Lost access to your two-factor authentication
Three ways back into your account if you can’t get a code from your authenticator app.
Reviewed regularly to match the current app.
Overview
If you can’t open your authenticator app — phone lost, app deleted, device wiped, or you switched phones without exporting — there are three ways back into your account. They get more involved as you go down the list. Try them in order.
- Path 1 — You have a backup code. Fastest. You sign in, disable 2FA, and re-enable it on your new authenticator. About 3 minutes.
- Path 2 — You don’t have backup codes, but your account email still works. You request a 7-day “cool-off” recovery. We email you daily during the wait so the real you can cancel if it wasn’t you. After 7 days, a one-time link removes 2FA from your account.
- Path 3 — You don’t have backup codes and you’ve also lost access to the email on your account. Manual review by support. Slowest. Requires you to prove you’re the real owner with details only you would know.
Two-factor authentication is doing its job — it’s blocking everyone who doesn’t have your authenticator app, including someone trying to take over your account. Every recovery path below exists to let the real you back in without giving an attacker a free pass. The waits and the questions aren’t friction for its own sake; they’re what makes the whole thing safe.
What you’ll need
- For Path 1: One unused backup code. These are the 8-character codes you saved when you first set up 2FA. Check your password manager, Notes app, the email you sent yourself, or a printed copy.
- For Path 2: Access to the email address on your GS Poetry account, and patience for a 7-day window. (Yes, really — see below for why.)
- For Path 3: Some specific things only the real owner of the account would know — a poem you’ve published, the rough month you signed up, a city you’ve recently signed in from, and (if you have a GS Pro subscription) the last 4 digits of the card on file.
Step-by-step
Path 1 — Recover with a backup code
- Go to the sign-in page and enter your email and password as usual. You’ll be prompted for a 6-digit authenticator code.
- Below the code field, click Use a backup code instead. Type one of your unused 8-character codes.
- Once signed in, go to Settings → Account → Security tab → Two-factor authentication and click Disable. You’ll be asked to re-verify (with another backup code or your password — see the security article on step-up verification).
- Open your new authenticator app and follow the standard setup flow: Settings → Account → Security tab → Set up two-factor authentication. Scan the new QR code, enter a 6-digit code to confirm, and save your new backup codes somewhere you’ll actually find them this time — a password manager is the most reliable spot.
- On the old authenticator app (if you can still reach it), delete the GS Poetry entry. This is purely housekeeping — the old code is already useless once you’ve disabled 2FA — but cleaning it up means you won’t accidentally tap the wrong entry next time and wonder why nothing works.
Each backup code can only be used once. If you only had a few left, regenerate a fresh set from Settings → Security after you’ve re-enabled 2FA.
Path 2 — Self-serve recovery (7-day cool-off)
This path is for the most common case: you lost the phone, but the email on the account still works. Here’s what happens.
- On the sign-in page, click Can’t access your authenticator? beneath the code field, then choose I don’t have backup codes.
- Enter the email address on your account. We’ll send a confirmation email to that address — open it and click Start recovery.
- That kicks off a 7-day waiting period. During the wait, we email you every day with a one-tap Cancel recovery link.
- After 7 days, you’ll receive a final email with a one-time unlock link. The link is valid for 24 hours and only removes 2FA — it does not change your password or email. You sign in normally, set up a new authenticator from your new device, and save the fresh backup codes.
If someone else were trying to take over your account through this flow, those daily cancel emails are how you’d catch it — you’d see “Recovery in progress” in your inbox, click cancel, and they’d be locked out. The wait is what protects you. If you’re still signed in on another device when you start recovery, you can also cancel from Settings → Account → Security tab → Active recovery requests.
What about SMS recovery? We don’t offer it. SMS-based recovery can be defeated by a SIM-swap attack, which is one of the most common ways accounts get taken over today. Email + a long cool-off is genuinely safer.
Path 3 — Manual review by support
Use this only if Path 1 and Path 2 are both impossible — typically because you no longer have access to the email on your account either.
- Open the contact form and choose Account recovery — lost 2FA and email as the topic.
- Tell us as much as you can about your account. The more of these you can answer confidently, the faster the review goes:
- Your username or display name on GS Poetry.
- The old email address that was on the account (even if you can’t access it).
- The roughly approximate month and year you signed up.
- The title and a line or two from a poem you’ve published on the account — we cross-check this against your post history. This is the strongest single signal.
- The last city or country you remember signing in from.
- If you’re on a paid plan: the last 4 digits of the card on file.
- A new email address you’d like the account moved to, and confirmation that you have access to it.
- A support agent reviews your answers against our records. If the signals line up, we’ll (a) remove 2FA from the account, and (b) queue an email change to the new address you supplied — with the same 7-day cool-off, announced to your old email. This means a real attacker who guessed enough details still couldn’t silently take the account; the legitimate owner would see the old-email notifications and could block the change.
- Once the cool-off ends, we’ll email the new address with sign-in instructions and a one-time password reset link.
Manual review usually takes 2–5 business days from your first message, plus the 7-day cool-off if an email change is needed. We can’t shorten either window — they’re what keeps social-engineering attacks from working.
What we won’t accept as proof: a screenshot of you holding your phone, a photo of an ID, a friend vouching for you, or a payment we don’t already have on record. We don’t want to hold that kind of personal information, and none of it actually proves you’re the original account owner anyway.
If something goes wrong
- “My backup code doesn’t work.” Backup codes are single-use — if you’ve used this one before, it’s dead. Try a different one. If none of them work, your codes may be from a previous 2FA setup that’s been replaced; move to Path 2.
- “I started Path 2 but want to cancel.” Click the Cancel recovery link in any of the daily emails, or go to Settings → Account → Security tab → Active recovery requests if you’re still signed in elsewhere.
- “I never got the recovery emails.” Check spam, then check that you typed the right email at step 1. If the email on file is wrong, Path 2 won’t work — go to Path 3.
- “Support says my answers don’t match.” We can only act on what’s in our records. If you’re confident in your identity but a detail is off (e.g., the signup year is wrong), reply with corrections — the agent re-reviews.
- “I’ve regained access to my old phone halfway through Path 2.” Cancel the recovery, sign in normally with your authenticator, and you’re done — no need to wait out the cool-off.
- “I deleted the GS Poetryentry from my authenticator before disabling 2FA on the site.” The entry on your phone and the secret on our side are linked — deleting one doesn’t affect the other. You’re effectively in the “lost authenticator” situation; restart from Path 1 (with a backup code) or Path 2.
Where to go next
Once you’re back in, take five minutes to make this easier next time: regenerate your backup codes and save them in a password manager, and confirm the email on your account is one you’ll keep access to. See Setting up two-factor authentication for the full setup walkthrough, or Change your email to update your contact email. Still stuck? Contact support.
