← All guides

Troubleshooting

Why your authenticator code is not working

Diagnose clock drift, wrong secrets, expired windows, account mix-ups, and configuration differences without exposing your setup key.

6 minute read Reviewed 25 July 2026

Start with the clock

TOTP codes depend on time. If the phone or computer clock is noticeably wrong, the authenticator and service calculate different counters. Enable automatic date, time, and time-zone settings, then allow the device to synchronise before trying a newly generated code.

Do not keep submitting the same code near the end of its window. Wait for the next code, enter it carefully, and submit it promptly. Repeated failed attempts may trigger a temporary account lock.

Confirm the account and configuration

People often have multiple entries with similar names, especially for work and personal accounts. Match both the issuer and account label. If the entry was added manually, confirm the algorithm, digit count, and period specified by the service.

A secret copied with missing characters, visually similar characters, or unrelated text will generate valid-looking but incorrect codes. Return to the authenticated security settings and re-enrol rather than sending the secret to a support agent.

  • Automatic time is enabled and recently synchronised.
  • The correct issuer and account are selected.
  • The code has not reached the final second of its period.
  • Manual settings match the service's setup instructions.

Re-enrol safely when necessary

If you still have an authenticated session, add a replacement authenticator before removing the old entry. Confirm a code from the new entry, save fresh backup codes, and only then remove the unusable factor.

If you are locked out, follow the recovery order in our lost-authenticator guide. Avoid websites or individuals claiming they can derive a secret from a few expired codes; standard TOTP is designed so the short outputs do not reveal the underlying key.