# Get back in when you’re locked out

Locked out of WordPress by BetterShield? Use your recovery link or a printed code to pause its protections for an hour and sign in again.

If BetterShield is stopping you from signing in, your recovery link or a printed recovery code pauses its protections for one hour, with nothing deactivated and no setting changed. You manage both under **BetterShield › Protect › Recovery**.

## Use your recovery link

The recovery link is a private address for your site. BetterShield emailed it to the site's administration email address when you activated it (and again if you resent it from Quick Setup), with the subject "[your site] Your BetterShield recovery link". If a link has been used since, the newest one arrived in an email titled "Your BetterShield recovery link was used on [your site]". A link you generated on the Recovery screen was shown there, not emailed.

1. Open the newest link in your browser. Opening it changes nothing yet.
2. On **Pause protection and get back in?**, press **Pause protection and continue**.
3. The **Safe mode is on** page says when the pause ends. Under **Save your next recovery link** it shows a new link: copy it somewhere safe now. A copy is also emailed to the administration address.
4. Press **Go to sign-in** and sign in with your username and password.

Each link works once: using it spends it and issues the next one straight away. A link also stops working 90 days after it was issued, or as soon as a newer one is generated. A spent, replaced or expired link shows "This recovery link or code is not valid."

For that hour, BetterShield stops enforcing lockouts, the blocklist, a moved sign-in address, session limits and its two-factor step, so the standard sign-in page works again. Safe mode ends on its own; to end it sooner, press **End safe mode now** on the Overview.

## Use a printed recovery code

Printed codes work without email. Each sheet lists eight codes and the address to use them at.

1. Open the address printed on the sheet with one code added to the end, typed as printed.
2. Press **Pause protection and continue**. Only that code is spent; your other codes keep working.
3. The **Safe mode is on** page says how many codes you have left. Press **Go to sign-in**.

A code does not issue a new link. When your codes run low, issue a new set from the Recovery screen.

## If you have neither

- **Locked out after wrong passwords.** A sign-in lockout ends on its own (15 minutes by default, longer if it keeps happening within a day). The account's email address also receives "[site name] Sign-in temporarily locked" with an unlock link: open it and press **Clear the lockout**.
- **Another administrator can still sign in.** They can generate a new recovery link for you under **Protect › Recovery**, or fix whatever is blocking you.
- **You or your host can run WP-CLI.** `wp bettershield recover` turns safe mode on for one hour and needs no user account. Add `--hours=4` for longer (1 to 24 hours) or `--new-link` to print a fresh recovery link (the old one stops working). `wp bettershield recover --end` ends safe mode early.

## Lost your two-factor device

- **Use a backup code.** Setting up two-factor gave you ten backup codes. On the code screen, type one in place of the app code. Each works once.
- **No backup codes left?** An administrator can open your account under **Users**, find **Two-factor sign-in** and press **Turn off two-factor for this account**. You then sign in with your password and set two-factor up again.
- **The only administrator?** Your recovery link or a printed code gets you into the dashboard, because the two-factor step is not asked while safe mode lasts.

## Before you need it

On **BetterShield › Protect › Recovery**, in the order the screen shows them:

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Generate a new link** (**Generate recovery link** if none exists) | Makes a new recovery link, good for 90 days, and shows it once, with **Copy link**. The old link stops working. A link made here is not emailed. | Keep it outside the site, such as in a password manager. In a link's last 14 days, Findings shows "The recovery link is close to expiring". | One link, emailed at activation |
| **Issue recovery codes** | Shows eight single-use codes once, with **Print** and **Copy all**. **Issue a new set** replaces any unused codes. | Your way back on the day email is broken. | None until you issue them |
| **Check readiness now** | Checks the link, your unused codes, an administrator email address and the email path. Never uses a link or code. | Shows a broken way back early. | Runs daily on its own |
| **Send a weekly recovery email check** | Sends a test email to your alert recipients at most once a week. | Shows whether mail actually leaves the site. | Off |
| **Lock the site down** | Signs out every other dashboard session, refuses sign-ins from accounts that cannot manage the site, turns off XML-RPC and application passwords, and stops registrations, installs and updates. Never expires; **Lift the lockdown** ends it. The front end and a WooCommerce checkout keep working. | For an emergency. Your recovery link pauses it too. | Off |

Before a change to how people sign in, such as moving the sign-in address or requiring two-factor for a role, BetterShield checks that you have a working recovery link or an unused printed code.

> **Note:** On multisite, the network's **BetterShield › Network** screen has a **Recovery link for the network**, which pauses enforcement on every site for an hour.

## Related

- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Hardening](/docs/hardening/)
- [WP-CLI commands](/docs/wp-cli-commands/)
- [Install and set up](/docs/install-and-set-up/)
- [Support](/support/)
