Troubleshooting

2FA Codes Out of Sync: How to Fix Time Synchronisation Problems

TOTP authenticator codes are generated using the current time. If your phone's clock drifts by more than 30 seconds, every code you generate will be rejected โ€” even if it looks right.

Why TOTP Codes Go Out of Sync

Your authenticator app and the server both independently calculate the current 30-second time window. If your clock is off โ€” even by 31 seconds โ€” you'll be calculating a different window than the server, and your code will be wrong.

Common causes: airplane mode for extended periods, travelling across time zones, a faulty system clock, or a recently replaced phone battery.

Fix Time Sync on Android

  1. Open Settings
  2. Go to General management โ†’ Date and time
  3. Toggle Automatic date and time off, then back on
  4. Your phone will sync with network time servers

Fix Time Sync on iPhone

  1. Open Settings โ†’ General โ†’ Date & Time
  2. Enable Set Automatically
  3. If already enabled: disable it, wait 10 seconds, then re-enable it to force a re-sync

Sync Time in Google Authenticator

Google Authenticator has a built-in time correction feature for Android:

  1. Open Google Authenticator
  2. Tap the three-dot menu (โ‹ฎ) โ†’ Settings โ†’ Time correction for codes
  3. Tap Sync now

On iPhone, Google Authenticator uses the system clock โ€” fix the iOS clock as described above.

Sync Time in Authy

Authy automatically synchronises time with its servers. If you're seeing wrong codes in Authy, the issue is almost certainly your device's system clock โ€” fix it using the Android or iPhone steps above.

Quick test: Use 2faco.com to generate a code using the same secret key. If the code matches what your app shows but still fails, the issue is on the server side or in how you entered the key.

After Re-Syncing

Your codes should start working immediately after fixing the clock. If codes are still rejected, the service may require you to wait 5โ€“10 minutes for the fix to propagate.

Why TOTP Codes Are Time-Dependent

TOTP (Time-based One-Time Password) codes work by combining your secret key with the current time. Both your authenticator app and the server independently calculate the expected code for the current 30-second window. If your phone's clock shows a different time than the server's clock โ€” even by a minute or two โ€” the code your app generates will not match what the server expects, resulting in an "Invalid code" or "Incorrect code" error.

How to Fix Time Sync on iPhone

Go to Settings โ†’ General โ†’ Date & Time and make sure Set Automatically is toggled on. This keeps your iPhone synchronised with Apple's time servers. If it is already on and you are still having issues, toggle it off, wait a few seconds, then toggle it back on to force a re-sync.

How to Fix Time Sync on Android

Go to Settings โ†’ General Management โ†’ Date and Time (location varies by manufacturer). Make sure Automatic date and time is turned on. Some Android versions also show a Sync now button. For Samsung devices, it may be under Settings โ†’ General Management โ†’ Date and Time โ†’ Automatic date and time.

How to Fix Time Sync in Google Authenticator

Google Authenticator has a built-in time correction feature. On Android: tap the three-dot menu โ†’ Time correction for codes โ†’ Sync now. This corrects for any clock drift in the app itself, independent of your device's system clock. Note: this feature is available on Android; on iOS, rely on the system time setting.

The 30-Second Grace Window

Most servers accept not just the current 30-second window's code, but also the one from the immediately preceding window (the previous 30 seconds). This gives a 60-second total grace period to account for network latency and minor time differences. If your clock is off by more than about 30 seconds, even this grace period may not help โ€” use the time sync steps above.

Other Causes of TOTP Failures

Time drift is the most common cause, but not the only one. Other possibilities: you are entering the wrong code (check you are looking at the right account in your authenticator app); the code has just expired as you were typing (wait for the next code and enter it quickly); you have multiple entries for the same service and are using the wrong one (common after re-scanning a QR code without deleting the old entry); or the service has a stricter synchronisation requirement than standard. If syncing your clock does not fix the issue, try deleting the account from your app and re-scanning the QR code from the service's 2FA settings.

How Other Authenticator Apps Handle Time Sync

Google Authenticator and Authy are not the only apps affected by clock drift. Microsoft Authenticator, 1Password, Bitwarden, Ente Auth and Aegis all generate standard TOTP codes, which means they all depend on the operating system's clock. In practice, if you have enabled automatic time on your phone, every app on it will start producing correct codes at the same moment โ€” there is no per-app secret to fix.

The one exception is Authy, which synchronises its codes with Authy's own servers rather than relying purely on the device clock. If Authy codes are correct while your other apps are wrong, or the reverse, the discrepancy points to the device clock or to how the account entry was added, not to a fault in the apps themselves.

A useful diagnostic: if codes from several apps all fail on your phone but work on a second device, the clock is the problem; if a single account fails everywhere, the entry is the problem. The two cases demand completely different fixes โ€” the first is solved in your system time settings, the second in the service's 2FA settings where you re-scan the original QR code.

Preventing Clock Drift When You Travel or Replace a Battery

Drift rarely appears on its own. The most common triggers are long periods in airplane mode, crossing several time zones without a network signal, and a phone that has been turned off for days โ€” for example, while it sat waiting for a battery replacement. In each case the device stops receiving network time corrections, and its internal clock slowly accumulates error.

Before you fly, confirm that automatic date and time is switched on so the phone re-syncs the moment you land and reconnect to a network. When you replace a battery or leave a phone powered off for an extended period, plan to verify a TOTP code shortly after turning it back on, and never switch to manual time-zone or clock settings to "save battery" โ€” manual time is the single most reliable way to produce a wrong code.

When Only One Service Rejects Your Codes

If codes from every authenticator entry work except one, your clock is probably fine and the problem lives in that specific account. A service may require a re-enrolment because its record of your device was reset, or the account entry in your app may contain an older or duplicated secret โ€” both are common after re-scanning a QR code without deleting the old entry.

Try this order: confirm you are looking at the newest entry for the service, delete the stale one, then check the service's 2FA settings for an option to rotate or reset your authenticator key. If the service shows a "setup key" or QR code, scan it again and generate a fresh code. A small number of services deliberately use a 60-second time step instead of the standard 30-second one; codes from those services still work normally, they just change less often, so do not treat slower code rotation as a malfunction.

Still Getting Rejected? A Final Checklist

  • Verify the clock: compare your phone's time with a web time service such as time.is โ€” a difference of more than a few seconds is the usual culprit
  • Toggle automatic time off and on to force a fresh sync, then wait a minute before generating a code
  • Check that you are entering the code for the correct account and service entry
  • Type the code while it still has at least ten seconds remaining in its window
  • If you recently restored a phone backup, remove and re-add the entry using the service's original QR code or setup key
  • Wait 5โ€“10 minutes after any fix โ€” some services cache failed attempts and temporarily reject codes

If every item on this list checks out and codes still fail on a single service, contact that service's support and ask for a 2FA reset. To verify your identity they will typically need access to the email on the account, which is why it is worth keeping that inbox protected with its own 2FA method.

Related Articles