Show HN: RecoveryCodes – MFA inventory for auth outside IdPs

CER10TY2 pts1 comments

RecoveryCodes · MFA continuity for accounts outside your IdP

Get started

FOR ACCOUNTS OUTSIDE YOUR IDP<br>The MFA inventory your IdP doesn't have.<br>Okta and Entra cover federated apps. Your vault stores secrets. Neither maps the root<br>accounts, registrars, banks, and vendor portals to the devices and recovery codes that<br>unlock them.<br>Get started → See how it works<br>14 DAY FREE TRIAL · NO CREDIT CARD REQUIRED

RecoveryCodesSecurity keyPassword appPasskeyAuthenticatorSMSBackup codes

Made and hosted in EU<br>All data stored in the EU<br>KMS wrapped encryption keys<br>No TOTP seeds stored

00  THE PROBLEM<br>Your IdP and password manager only see part of MFA.<br>Okta and Entra cover federated apps. Your password vault stores secrets. Neither tells you<br>which bank portal, registrar, root account, founder account, or vendor portal depends on a<br>specific phone or security key.

01 Unmanaged accounts sit outside reports<br>Root accounts, registrars, banks, vendor portals, and founder accounts rarely live in<br>the same identity report. The map exists in memory, chat, and old tickets.

02 A password vault is not an MFA map<br>Your vault stores secrets. It does not tell you what a lost YubiKey unlocks, or which<br>services depend on one phone.

03 Offboarding leaves blind spots<br>A departing employee may hold the only authenticator for accounts the company owns.<br>Revoking access before you transfer MFA can create the outage you were trying to<br>avoid.

01  WHAT IT DOES<br>Accounts, authenticators, recovery codes, and evidence in one inventory.

ACCOUNTS & ENROLLMENTS<br>Every account, with the authenticators assigned to it.<br>Add the services that matter outside your identity provider and see which authenticators<br>protect each one. One account can have several authenticators, and one authenticator can<br>protect many accounts.<br>✓ Unlimited accounts, authenticators,<br>and assignments<br>✓ Best practice default:<br>2 MFA devices per domain, adjustable<br>✓ Clear status: protected,<br>one device risk, or no 2FA yet<br>✓ Record upstream identity<br>providers and SSO chains

01trello.comNO 2FA02github.comPROTECTEDPersonal security keyPrimary phone (SMS)03nextcloud.comNEEDS 1 MORE DEVICEPersonal security key

RECOVERY CODES<br>Recovery codes without shared TOTP seeds.<br>RecoveryCodes stores recovery codes for a domain. It does not store TOTP seeds or generate<br>shared login codes, so it is an inventory and emergency record, not another team<br>authenticator app.<br>✓ Codes stay separate from<br>the password vault<br>✓ Share selected domains<br>with approved workspace members<br>✓ Every reveal requires step-up<br>authentication and audit logging

01efgh-5678UNUSED02ijkl-9012UNUSED03mnop-3456USED 2026-06-09 12:08

DEVICES & REVERSE LOOKUPS<br>Replacing security key 1? These are the 14 accounts to enroll again.<br>Each authenticator has a name, kind, owner, and optional physical location. When a phone,<br>hardware key, or backup phone leaves service, you get the exact list of accounts to fix<br>before you disable it.<br>✓ Personal authenticators<br>for one person, shared authenticators for the whole team<br>✓ Reverse lookup: every account<br>an authenticator protects, in one click

01TOTP appTOTPASSIGNED TO 3 ACCOUNTS02Personal security keyYUBIKEYASSIGNED TO 5 ACCOUNTS

02  THE AUDIT<br>Evidence for the accounts your IdP cannot report.<br>Security reviews and ISO 27001 audits ask how you manage MFA outside the identity<br>provider. What protects each account? What happens when someone leaves? Where do recovery<br>codes live, and who accessed them? Export inventory and audit evidence instead of assembling<br>it from memory.

01<br>MFA coverage report<br>Every account, its 2FA status, and every authenticator enrolled on it. The concise answer<br>to "show us your MFA coverage."

02<br>One device risks<br>Accounts protected by only one authenticator. No account should be one lost phone away<br>from a lockout.

03<br>Offboarding attestation<br>Every authenticator a departing user held and every account it was enrolled on. Proof that<br>access was transferred before the account was removed.

04<br>Access and change log<br>A log of who viewed recovery codes, changed enrollments, updated devices, or shared access<br>to a domain. The raw trail behind every report.

03  TRUST<br>How the recovery material is protected.<br>Recovery codes can bypass MFA, so the product has to be explicit about what it stores, what<br>it does not store, and what you can take with you.

01<br>Envelope encryption per code<br>Recovery code values are encrypted with per code data keys. Those keys are wrapped by KMS<br>infrastructure in the EU.

02<br>No TOTP seed vault<br>RecoveryCodes records which authenticators protect which accounts. It does not hold TOTP<br>seeds or act as a shared code generator.

03<br>Continuity and export<br>Export the inventory and audit evidence as JSON from the dashboard. Recovery code values<br>stay view only behind step-up authentication, so the emergency story is explicit rather<br>than implied.

04<br>Fresh sign in for sensitive actions<br>Viewing a recovery code, changing an assignment, or deactivating a user requires fresh<br>authentication....

accounts recovery codes account authenticator authenticators

Related Articles