We're on Product Hunt today! Leave a comment

2FA code not working? Why an authenticator code is rejected, and how to fix it

When a website says your 2FA code is invalid, the code itself is usually fine — it just belongs to a different QR code than the one the website is waiting for. The most common reasons: the website made a new QR code because its setup page was reloaded or opened again, so the account you added first no longer matches; the same website is in your authenticator twice and you used the older entry; 2FA was set up in another app or on another phone; or the website is asking for a text message, email or backup code, not the one from the app.

Less often the code ran out while you were typing it, or a secret key typed in by hand has a mistake in it. The device clock comes last: it matters for a phone app, where the fix is to turn on automatic date and time. Each cause and its fix is below — in the order people run into them.

1. The website made a new QR code

This is the one that catches most people during setup. A website creates a new secret — and a new QR code — every time its 2FA setup page is reloaded, opened again, or started over. Remote's help centre describes exactly this: any QR code scanned earlier stops working. Your authenticator still shows codes for the first QR code, the website now expects codes for the new one, and nothing on the screen tells you they no longer match.

Fix: start the 2FA setup on the website again and stay on that page. Add the QR code that is on the screen now — with our extension, Add Account → QR Code → "Scan QR from screen" — and type the code it shows straight back into the website, without reloading or leaving the page. Then save the backup codes the website offers.

The same thing happens after you turn 2FA off and on again, or click "change authenticator app": the old entry in your app stops working and only the new QR code counts.

2. The code came from another entry

After a second try at setup, the same website is often in the list twice, with the same name. Only the entry from the QR code you added last works — the older one belongs to a QR code the website has already thrown away. During setup, the website always wants the code of the account you have just added.

The same mix-up happens with two accounts on one website — a personal and a work Google account, say. Google's own advice for an incorrect code is to check that the code is for the right service and the right account. Look at the name under the code, not just the logo.

Fix: use the newest entry. Once a code from it has been accepted, you can delete the old one — export a backup first (Settings → "Export") in case you pick the wrong one.

3. 2FA was set up in another app or on another phone

An authenticator shows codes only for the accounts added to it. If you turned on 2FA for a website months ago with Google Authenticator, Microsoft Authenticator or an old phone, that is where its codes are — an entry you add somewhere else later will not match, unless it was made from the very same QR code.

Fix: take the code from the app you used at setup. To move the account, either export it from that app — Google Authenticator's export QR code imports straight into our extension, see import from Google Authenticator — or sign in, open the website's 2FA settings and set up the authenticator again, this time with the new app. Keep the old app until a code from the new one has been accepted. More on this in moving 2FA to a new phone.

4. The website wants a different code

Not every six-digit box is waiting for your authenticator. Many websites send a code by text message or email — at sign-in, or to confirm your address before 2FA is even on — and only that code works there. Remote's help centre makes the same point: a code sent to your email is not a 2FA code from an authenticator app. If the page says "we sent a code to…", look in your messages or inbox, not in the app.

Some sign-in pages ask for a backup code (also called a recovery code) instead: one of the one-time codes the website gave you as a list when you set up 2FA. Those are on the paper or file you saved them to, not in the authenticator — and they are not secret keys, so adding one to an authenticator as an account produces codes no website will accept. Lost them? Google, for one, lets you get new backup codes from the 2-Step Verification settings while you are still signed in.

Fix: read the text above the box. "Authenticator app", "verification app" or "code from your app" means the authenticator; anything else means the message, the email or the backup list.

5. The code ran out while you were typing it

Most authenticator codes change every 30 seconds — Microsoft's FAQ for its own app says the same. A code typed in during its last couple of seconds can reach the website after it has already changed.

Fix: if the timer is nearly empty, wait for the next code and enter it straight away. In our extension, clicking a code copies it, so you can paste it instead of typing it.

6. The secret key was copied with a mistake

If you added the account by typing the secret key rather than scanning the QR code, a single wrong character gives a different key. Its codes look perfectly normal and are simply rejected.

Fix: on the website's setup page — the same one, not reloaded — copy the key again and paste it into our TOTP code generator, which runs in your browser and saves nothing. Compare its code with the one in your authenticator. If they differ, the key in your authenticator is wrong: delete that entry and add it again by pasting the key or scanning the QR code. If they match and the website still refuses them, go back to the first cause.

A few services use eight digits, SHA256 or a 60-second period instead of the usual six digits, SHA1 and 30 seconds. A QR code carries these settings; a key typed in by hand does not, so set them to what the website says — see algorithm, digits and period.

7. Last: the device clock

A code is made from the secret key and the current time, so an app on a device whose clock is wrong makes codes that are refused. With a phone app, turn on automatic date and time in the phone's settings. Google Authenticator relies on the phone's own clock — Google removed its separate time-correction setting in version 7.0.

With 2FA Authenticator there is nothing to change: the extension checks the time against several sources itself and adjusts the codes if your computer's clock is off. Only if it cannot do that does it show a warning about the time — then follow the steps in the FAQ.

Still can't get in?

Sign in another way — a backup code, a text message or an email code, whatever the website offers — then open its 2FA settings, turn the authenticator off and on again, and add the new QR code. Our setup guides show where that setting is for 108 services.

Do not delete entries or reinstall your authenticator in the hope of fixing a code: the codes will not change, and you may lose the one entry that works. Uninstalling our extension also deletes its automatic copies — if you have already deleted an account, restore it from an automatic copy instead.

Frequently asked questions

Why does my authenticator say the code is invalid when it is the right account?
Most often because the website made a new QR code after you added the account — its setup page was reloaded or opened again. Your app shows codes for the old QR code; the website expects the new one. Start the setup again, add the QR code that is on the screen now, and enter its code without leaving the page. The full list of causes is in the FAQ.
Why is my Google Authenticator code wrong?
For the same reasons as any authenticator: a newer QR code, an older entry for the same account, a code for a different Google Account, or a code that expired while you typed it. Google's own checklist adds the phone's clock: since version 7.0 Google Authenticator uses the phone's time, so turn on automatic date and time.
The code on my phone and the code in the extension are different. Which one is right?
The one made from the QR code the website issued last. Two apps holding the same secret key show the same code at the same moment, so different codes mean the two entries come from different QR codes — and only the newest one works.
Do I need to fix my computer's clock?
Not for our extension: it measures the time itself and adjusts the codes. Do something only if it shows a warning about the time — the FAQ on time sync has the steps. With a phone app, turn on automatic date and time on the phone.
Will deleting the account and adding it again fix the code?
Only if you add the QR code the website is showing now. Adding the same old key again gives the same codes. Export a backup before you delete anything, and keep the old entry until the new one's code has been accepted.
How can I check a secret key without signing in?
Paste it into the TOTP code generator: it shows the code that key is producing right now, computed in your browser. If it matches your authenticator, the key was added correctly.

2FA codes in Chrome, set up from the screen

2FA Authenticator scans the setup QR code straight off the page and corrects for a wrong computer clock on its own. Free to use, open source, no account.

Add 2FA Authenticator to Chrome — free

Sources

Checked October 9, 2026. If anything here is wrong or out of date, tell us and we will fix it.