Rotating recovery codes, app passwords, and tokens is one of the simplest ways to prevent old credentials from becoming a backdoor into your accounts. But doing it ad hoc can cause lockouts, broken automations, and lost access during emergencies. This guide shows you how to design a simple maintenance calendar, what to rotate and when, and how to verify each step safely so you protect your identity without disrupting your life.
Why Rotation Matters (and What You’re Rotating)
Old credentials are risky. If a backup code, app password, or token leaks in a breach, gets saved in an old email, or sits on a retired laptop, an attacker might use it months later. Regular rotation limits the window of opportunity and helps you confirm your backups actually work.
Here’s what we’re rotating and why:
- Recovery codes: One-time printable codes from services like Google, Apple, Microsoft, and password managers. They bypass your second factor in emergencies. If exposed, they can grant access to your account.
- App passwords: Service-specific passwords used for older email clients, calendaring apps, smart devices, or automation tools that don’t support modern sign-in. They’re often long-lived and forgotten.
- Tokens: Includes TOTP seeds (authenticator-app tokens), API tokens, personal access tokens, and session-less tokens for services and developer tools. Stale tokens are a common breach path.
Design a Safe Rotation Cadence
Pick a manageable rhythm that you can follow consistently. More frequent isn’t always better if it leads to errors or skipped steps.
- Quarterly: Rotate recovery codes, app passwords, and high-privilege tokens.
- Monthly: Rotate tokens and app passwords for financial, email, cloud storage, and password-manager-related accounts.
- Weekly (lightweight): Review the next scheduled items, archive last week’s confirmations, and handle one small rotation task to keep momentum.
For most people, a monthly token/app-password check plus a quarterly recovery-code refresh strikes a good balance.
Set Up Your Maintenance Calendar
Use any calendar you trust (Google Calendar, Apple Calendar, or a privacy-focused calendar). Create recurring events and attach a checklist. Keep time blocks realistic—30–60 minutes is typical.
- Create three recurring events:
- “Quarterly Recovery Codes Refresh”
- “Monthly App Password and Token Review”
- “Weekly Security Touchpoint” (10–15 minutes)
- Add a consistent time slot: Example: first Saturday morning of the month for monthly reviews; first weekend of each quarter for recovery codes.
- Include pre-reads: In the calendar description, list the accounts you’ll cover and links to their security pages (e.g., “Google My Account > Security,” “Apple ID > Sign-In & Security,” “Microsoft Account > Security”).
- Attach your rotation checklist: Paste the steps (below) into the event description so they’re always handy.
Preparation: Inventory and Access
Before the first rotation cycle, build a quick inventory and confirm you can reach every account you plan to update.
- Inventory your accounts: Start with your password manager’s list. Flag:
- Email providers (primary and recovery mailboxes)
- Cloud storage and device backups
- Password manager account
- Banking/financial, tax, mobile carrier
- Social, marketplace, and work-related accounts
- Map your 2FA: Note which accounts use TOTP (authenticator app), SMS, security keys (WebAuthn), or passkeys.
- Identify where recovery codes live: Password manager secure note, printed copy in a safe, or both.
- Ensure two-device access: Have at least two signed-in devices (e.g., phone and laptop) to avoid lockouts during changes.
- Enable offline access where possible: Download authenticator recovery or ensure your password manager works offline if you lose connectivity mid-rotation.
Rotation Principles That Prevent Lockouts
- Change one class at a time: For example, refresh recovery codes this week, app passwords next week, tokens the following week.
- Verify on two devices before deleting old credentials: After adding new codes or tokens, confirm you can sign in on a second device or private browser session.
- Never rotate everything for a “root” account at once: For your primary email, password manager, or cloud identity, split changes across days to preserve a fallback.
- Keep a time-limited overlap: For app passwords and tokens, maintain both old and new for a few minutes while you swap them in dependent apps, then immediately revoke the old one.
- Label clearly in your password manager: Include the service name, device/app purpose, and creation date.
How to Rotate Recovery Codes Safely
- Locate the recovery-code page: Sign in to the account’s security settings and find “Recovery codes” or “Backup codes.”
- Generate new codes but don’t delete the old yet: Download, copy, or print new codes. Store them in your password manager as a secure note and, if you prefer, print a copy for a fireproof safe.
- Validate access: On a second device or private browsing window, sign in using a normal second factor (not the codes) to confirm your MFA still works.
- Retire the old codes: When the service allows, “replace” or “regenerate” codes. If it only shows new ones, ensure the old set is invalidated. Destroy physical copies of the old set.
- Record the date: Add the rotation date to the secure note title or body for easy tracking.
Tip: If multiple services share the same identity provider (like your email), refresh that provider’s codes on a different day than other high-stakes accounts.
How to Rotate App Passwords Without Breaking Things
App passwords are commonly used for older IMAP/SMTP email clients, calendar sync, and automation tools. Replace them gradually and revoke the old one once each app is updated.
- List active app passwords: In each account’s security page, find “App passwords,” “App-specific passwords,” or “Connected apps/devices.”
- Rotate one app at a time: Create a new app password with a clear label like “iPhone Mail – Sep 2026.”
- Update the client immediately: Paste the new password into the app’s settings and confirm it syncs.
- Revoke the old app password: Remove it from the service’s security page to eliminate overlap.
- Repeat for each device/app: Track progress in your calendar event notes.
Warning: Some services bundle multiple apps under one app password. If so, be ready to update all affected apps before revoking the old credential.
How to Rotate Tokens and TOTP Seeds
Tokens include developer and personal access tokens (for APIs and services), and TOTP seeds used by authenticator apps.
Personal Access Tokens (APIs and services)
- Inventory tokens and scopes: Note which services use tokens (e.g., cloud providers, developer platforms, storage, automation). Record purpose and scopes (read-only vs. admin).
- Create a new token with minimum necessary scope: Prefer the least privilege that still allows the app to function.
- Swap tokens in dependent apps: Update environment variables, integrations, or app settings.
- Test functionality: Run a quick action (sync, upload, API request) to confirm success.
- Revoke the old token: Immediately remove the previous token to prevent reuse.
TOTP Seeds (Authenticator Apps)
You don’t need to rotate TOTP codes themselves, but you may periodically re-enroll TOTP if you suspect the seed was exposed or to migrate between authenticators.
- Add a second factor method first: Ensure a backup method (security key or another TOTP device) is active before re-enrolling.
- Re-enroll TOTP on your primary authenticator: In the account’s security settings, remove TOTP only after you successfully add a new one.
- Add a backup authenticator: Many services allow multiple TOTP devices; add a second device or backup phone stored securely.
- Verify sign-in from another browser: Confirm both authenticators work before removing any old device.
Consider upgrading to security keys or passkeys (WebAuthn) for critical accounts. They’re phishing-resistant and reduce risks tied to SMS or reused TOTP seeds.
The Rotation Checklist (Copy Into Your Calendar)
- Prepare two signed-in devices and confirm you can receive second factors.
- Open the service’s security page and password manager entry.
- Generate new recovery codes/app password/token but don’t revoke old yet.
- Update any dependent apps or devices immediately.
- Test sign-in or function in a separate browser/device.
- Revoke the old credential and save the new entry with a clear label and date.
- Update your inventory note and mark the calendar task complete.
Labeling, Storage, and Documentation
Clear labeling prevents confusion months later and speeds up troubleshooting.
- Use specific names: “Gmail – App Password – Mac Mail – Sep 2026” is better than “Gmail app pass.”
- Centralize in your password manager: Store app passwords and tokens in item notes with purpose, scopes, and last-rotated date.
- Physical backups for recovery codes: If you print, keep in a fireproof safe. No photos on your phone.
- Avoid email for storage: Don’t email recovery codes or tokens to yourself; email inboxes are common breach targets.
Staggering High-Risk Accounts
Certain accounts anchor your digital identity. Rotate them on separate days to preserve a safety net.
- Primary email account(s): The gateway to most password resets.
- Password manager account: Protects all other credentials.
- Cloud identity/phone carrier: Affects device recovery and SIM-related risks.
- Financial accounts: Banks, brokerage, and payment platforms.
Rotate one anchor account per week and always confirm emergency access before revoking any old method.
What to Do Before and After a Breach Notice
If a service you use announces a breach or you receive a legitimate alert that your credentials may be exposed, accelerate rotation.
- Change the account password immediately and sign out all sessions if the service offers it.
- Rotate recovery codes and tokens as soon as practical.
- Review connected apps and revoke anything you don’t recognize.
- Monitor for unusual sign-ins and enable additional alerts (email and mobile push).
Automations and Safety Nets
- Calendar alerts: Set two reminders per event (one day before and at start time).
- Password manager tags: Tag items with “Rotate-Monthly,” “Rotate-Quarterly,” and filter during each session.
- Device health check: During your weekly touchpoint, update OS and app patches—outdated software undermines good rotation hygiene.
- Sign-in alerts: Enable new-device and new-login notifications for critical accounts so you detect suspicious activity between rotations.
Common Pitfalls (and How to Avoid Them)
- Rotating too much at once: Leads to lockouts. Space changes over days/weeks.
- Deleting old credentials before testing: Always validate the new method first on a second device.
- Forgetting dependent apps: Keep a list of devices and services that rely on each app password or token.
- Storing codes in email or notes apps: Use a password manager and, for printed codes, a secure physical location.
- Ignoring scope minimization for tokens: Grant only what the integration needs.
When to Involve Monitoring and Alerts
Even with good rotation hygiene, you may not catch every exposure. Credit and identity-related monitoring adds another layer—especially for financial and account-takeover risks. If you’ve recently rotated credentials after a breach, changed phone numbers, or cleaned up exposed information, consider adding continuous monitoring to catch early signs of fraud or misuse.
For a simple way to watch for changes that may affect your financial identity and to centralize alerts, see our overview of privacy, credit monitoring, and identity-protection tools.
A Simple Starter Schedule
Use this if you’re beginning from scratch:
- Week 1: Refresh recovery codes for primary email and password manager. Verify on two devices. Store codes securely.
- Week 2: Rotate app passwords for email/calendar clients on all devices. Revoke old entries.
- Week 3: Rotate tokens for cloud storage, note-taking, and any connected automation. Test and revoke old tokens.
- Week 4: Catch-up and documentation: update labels, notes, and set next month’s focus on financial and carrier accounts.
- Quarterly: Repeat Week 1 across all major services; audit connected apps and remove any you don’t use.
FAQ
How often should I rotate recovery codes?
Quarterly is a good default, or immediately after a breach, device loss, or major account change. Rotate more frequently for high-risk accounts.
Do I need to rotate app passwords if I switch to modern clients?
If you stop using an app password, revoke it. For remaining legacy apps, rotate monthly or quarterly depending on sensitivity.
What if an account doesn’t support multiple authenticators?
Add or confirm a different backup method (like recovery codes or a security key) before you remove the old one. If that’s not possible, schedule the change when you have direct access to support and are on two signed-in devices.
Should I rotate passkeys or security keys?
You don’t rotate passkeys like passwords, but you should periodically review and remove keys you no longer use and add a backup key stored securely.
Conclusion
Setting a maintenance calendar transforms credential rotation from a stressful chore into a predictable, low-risk routine. Start by scheduling small, focused sessions, rotate one class of credentials at a time, verify on two devices, and document everything in your password manager. Over time, these habits close lingering backdoors, reduce lockout risk, and keep your recovery paths reliable when you need them most. If you want added protection against the fallout of identity misuse, pair your rotation plan with ongoing monitoring so you can spot issues quickly and act with confidence.
Good to Know
Rotate one class of credentials per week and verify access on at least two devices before deleting old codes. This minimizes disruption while keeping your accounts protected.