Question

Why is my two-factor authentication code not working?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Almost always a clock problem — authenticator codes are generated from the current time, so a device whose clock has drifted produces codes the server rejects, and nothing about the account is wrong.

How time-based codes work. A TOTP code is calculated from a shared secret and the current time, in 30-second intervals. Both your device and the server compute the same code independently. If your clock is out by more than a small margin, you compute the code for the wrong interval.

The fix, which resolves the large majority of cases:

Set the device clock to automatic network time. On some authenticator apps there is a specific "time correction" or "sync" option that adjusts the app's internal offset without changing the device clock — which is the appropriate fix when the device time cannot be changed.

Seconds matter. A clock correct to the minute but out by 40 seconds will still fail, which is why "my clock looks right" is not sufficient.

The other causes:

Entering a code that has just expired. Codes rotate every 30 seconds, and entering one in its final second frequently fails. Wait for a fresh code.

Using the wrong account's code, where an authenticator holds several similar entries.

The account was set up on a different device, and you are using an authenticator that never received that secret.

Backup codes used once — each is valid a single time.

SMS codes not arriving, which is a delivery problem rather than a code problem, and a reason to prefer app-based or hardware authentication.

The service having an issue, which is worth checking before assuming.

What to do if you are locked out:

Use a backup code, which is what they exist for — and this is the moment people discover they never saved them.

Use a second registered method.

Account recovery through the provider, which is deliberately slow.

What to do now, before this happens:

Save backup codes somewhere you can reach without the account, on paper or in a password manager.

Register more than one method, including a second device.

Use an authenticator that supports encrypted backup, so losing a phone does not lose every account.

Hardware keys resist phishing in a way codes do not, and a spare key is the robust arrangement.

Related Questions