What Account Recovery Information Should You Save After Completing OKX Registration?
After registration, you must save two independent sets of information—login credentials (email/phone number) and two-factor authentication (2FA) keys. Seed phrases and private keys typically belong to the Web3 wallet, not the exchange account, but if you have activated the OKX Web3 Wallet, you must back them up as well. Below is a complete checklist and step-by-step guide, listed by priority.
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Step 1: Confirm That Your Login Credentials Are Safe and Recoverable
Your login credentials are the email address and linked phone number. They are the basis for password recovery and receiving verification codes.
How to do it:
Log in to the OKX App, go to [User Center] – [Security Settings] – [Contact Information], and confirm that the email and phone number on file are yours and can receive messages normally.
If you have linked an email, make sure that email account itself has a strong password and two-factor authentication enabled, so that if your email is compromised, your OKX account cannot be reset.
Completion standard: You can receive test emails and SMS verification codes from OKX.
Prerequisite: Account successfully registered and logged in.
Step 2: Save Your Two-Factor Authentication (2FA) Key or Recovery Codes
After enabling two-factor authentication such as Google Authenticator, the system generates a 16-character alphanumeric secret key. This is the only credential for recovering your 2FA if you switch phones or reinstall the authenticator app.
How to do it:
In OKX [Security Settings] – [Two-factor Authentication] – [Google Authenticator], the binding page shows a QR code and the key string below it.
Immediately screenshot or write down that key; do not store it only on your phone.
Scenario A: You have completed the binding but did not save the key → In the security center, find the option to "Rebind" or "Change device", go through the binding process again, and save the newly generated key.
Scenario B: You have already saved the key → Verify that the storage location is secure (see storage suggestions below).
Completion standard: You have an offline copy of the 2FA secret key, or you have archived the list of backup recovery codes generated by OKX. When enabling two-factor authentication for the first time, the system generates 10 one-time-use recovery codes; these must also be stored.
Step 3: Back Up the OKX Web3 Wallet Seed Phrase (If Activated)
If you have activated the Web3 wallet (non-custodial wallet) within the OKX App, you are forced to back up a 12-word seed phrase during creation.
How to do it:
When the system displays the seed phrase, write it down word by word with pen and paper, numbering them in order.
After writing it down, the system will ask you to verify the words in order. After confirming they are correct, click "I have safely saved it".
Completion standard: The seed phrase is physically written down and stored in at least two separate secure locations.
Note: The seed phrase gives full control over your Web3 wallet. Anyone with it controls all assets in the wallet. Do not take screenshots, photos, or store it on internet-connected devices. OKX will never ask for your seed phrase under any circumstances.
Step 4: Record API Key Information (If You Use API Features)
If you have enabled API interfaces for automated trading or connecting third-party tools, the API Secret and Passphrase are shown only once at creation.
How to do it: At the moment of creating the API Key, immediately copy the Secret and Passphrase and save them in a password manager or offline record. If you did not save them at that time, you will need to delete the old key, create a new one, and back it up again.
Completion standard: Complete information for all active API Keys is saved, or you have confirmed that no API backup is needed.
Step 5: Store Backup Information Securely
Storage methods ordered by recommendation:
| Information Type | Recommended Storage Method | Forbidden Methods |
|---|---|---|
| Seed phrase / Private key | Handwrite on paper, store in a safe; or engrave on a metal plate | Screenshots, photos, cloud storage, sending via messaging apps |
| 2FA secret key / recovery codes | Same as seed phrase, store separately | Keeping in phone photo album or notes |
| API Key | Encrypt and save in a password manager (e.g., 1Password) | Storing as plain text on the computer desktop |
| Login password | Strong password, remember using a password manager | Using simple combinations like birthday/phone number |
Completion standard: Every type of information has at least two physical or encrypted backups, stored in different locations to avoid a single point of loss.
Common Reasons for Failure
The most common mistake is remembering only the login password but not saving the 2FA key and seed phrase. If you lose your phone and have not backed up the 2FA key, and have no recovery codes, contacting customer support to reset two-factor authentication requires manual review. After submitting identity verification materials, it usually takes over 24 hours to process. During this period, your account will be temporarily locked, and you cannot trade or withdraw.
Another common problem is confusing exchange account login information with the Web3 wallet seed phrase—forgetting the exchange login password can be recovered via email or phone, but if you forget the Web3 wallet password and have no seed phrase, the assets are permanently unrecoverable, and OKX customer support cannot help.
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
How to Confirm Everything Is Properly Backed Up
After logging out, test the following separately:
Check whether the password recovery process via email/phone can be triggered normally (you do not need to actually reset it).
If you have saved the 2FA key, install Google Authenticator on another device, try adding the account by manually entering the key, and confirm that the generated 6-digit dynamic code matches that on your phone—this proves the key is valid.
Only after completing all the backup items above is your account recovery information fully ready. Next step: it is recommended to enable login device management and an anti-phishing code to prevent receiving fake official phishing emails.
