The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →A time-based authenticator code is generated on your device from a shared secret and the current time; the app does not need to contact the service for each code. A service can still reject a code that looks current if its clock, enrolled secret, or acceptance rules do not match the app’s.
How a time-based authenticator code is generated
Time-based one-time password (TOTP) is a version of the HOTP algorithm in which the counter comes from the current Unix time rather than from a counter that increases with each use. The authenticator and service independently calculate a code from the same secret and compatible settings. That is why an app can display codes while offline.
The calculation divides time since a starting point—the Unix epoch by default—into configured intervals. The resulting interval number is used with the shared secret to calculate an output, which is shortened to digits a person can enter. Implementations may use HMAC-SHA-1, HMAC-SHA-256, or HMAC-SHA-512 as specified by the standard. The IETF’s RFC 6238 recommends a default interval of 30 seconds, but services and authenticators are not guaranteed to use that setting.
During setup, the service provisions the authenticator with a secret and parameters. If the app has a different secret or incompatible settings, it can generate codes successfully that the service will never accept.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why a code that looks current can be rejected
The device and service clocks disagree
The app and verifier use time to select a counter. If the device clock is ahead or behind, they may calculate different counters. GitHub’s troubleshooting guidance explicitly notes that a phone or computer clock out of sync with GitHub’s server can make a code invalid: GitHub’s TOTP troubleshooting steps.
You submit near an interval boundary
A code generated just before an interval changes may reach the service after its counter has advanced. The service may allow a limited number of neighboring intervals to account for clock drift, network delay, and the time needed to enter the digits, but it sets its own policy. RFC 6238 recommends allowing no more than one time step for network delay; accepting more steps can make an exposed code usable for longer.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The authenticator entry or setup is wrong
Check that you selected the entry for the correct account and service. A different enrolled secret—or different time-step settings—produces a different code even when the app itself is working normally.
The code has already been used
Time-based codes are not intended for repeated use after successful validation. RFC 6238 says a verifier must not accept a second use for the same time step, and NIST likewise calls for accepting a given time-based one-time password only once during its validity period. A duplicate submission can therefore fail even if the displayed digits have not changed. See NIST SP 800-63B Revision 4.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The service applies a different acceptance policy
The 30-second display interval is not a guarantee that every service accepts a code for exactly 30 seconds. Verifiers choose how much clock drift and submission delay to tolerate, so a code accepted by one service may not be accepted by another. RFC 6238 gives an illustrative configuration using a 30-second interval and two accepted steps backward, with about 89 seconds of maximum elapsed drift. That is an example of a particular policy, not a universal setting.
What to do when a code does not work
- Synchronize the device clock. In the device’s date-and-time settings, enable automatic time (and automatic time zone, if available), or otherwise ensure its time is synchronized.
- Try a fresh code promptly. Wait for the next displayed interval, then enter the new code without delay. Do not keep submitting a code the service has already accepted.
- Check the account entry. Confirm the authenticator entry belongs to the account you are signing in to. If the clock is synchronized and fresh codes still fail, the enrolled secret or settings may not match.
- Use the service’s recovery process if needed. Follow that service’s current instructions for a recovery code or another recovery method. NIST defines recovery codes as secrets for regaining account access when the subscriber can no longer authenticate; available options differ by service.
- Re-enroll after regaining access. Bind a new authenticator through the service’s security settings and invalidate the old one when appropriate. For a device change, NIST advises binding the new software authenticator and invalidating the former one, or using an appropriate protected sync method.
Never send another person your one-time code or authenticator setup secret. The setup secret is the persistent key used to generate future codes, and RFC 6238 calls for protecting it from unauthorized access.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How long do you have to enter a code?
There is no single acceptance window for every service. A 30-second interval is the RFC-recommended default for generating a new code, not a promise that a verifier accepts a code for exactly that long. A verifier can allow nearby time steps to account for drift, transmission, and entry time; a wider window also extends the period in which an exposed code might be accepted. The service’s own rules determine the actual window.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Recovery options and alternatives
Save recovery information where the service provides it, and keep it separate from the device used to generate codes. If you lose access to the authenticator, use the service’s documented recovery route rather than trying to recreate or share the setup secret.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Some services also support WebAuthn/FIDO2, which can authenticate without manually copying a TOTP code. NIST identifies WebAuthn’s verifier-name binding as a phishing-resistant property. Availability depends on the service, and switching methods will not resolve a TOTP problem on an account that still requires TOTP.
Dedicated hardware TOTP tokens are another possible authenticator type, but they still rely on time and can experience clock drift. They are not a universal fix for a device-time issue, incorrect enrollment, or a service’s acceptance policy.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




