An authenticator app can generate a changing login code without contacting the website because both sides use the same secret and a time-based counter. A code may still be rejected if their clocks or setup parameters do not match, if you submit it too late, or if the service has already accepted it once. The common TOTP interval is 30 seconds, but that is not a guarantee that every service accepts a code for exactly 30 seconds.
How a time-based authenticator code is generated
Time-based one-time passwords, or TOTP, are a form of the HMAC-based one-time password algorithm (HOTP). In TOTP, the moving counter is derived from the current Unix time divided into configured time steps. The authenticator app and the service each calculate a code from that counter and a shared secret, so the app does not need to fetch each new code from the website.
The IETF specification RFC 6238 recommends a 30-second default time step. At each boundary, the counter advances and the generated code changes. The specification supports HMAC-SHA-1 and allows HMAC-SHA-256 or HMAC-SHA-512 when configured. The secret and parameters are established when the authenticator is enrolled; if the app and service do not have compatible values, their codes will differ.
Why a valid-looking code can be rejected
The device and service clocks disagree
If your phone’s clock is ahead of or behind the service’s clock, each side may calculate a different time counter. GitHub’s two-factor authentication troubleshooting guidance, for example, notes that an out-of-sync phone or computer clock can make a code invalid. Hardware clocks can drift as well; Token2’s discussion of classic TOTP token drift describes that issue for physical tokens.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
You submit near a time-step boundary
A code displayed near the end of its time step may be submitted just after the next one begins. Services can allow a bounded tolerance for clock drift and transmission delay, but the acceptance policy is service-specific. RFC 6238 recommends allowing no more than one time step for network delay; a wider window makes an exposed code usable for longer.
The authenticator entry or enrollment does not match
A code can be calculated correctly by the app and still fail if you selected an entry for a different account, enrolled with a different secret, or the app and service use incompatible parameters. TOTP depends on both sides having the same secret and time-step configuration, not merely on the app displaying a plausible-looking number.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The code has already been used
TOTP is not intended to make a code reusable throughout its displayed interval. RFC 6238 says a verifier must not accept the same successfully validated code a second time for that step. NIST likewise calls for accepting a time-based OTP only once during its validity period. A repeat submission may therefore fail even before the digits change.
How long do you have to enter a code?
The app’s display interval and a service’s acceptance window are different things. The 30-second interval is the IETF’s recommended default for TOTP, not a universal promise about how long every website will accept a displayed code. A verifier’s policy can take account of expected clock drift in either direction, network delay, and the time a person needs to enter the digits.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
RFC 6238 gives an illustrative example: with a 30-second step and a validator configured to accept two steps backward, the maximum elapsed drift is about 89 seconds. That is an example of a configured tolerance, not a typical setting or a measured failure rate. A larger acceptance window can reduce failures caused by delay or drift, but it also gives someone who obtains a code more time to try to use it.
What to do when your authenticator code fails
- Check the device time. Set your phone or computer’s date, time, and time zone to update automatically or synchronize with a reliable time source. GitHub identifies a clock mismatch as one possible cause of an invalid TOTP code.
- Try a fresh code promptly. Wait for the next code interval if the current one is near its boundary, then enter the newly displayed code without delay. Do not keep resubmitting a code the service has already accepted.
- Check the account entry. Confirm that you selected the authenticator entry for the service and account you are trying to access. If the problem persists, the enrollment secret or configured parameters may not match.
- Use the service’s recovery process if needed. NIST defines recovery codes as secrets for regaining account access when a subscriber can no longer authenticate. Available options vary by service, so follow its current recovery instructions.
- Re-enroll after regaining access. When changing devices, NIST advises binding the new software authenticator and invalidating the old one, or transferring the secret through a sync method that meets its requirements. Use the service’s own security settings to re-enroll and retire an old authenticator when appropriate.
Never send your one-time code or authenticator setup secret to another person. The setup secret is the persistent key used to generate codes, and RFC 6238 says keys should be protected against unauthorized access.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Recovery options and alternatives to TOTP
Recovery codes are intended for situations in which you cannot use your usual authenticator. Store them somewhere protected and follow the service’s instructions for use. If you move to a new device, secure re-binding or a protected transfer is preferable to leaving the old authenticator active.
Where a service supports it, WebAuthn/FIDO2 can provide a different sign-in experience without manually copying a TOTP code. NIST identifies WebAuthn as phishing-resistant through verifier-name binding. It is not available on every service, and setting it up does not fix a TOTP problem on an account that still requires TOTP.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Physical TOTP hardware tokens are another possible code-generation method, but they still depend on compatible enrollment and timekeeping. A dedicated token is not a general solution to a phone clock problem, mismatched secret, or service-side acceptance policy.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

