Set Up and Use the QCBM Recovery PIN
The QCBM Recovery PIN protects access to the standalone Recovery Runner included with a Recovery Package. QCBM requires exactly four digits when you set the PIN, stores it securely for QCBM operations, and assigns the configured PIN to newly created Backup Sets.
The most important rule is that a PIN belongs to the Backup Set created with it. Changing the current site PIN does not rewrite old Recovery Packages.
Why QCBM Uses a Recovery PIN
A Recovery Package can contain enough information to restore part or all of a Joomla site. The standalone Recovery Runner therefore should not open directly into recovery controls without an access check.
The four-digit Recovery PIN is used to unlock the package's Recovery Runner. It is not a Joomla administrator password, database password, QuantaCade account password, or substitute for protecting the Recovery Package itself.
Set the Recovery PIN
- Open Components > QC Backup Manager > Settings.
- Find the Recovery Security section.
- Enter exactly four numeric digits in the Recovery PIN field.
- Enter the same four digits in the confirmation field.
- Save the settings.
QCBM rejects a value that is not exactly four digits and rejects the change when the confirmation does not match. Once saved, the new value is used for future Backup Sets.
When the PIN Is Attached to a Backup Set
The PIN is assigned when the Backup Set is created. That design preserves the usability of older recovery media.
For example:
- You create Backup Set A while the current Recovery PIN is 1234.
- You later change the site Recovery PIN to 5678.
- Backup Set A and its existing Recovery Package still use 1234.
- New Backup Set B created afterward uses 5678.
This means you should record the PIN associated with every Recovery Package you intend to retain for disaster recovery.
Change the Recovery PIN
Use the same Settings area to enter and confirm a new four-digit value. Changing the PIN can be appropriate when:
- the old value was exposed to someone who should no longer have it;
- your organization rotates recovery credentials on a schedule;
- the responsibility for disaster recovery changes to a different administrator;
- you want newly created Recovery Packages to use a new recovery credential.
After changing the PIN, create a fresh Backup Set if you need a current Recovery Package protected by the new value.
View the PIN for an Existing Backup Set
QCBM can show the Recovery PIN associated with an existing Backup Set when the current administrator account has the permission required to view it and the PIN data for that Backup Set is available.
This is different from simply looking at the current Settings PIN. If the site PIN has changed since a Backup Set was created, the historical Backup Set can still require the older value.
Use the PIN During Recovery
When you extract a Recovery Package into the target Joomla root and open qcbm-recover.php, the runner asks for the four-digit Recovery PIN before allowing the guided recovery workflow to proceed.
Use HTTPS whenever possible. The runner can warn when a new destination has no working certificate, but an encrypted connection is preferred because recovery can involve the PIN and database connection details.
Who Should Be Able to See Recovery PINs
Joomla ACL can separate ordinary QCBM administration from permission to reveal Recovery PINs. Use that separation when multiple administrators manage the site but only a smaller recovery team should see recovery credentials.
A plan tier and an ACL permission are not the same thing. Even when a feature exists for the current plan, the current Joomla administrator can still be denied access by site permissions.
Protect the PIN and the Package
- Do not post the PIN in public community topics, screenshots, or documentation.
- Do not store the PIN in a publicly accessible file on the Joomla site.
- Keep the Recovery Package itself protected; the package may contain sensitive site and database data.
- Store the package and its PIN in your disaster-recovery records so the correct value can be found during an outage.
- Limit Recovery PIN visibility to administrators who actually need it.
If QCBM Will Not Create a New Backup
A missing or invalid Recovery PIN can prevent QCBM from creating a new Backup Set. Return to Settings, enter and confirm a valid four-digit PIN, save the settings, and then retry the backup.
If a PIN is already configured and the backup still does not start, do not repeatedly change the PIN. Review Status, Managed Private Storage, active-job state, and the backup error message so you troubleshoot the correct subsystem.
Recovery PIN Checklist
- The site has a valid four-digit Recovery PIN configured.
- The PIN is stored in a secure recovery record.
- Important retained Recovery Packages have their corresponding historical PIN recorded.
- Administrators without a recovery role do not have unnecessary PIN-view permission.
- A fresh Backup Set is created after a PIN change when you need a package using the new value.
Community Discussion
Want to discuss recovery planning without sharing private credentials? Visit the QC Backup Manager Community. Never post an actual Recovery PIN publicly. For private support, bug reports, or feature requests, use the QuantaCade support system.