I no longer have my Two-Factor device and/or backup code
If you have lost the device or backup code for two-factor authentication, you can regain access to your account using your backup code, or contact our support team to verify your identity and disable 2FA temporarily. Once you are back in, you can set up two-factor authentication again with a new device.
Click “Login using Backup Code” on the Two-Factor prompt at portal.hostworld.uk if you still have your 16-character backup code. If you do not, open a support ticket so we can verify your identity and disable 2FA on your user, then you can log in and set it up again.
Before you start
- Your Hostworld account email address. You will need this for password resets and ticket replies.
- Your 16-character backup code, if you still have it.
Step 1: Log in with your backup code
This uses the one-time backup code WHMCS gave you when you enabled Two-Factor Authentication. After you use it, WHMCS shows a new code you must save before you continue.
- Go to portal.hostworld.uk and log in with your email address and password.
- On the Two-Factor prompt, click “Login using Backup Code”.
- Enter your 16-character alphanumeric backup code in full. It is four groups of four characters. Click Login.
- WHMCS will display a new backup code. Save it now before you proceed. It is shown once and replaces the old one.
- If your authenticator device is lost or replaced, go to My Details > Change Security Settings, disable Two-Factor Authentication, then enable it again to pair a new device. Save the new backup code. This is the undo step: you can turn 2FA off here if you need to, then turn it back on.
Step 2: If you do not have the backup code, ask us to disable 2FA
If you have lost both the device and the backup code, we need to turn 2FA off for your user so you can get back in.
- Open a support ticket. Say you have lost both your Two-Factor device and backup code.
- We will verify your identity, then disable 2FA for your user from our Admin Area.
- When we confirm, log in at portal.hostworld.uk with your email and password.
- Go to My Details > Change Security Settings and enable Two-Factor Authentication again. Save the new backup code. This is the undo step after we turned 2FA off.
Step 3: If you have also forgotten your password
Password resets do not bypass 2FA. Reset the password first, then use Step 1 or Step 2 for the second factor.
- On portal.hostworld.uk, click Forgotten Password and follow the email to set a new password.
- Log in with the new password. When prompted for Two-Factor, either use “Login using Backup Code” or open a support ticket so we can disable 2FA if you have no code.
If it does not work
- Wrong code type: the backup route needs the 16-character code, not a 6-digit app code. Enter all 16 characters with no spaces.
- No new backup code saved: if you logged in with a backup code and did not save the new one, go to My Details > Change Security Settings and disable then re-enable 2FA to generate a fresh backup code. If you have already logged out and are locked out again, open a support ticket.
- Password reset loop: resetting your password will not remove 2FA. Use the backup code, or ask us to disable 2FA as in Step 2.
What next
After you are back in, make sure Two-Factor Authentication is enabled and that you have saved the new backup code. If you were logging in to manage servers, you may find our VPS guides useful. If you are planning your next deployment, review our London VPS options.
Common questions
What do I do if I have lost my two-factor device?
If you still have your 16-character backup code, use it to log in. If you have lost both the device and the backup code, open a support ticket so we can verify your identity and disable 2FA temporarily.
Can I use a 6-digit code from my authenticator app instead of the backup code?
No. The backup route requires the full 16-character backup code, not a 6-digit app code. Enter all 16 characters with no spaces.
What happens after I log in with my backup code?
WHMCS will display a new backup code that you must save before proceeding. This new code replaces the old one.
How long does it take for support to disable two-factor authentication?
After we verify your identity, we disable 2FA from our Admin Area. Once we confirm, you can log in and re-enable two-factor authentication with a new device.
Can I reset my password if two-factor authentication is locked?
Yes, but password resets do not bypass 2FA. Reset your password first, then use your backup code or contact support to disable 2FA if you have no code.
Was this article helpful?
0 people found this helpful