{
  "id": 56885,
  "title": "GitLab 2FA Lockout: How My Local SSH Key Saved the Day",
  "url": "https://urgent.news/2026/08/02/gitlab-2fa-lockout-how-my-local-ssh-key-saved-the-day",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-02T21:06:02.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/letstalkoss/gitlab-2fa-lockout-how-my-local-ssh-key-saved-the-day-5g4d"
  },
  "original_language": "en",
  "account": "Two-factor authentication (2FA) is a security measure that requires users to provide two forms of identification when logging into an account. One such user experienced a lockout on their GitLab account after attempting to change the backup password using their authenticator app. Stranded without access, they had to disable 2FA and re-enable it using a different app.\n\nWhile re-enabling 2FA proved straightforward since they were still logged into most of their accounts, the user found themselves in a predicament when they realized they did not have their GitLab recovery codes. GitLab provides two methods to retrieve access: either via email or by generating new recovery codes using an SSH key linked to the account. The latter option proved to be a lifesaver for this individual.\n\nWhen setting up GitLab in their local environment, the user always creates an SSH key for authentication and commit signing. They documented this process in a previous article. To obtain new recovery codes without an email verification code, the user must check the SSH keys on their machine. By listing files in the ~/.ssh directory, they identified key files such as id_rsa or id_ed25519.\n\nTo generate new recovery codes, the user executed the command \"ssh -i ~/.ssh/id_ed25519 git@gitlab.com 2fa_recovery_codes\". They replaced \"id_ed25519\" with the name of their SSH key file. Once they had copied a recovery code, they signed in using their username and password, entering the recovery code when prompted. Now back in their GitLab account, they disabled 2FA and re-enabled it, ensuring they saved the recovery codes in a secure location for future reference.",
  "summary": "I have two-factor authentication (2FA) enabled on most of my accounts using an authenticator app. Recently, while installing the app on another Android device, I tried to change the backup password, but it didn't work. As a result, I lost access, had to disable 2FA, and re-enable it using a different authenticator app. Setting up 2FA again wasn't a problem because I was still logged in to most of…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}