What is a recovery key?
A recovery key is a backup method that lets an administrator log in to ZUNDA ID if a configured login method (SAML authentication, Google authentication, Microsoft authentication, etc.) becomes unavailable for some reason.
If, after enabling SAML authentication, an outage occurs on the IdP side, a certificate is revoked, or a misconfiguration occurs, no one may be able to log in to ZUNDA ID, resulting in a lockout. By issuing a recovery key in advance and storing it somewhere safe, an administrator can recover the account in an emergency like this.
Always issue and store a recovery key before enabling a login method backed by an external IdP, such as SAML authentication. If you become unable to log in after enabling it, recovery is difficult without a key issued in advance.
How to issue a recovery key
Open the Login Methods settings screen in ZUNDA ID, and click Generate Recovery Key
Review the notes, then click Continue to proceed
This screen shows important notes about generating a recovery key. The recovery key is displayed only once, so you must copy or download it on the next screen.
Copy or download the recovery key shown, and store it somewhere safe
Once you close this screen, the recovery key is never shown again. Make sure to store it at this point.
Recommended storage locations:
- A password manager such as 1Password, Bitwarden, or Keeper
- A secrets manager managed by your organization (such as HashiCorp Vault or AWS Secrets Manager)
- A physically locked location for printed copies (as an offline backup)
Storage precautions:
- If multiple administrators need access, use a shared vault with access controls
- Avoid sharing it over plaintext channels such as email or chat
- Periodically check the storage location and contents to make sure it hasn't been lost
How to log in using a recovery key
If your regular login method (such as SAML authentication) becomes unavailable, you can log in to ZUNDA ID using your stored recovery key. Follow the steps below.
Click the Sign in with recovery key link at the bottom of the ZUNDA ID login screen
On the screen that appears, enter the administrator's email address and your stored Recovery Key, then click Verify
The email address you enter here must belong to the administrator who issued the recovery key. Once the recovery key and email address combination is verified, a confirmation email is sent.
A login email is sent to the email address you entered — please wait a moment for it to arrive
If the email doesn't arrive, check the following:
- Whether it was filtered into your spam folder
- Whether you entered the correct email address
- Whether your mail server is configured to reject incoming mail
Click the login link in the email you received to log in to ZUNDA ID
After logging in, review the status of your SAML provider settings and make any necessary fixes or reconfigure your login method. Once the configuration is fixed, you can switch back to your regular login method (such as SAML authentication).
A recovery key is an emergency measure. After logging in with a recovery key, we recommend reissuing a new recovery key and invalidating the one you just used. Avoid reusing keys, to limit the damage if one is ever leaked.