Why is my two-factor authentication code not working?
Almost always a clock problem — authenticator codes are generated from the current time, so a device whose clock has drifted produces codes the server rejects, and nothing about the account is wrong.
How time-based codes work. A TOTP code is calculated from a shared secret and the current time, in 30-second intervals. Both your device and the server compute the same code independently. If your clock is out by more than a small margin, you compute the code for the wrong interval.
The fix, which resolves the large majority of cases:
Set the device clock to automatic network time. On some authenticator apps there is a specific "time correction" or "sync" option that adjusts the app's internal offset without changing the device clock — which is the appropriate fix when the device time cannot be changed.
Seconds matter. A clock correct to the minute but out by 40 seconds will still fail, which is why "my clock looks right" is not sufficient.
The other causes:
Entering a code that has just expired. Codes rotate every 30 seconds, and entering one in its final second frequently fails. Wait for a fresh code.
Using the wrong account's code, where an authenticator holds several similar entries.
The account was set up on a different device, and you are using an authenticator that never received that secret.
Backup codes used once — each is valid a single time.
SMS codes not arriving, which is a delivery problem rather than a code problem, and a reason to prefer app-based or hardware authentication.
The service having an issue, which is worth checking before assuming.
What to do if you are locked out:
Use a backup code, which is what they exist for — and this is the moment people discover they never saved them.
Use a second registered method.
Account recovery through the provider, which is deliberately slow.
What to do now, before this happens:
Save backup codes somewhere you can reach without the account, on paper or in a password manager.
Register more than one method, including a second device.
Use an authenticator that supports encrypted backup, so losing a phone does not lose every account.
Hardware keys resist phishing in a way codes do not, and a spare key is the robust arrangement.