> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace recovery codes

> Replaces a saved login's two-factor recovery codes.

<Accordion title="Details">
  Saved codes are never shown again, only counted. The codes pass through this client and its model provider, so warn the user first.

  * **Callers:** an API key, an MCP OAuth token or a Dashboard session.
  * **Permission:** `logins:manage`.
  * **Effect:** Creates or changes something.
  * **Errors:** [`not_found`](/errors#not_found), [`site_login_exists`](/errors#site_login_exists), [`login_identity_conflict`](/errors#login_identity_conflict), [`legacy_duplicate_saved_logins`](/errors#legacy_duplicate_saved_logins), [`saved_login_unsettled`](/errors#saved_login_unsettled), [`login_in_use`](/errors#login_in_use), [`login_save_in_progress`](/errors#login_save_in_progress), [`invalid_credential`](/errors#invalid_credential), [`acceptance_unknown`](/errors#acceptance_unknown), and the [errors any request can get](/errors).
</Accordion>


## OpenAPI

````yaml /api-reference/openapi.json put /v1/logins/{id}/recovery-codes
openapi: 3.1.0
info:
  title: Pomerado API
  version: '1'
  description: >-
    Run and build website tools, follow their jobs, and manage logins, API keys
    and webhooks. Authenticate with a Pomerado API key (pom_…), an MCP OAuth
    token or a Dashboard session as a Bearer token.
servers:
  - url: https://api.pomerado.ai
security: []
tags:
  - name: account
    x-group: Account
  - name: api_keys
    x-group: API keys
  - name: connected_apps
    x-group: Connected apps
  - name: usage
    x-group: Usage
  - name: quota
    x-group: Quota
  - name: billing
    x-group: Billing
  - name: integrations
    x-group: Integrations
  - name: connect
    x-group: Connect
  - name: logins
    x-group: Saved logins
  - name: two_factor
    x-group: 2FA
  - name: login_access
    x-group: Login access
  - name: tools
    x-group: Tools
  - name: webhooks
    x-group: Webhooks
  - name: runs
    x-group: Runs
  - name: builds
    x-group: Builds
  - name: jobs
    x-group: Jobs
  - name: files
    x-group: Files
  - name: team
    x-group: Team
paths:
  /v1/logins/{id}/recovery-codes:
    put:
      tags:
        - two_factor
      summary: Replace recovery codes
      description: Replaces a saved login's two-factor recovery codes.
      operationId: logins.set_recovery_codes
      parameters:
        - name: id
          in: path
          required: true
          description: 'a saved login ID: login_ and 32 lowercase hex digits'
          schema:
            type: string
            examples:
              - login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - codes
              properties:
                codes:
                  type: array
                  items:
                    type: string
                    description: a string at most 64 character(s) long
                    minLength: 4
                    maxLength: 64
                  description: an array of at most 20 item(s)
                  minItems: 1
                  maxItems: 20
              additionalProperties: false
      responses:
        '200':
          description: The login
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Login'
        '400':
          description: invalid_request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: unauthorized, reauthentication_required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: not_found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            site_login_exists, login_identity_conflict,
            legacy_duplicate_saved_logins, saved_login_unsettled, login_in_use,
            login_save_in_progress
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          description: request_too_large
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: invalid_credential
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: internal_error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: acceptance_unknown, temporarily_unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearer: []
components:
  schemas:
    Login:
      type: object
      required:
        - id
        - label
        - site
        - username_masked
        - identifier_type
        - sign_in
        - saved_fields
        - two_factor
        - status
        - needs_attention
        - locked
        - your_access
        - created_at
        - updated_at
        - verified_at
      properties:
        id:
          $ref: '#/components/schemas/login_id'
        label:
          anyOf:
            - type: string
            - type: 'null'
        site:
          type: object
          required:
            - url
            - name
          properties:
            url:
              type: string
            name:
              type: string
              description: The site as people say it
          additionalProperties: false
        username_masked:
          type: string
        identifier_type:
          type: string
          enum:
            - username
            - email
            - phone
            - account_number
        sign_in:
          type: string
          enum:
            - password
            - code
        saved_fields:
          anyOf:
            - type: array
              items:
                type: string
                enum:
                  - email
                  - phone
                  - account_number
                  - date_of_birth
                  - zip
                  - recovery_codes
                  - preferred_method
            - type: 'null'
          description: >-
            What it holds besides its username and password; null when not
            recorded
        two_factor:
          type: object
          required:
            - authenticator
            - sms_number
          properties:
            authenticator:
              anyOf:
                - type: boolean
                - type: 'null'
            sms_number:
              type: string
              enum:
                - none
                - linked
          additionalProperties: false
        status:
          type: string
          enum:
            - unverified
            - verified
            - needs_attention
        needs_attention:
          anyOf:
            - type: object
              required:
                - field
              properties:
                field:
                  type: string
                  enum:
                    - username
                    - email
                    - phone
                    - account_number
                    - password
              additionalProperties: false
            - type: 'null'
        locked:
          type: boolean
          description: >-
            Personal accounts: its identity is fixed after the first verified
            sign-in
        your_access:
          type: string
          enum:
            - use
            - edit
            - manage
          description: >-
            use: run and build with it. edit: also reveal and change it. manage:
            also share and delete it
        created_at:
          type: string
          description: When it was saved, ISO 8601 UTC
        updated_at:
          type: string
          description: When it last changed, ISO 8601 UTC
        verified_at:
          anyOf:
            - type: string
            - type: 'null'
          description: Its first verified sign-in, ISO 8601 UTC; null before one
      additionalProperties: false
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - retryable
            - docs_url
          properties:
            code:
              type: string
            message:
              type: string
            retryable:
              type: boolean
            docs_url:
              type: string
            details:
              type: object
              required: []
              properties: {}
              additionalProperties:
                $id: /schemas/unknown
          additionalProperties: false
      additionalProperties: false
    login_id:
      type: string
      description: 'a saved login ID: login_ and 32 lowercase hex digits'
      examples:
        - login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.