase, verification codes or recovery codes in a shared message or ordinary notes app.
Do not assume that the provider can reveal a forgotten master passphrase. Read the provider's current official recovery options while you can still sign in, and note which choices require a previously registered device or method.
Keep a separate recovery path
Recovery material should be available if the vault or its main device is lost. Keeping every recovery detail only inside the vault creates a circular problem. Store it in a place that is protected from casual access but available to you when the main device is unavailable.
Do not share recovery codes, master passphrases or authentication codes with a helper, caller or message recipient. A person offering urgent recovery assistance cannot prove they are trustworthy merely by knowing details about your account.
Consider what happens when you replace a phone or lose an authenticator. Check the official account and device-change instructions before the change, and keep the old method available until the new one is confirmed where the provider permits this.
Rehearse the plan safely
Rehearse by finding the provider's official recovery instructions, checking the account email and confirming which devices and authentication methods are currently registered. Practise the sequence on paper or in a non-secret checklist rather than deliberately signing out everywhere or resetting working security controls.
Review the plan after a phone change, email change or major account change. Make sure you know where your recovery material is kept and who, if anyone, is authorised to help with the physical device. Never send secrets to test whether a recovery channel works.
If you suspect active compromise, unauthorised access or a scam, stop experimenting with recovery and use the guidance at Suspected scam: first steps.
Replacing your phone? Include authenticator access in your new-device checks.
What to read next
If you’d rather have local help, see our password safety and control help.