Two-factor (TOTP) code invalid / Invalid verification code (authenticator app time drift)
The 6-digit authenticator code is rejected — usually because the phone’s or server’s clock is off, or the secret was enrolled twice.
Seen on:
REST API
Meaning
TOTP codes change every 30 seconds and depend on accurate time. Manual phone time, server clock drift, re-scanning the QR (new secret) or using an old account entry in the app cause failures.
Common causes
- Phone or server clock not synced
- Old authenticator entry after re-enrolment
- Verification window too strict
- Typing the code after it rotated
⚡ Quick fix
- Enable automatic time on the phone; sync server time (NTP)
- Remove stale entries and re-scan the current QR code
- Allow ±1 time step on the server
Detailed fix by platform
JavaScript
- javascript
import { authenticator } from "otplib"; authenticator.options = { window: 1 }; // accept previous/next 30s step const ok = authenticator.check(code, user.totpSecret);
How to diagnose
- Clocks — Phone and server time
- Secret — Current enrolment?
- Window — Allowed drift
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- Clock skew too great Kerberos: Clock skew too great (KRB_AP_ERR_SKEW)
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026