View the Recovery PIN for an Existing QCBM Backup Set
Every new QCBM Backup Set stores an encrypted copy of the four-digit Recovery PIN that was active when that Backup Set was created. That historical PIN travels with the recovery record so changing the current PIN in Settings does not silently change the PIN required by older Recovery Packages.
Recovery PIN visibility is controlled by Joomla ACL. An administrator who can manage backups but does not have the Recovery PIN permission will see the PIN as restricted rather than receiving the secret value.
Where the Backup Set PIN Appears
- Open Components > QC Backup Manager > Backups.
- Locate the Backup Set under Backup History.
- Read the PIN pill shown with the Backup Set type and status.
When your account has the required permission and the historical encrypted PIN can be decrypted, QCBM displays it as PIN: 1234. If your account lacks permission, the record displays PIN: Restricted. If the Backup Set does not contain a usable stored PIN, it displays PIN: Unavailable.
The Required Permission
QCBM checks the Joomla ACL action qcbm.recovery.pin.view before exposing a historical Recovery PIN. Treat this as a sensitive permission because anyone who has both a Recovery Package and its matching PIN can begin the standalone recovery workflow.
Plan entitlement and ACL are separate. Recovery Packages are available on all QCBM plans, but the current Joomla user still needs permission to view a stored PIN.
Historical PIN Versus the Current Settings PIN
The PIN shown for a Backup Set is the encrypted PIN saved with that specific Backup Set at creation time. The PIN shown in QCBM Settings is the current PIN that will be copied into future Backup Sets.
If you change the Settings PIN today, an older Backup Set continues to use the older stored PIN. This is intentional: a previously created Recovery Package must remain paired with the PIN used when that package was built.
Why QCBM Stores the PIN with Each Backup Set
Before QCBM creates a new Backup Set, it requires a valid four-digit Recovery PIN in Settings. It stores an encrypted recoverable copy on the Backup Set record and also uses that PIN when building the Recovery Package.
This design avoids a dangerous situation where changing the site's current PIN would make administrators unable to recover older packages whose required PIN had been forgotten.
If the PIN Is Unavailable
PIN: Unavailable means QCBM cannot provide a valid four-digit PIN from that Backup Set record. It can occur when the historical encrypted value is absent, cannot be decrypted, or is not a valid four-digit value.
Do not assume the current Settings PIN will unlock that old package. If the live site is healthy, create a fresh verified Backup Set after confirming the current Settings PIN, then protect the new Recovery Package and its PIN together.
Store the PIN Separately from the Package
For disaster-recovery planning, record the PIN in a protected password manager or other controlled recovery record rather than relying on the production Joomla site to remain available. A Recovery Package stored off-server is much less useful during a total outage if the only copy of its PIN can be viewed from the failed server.
Do not put an unprotected PIN in the same public or broadly shared folder as the Recovery Package.
Verify You Have the Correct Pair
Before deleting older recovery points or during a scheduled recovery test, confirm the downloaded Recovery Package and the PIN come from the same Backup History record. The package is tied to one Backup Set; a PIN from a newer or older Backup Set may not be the correct one.
Community Discussion
Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.