Why is my MFA code being rejected as "invalid token" or "invalid code"?

Matt Dumouchel
Matt Dumouchel
  • Updated

If Ketryx rejects your authenticator code as "invalid token provided" or "invalid code" - whether you are approving an item or activating a new authenticator app - the code itself is almost always being generated correctly. The most common cause is a time synchronization issue on the device running your authenticator app.

Why this happens

Authenticator apps (such as Google Authenticator or Authy) generate codes based on the current time, in 30-second windows. If the clock on your phone or device drifts more than about 30 seconds from the actual time, every code will be rejected as invalid even though you are entering it correctly.

Repeated failed attempts on the signature prompt can also temporarily lock your MFA, which then requires an Organization Owner to reset it (see Multi-Factor Authentication (MFA) Reset). Note that entering an invalid code on the authenticator setup (activation) screen does not lock your account - the lockout comes only from repeated failed attempts on the approval or signature prompt.

How to fix it

  1. Correct the time on your device. Turn on automatic (network) date and time.
  2. Remove any old Ketryx entry in your authenticator app before re-enrolling, so there is no leftover secret from a previous setup.
  3. Rescan the current QR code, wait for a fresh code to appear, and enter it promptly within its window.
  4. Consider using a security key or Touch ID / Face ID instead of an authenticator app. These methods do not depend on clock synchronization, so they avoid this issue entirely, and they are generally faster to use for approvals.

If you belong to more than one organization

Your authenticator is tied to your Ketryx user account, so the same token works across every organization you belong to. You do not have a separate token per organization.

MFA status and resets, however, are managed per Organization. An Owner can only reset your MFA while you have that Organization set as your current Organization. If your MFA was reset in one Organization, make sure you are working in that same Organization (use "Switch organizations" in the left menu) when you set up your new authenticator - see the Owner definition in the Definitions and Acronyms section of MAN-001 in the Ketryx documentation.

Still not working?

If codes are still rejected after you have corrected your device time and re-enrolled, ask your Organization Owner to reset your MFA status, or reach out to a Ketryx team member. See also: Why does Ketryx say that I need to reset my MFA? and How do I set up multifactor authentication (MFA)?

Related to

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Article is closed for comments.