Why Your 2FA Code Is Not Working

Rejected, “incorrect”, or “invalid” 2FA codes almost always come down to one of five causes — and four of them you can fix in under two minutes. Work down this list in order.

1. Fix device clock drift (the cause ~80% of the time)

TOTP codes are computed from the current time. If your device clock drifts even a minute — common after travel, sleep mode, or on old PCs — every code you generate is for the wrong time window. Enable automatic time sync:

DeviceWhere to enable automatic time
Windows 10/11Settings → Time & language → Date & time → Set time automatically → Sync now
macOSSystem Settings → General → Date & Time → enable Set date and time automatically
iPhone / iPadSettings → General → Date & Time → Set Automatically
AndroidSettings → System → Date & time → Use network-provided time
Linuxtimedatectl set-ntp true (or your desktop’s clock settings)

After syncing, generate a fresh code and try again immediately.

2. Re-check the setup key itself

  • Copied completely? Base32 keys are long (16–32+ characters); a dropped character silently produces different codes. Paste instead of retyping.
  • Right key for the right account? Multiple enrollments create multiple keys; an old key keeps generating “plausible but wrong” codes.
  • Re-enrolled recently? If you (or the service) regenerated the key, update every tool that holds it — an app keeps using the old key until you re-add it.
  • Spaces and case don’t matter in Base32 — the generator strips them — but an O vs 0 or 1 vs I transcription error does.

3. Match non-default TOTP parameters

Most services use SHA-1, 6 digits, 30 seconds. Some — certain exchanges, enterprise SSO, older self-hosted tools — use SHA-256/SHA-512, 8 digits, or a different period. If the key is right but codes are rejected:

  1. Open the TOTP generator and paste your key.
  2. Try SHA-256 with 8 digits, then SHA-512, then 60-second periods.
  3. If the service showed an otpauth:// URI, paste the whole URI — parameters are read from it automatically.

4. Beat the timer

Codes expire with their 30-second window, and services reject codes in their final seconds. The fix is timing, not the key: watch the countdown, let a new code appear, and submit it immediately. The generator shows the time remaining under every code for exactly this reason.

5. Confirm the account actually uses TOTP

Not every second factor is a TOTP code. Push notifications, SMS codes, email codes, passkeys, and Steam Guard all look similar in prompts but work completely differently — a TOTP generator cannot produce them. If your prompt says “approve on your device” or a code arrived by text, use that channel (or switch the account’s method to authenticator app in its security settings).

Cross-check your code in seconds

A reliable way to isolate the problem: paste your key into the 2FA code generator and compare its output with your usual authenticator app, side by side. If they match, your code is right and the problem is timing or the service. If they differ, one of the two tools holds a wrong key or wrong settings — and the checklist above sorts out which.

Frequently asked questions

Why is my 2FA code invalid?

Usually device clock drift — enable automatic time sync and generate a fresh code. A mistyped or stale setup key is the second most common cause.

How do I fix 2FA time sync on Windows, Mac, or iPhone?

Windows: Settings → Time & language → Set time automatically → Sync now. macOS: System Settings → General → Date & Time → automatic. iPhone: Settings → General → Date & Time → Set Automatically.

The code is correct but still rejected — what else?

Non-default TOTP parameters: try SHA-256/SHA-512, 8 digits, or a 60-second period on the TOTP generator. Also re-check that you enrolled with the current key.

My 2FA code expires before I can type it — what now?

Wait for a fresh code and submit it as soon as the timer resets, rather than using one in its final seconds.

Related pages