If the token is lost, you can enroll a temporary password based token and give the password to the user. The OTP PIN of the old token is still the same.
The user will have to authenticate with the old OTP PIN he knows and this newly generated password.
The old token is disabled and can be deleted or enabled later.
Not yet implemented.