invalid two-factor code 🔐 Authentication

Two-factor (TOTP) code invalid / Invalid verification code (authenticator app time drift)

The 6-digit authenticator code is rejected — usually because the phone’s or server’s clock is off, or the secret was enrolled twice.

Seen on: REST API

Meaning

TOTP codes change every 30 seconds and depend on accurate time. Manual phone time, server clock drift, re-scanning the QR (new secret) or using an old account entry in the app cause failures.

Common causes

  • Phone or server clock not synced
  • Old authenticator entry after re-enrolment
  • Verification window too strict
  • Typing the code after it rotated

⚡ Quick fix

  1. Enable automatic time on the phone; sync server time (NTP)
  2. Remove stale entries and re-scan the current QR code
  3. Allow ±1 time step on the server

Detailed fix by platform

JavaScript

  1. javascript
    import { authenticator } from "otplib";
    authenticator.options = { window: 1 };   // accept previous/next 30s step
    const ok = authenticator.check(code, user.totpSecret);

How to diagnose

  1. Clocks — Phone and server time
  2. Secret — Current enrolment?
  3. Window — Allowed drift

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.