WED, SEP 9 Subscribe
Education

Google Authenticator Codes Not Working? It’s Your Clock (30-Second Fix)

Google Authenticator codes not working, the phone clock sync fix in 30 seconds

Disclosure: This article is information and opinion, not financial advice. See our full disclaimer.

You’re logging into your exchange. You type the six digits from Google Authenticator, carefully, with twenty seconds left on the timer. Invalid code. You wait for the next one. Invalid code. You try your bank’s login with the same app and it works, so now you’re staring at your phone wondering which of your accounts is broken.

None of them. And the app isn’t broken either, which is why you won’t find a “fix codes” button anywhere inside it.

Authenticator codes are math built from two ingredients: a secret key and the current time. If your phone’s clock has drifted even half a minute from true time, every code your phone produces is a code from the wrong moment, and the server rejects all of them, forever, until the clock is fixed. That’s the whole problem, and it has a 30-second fix.

The 30-second fix On Android: open Google Authenticator → tap the menu (⋮ or your profile picture) → SettingsTime correction for codesSync now. Done, codes work immediately.

On iPhone: the app has no sync option; it trusts the phone’s clock. Go to Settings → General → Date & Time and make sure Set Automatically is ON (if it’s already on, toggle it off and on again). Codes work as soon as the clock corrects.

Why this happens (and why the timer looks fine)

The system behind those six digits (TOTP, if you want the term) generates a fresh code every 30 seconds from the secret plus the current time in UTC. Your exchange’s server does the same math on its end, and accepts your code only if both clocks agree about what “now” is, give or take one window.

So a phone running 60 seconds behind produces perfectly valid-looking codes, with a perfectly normal countdown animation, that are answers to a question from two windows ago. Nothing looks wrong on your screen. Everything is wrong at the server.

How clocks drift: someone set the time manually once (often to cheat a game or an app trial, honestly), auto-time got disabled, a cheap or aging phone’s clock simply wanders, or a carrier’s network time is off. It accumulates silently until the day your codes stop working, which is usually the day you least have patience for it.

Two myths, killed quickly “I traveled and my timezone broke it.” No. Codes are computed in UTC, so timezones are irrelevant. Tokyo and Tel Aviv generate identical codes at the same instant. Travel only breaks 2FA when the clock itself (not the zone) is wrong.

“Someone hacked my account and changed something.” Rejected codes mean clock drift or a wrong entry, not intrusion. A hacker who controlled your 2FA would log in quietly, not lock you out loudly.

The fix, expanded per situation

Android, the sync worked, but it drifts again every few weeks. The app’s Sync now corrects its own calculation without touching your phone’s clock, so the underlying drift remains. Fix the source: Settings → System → Date & time → turn on automatic date and time (and automatic timezone while you’re there).

iPhone, Set Automatically is on, codes still fail. Toggle it off, wait ten seconds, toggle it on, so the clock re-fetches. Still off? Check Settings → Privacy → Location Services → System Services → Setting Time Zone is enabled, and restart the phone. iPhones sync time from Apple’s servers; a restart with auto-time on virtually always lands within a second of true.

Codes fail on exactly one account, work everywhere else. Then it’s not the clock (the clock would break all of them equally). You’re reading a different entry than you think: duplicate entries with similar names are the classic, especially after setting 2FA up twice. Delete nothing yet; test each candidate entry, then clean up once you’re in.

You type fast, still invalid. Server tolerance is tight: a code entered in its final seconds can expire in transit. Wait for a fresh code and enter it early in its 30-second life. If that fixes it, your clock is near the edge of tolerance; run the sync anyway.

Desktop or third-party authenticator apps. Same physics: the computer’s clock rules. Enable automatic time sync in Windows/macOS settings. Authy, 2FAS, and friends also live and die by system time.

New phone, restored from backup, some codes work and some don’t. Cloud-synced Authenticator restores your entries, but an entry created after your last sync may be missing or stale. The working accounts confirm your clock is fine; the broken one needs 2FA re-setup through that platform’s recovery process.

Nothing works and you’re locked out. This is what backup codes were for, the ones offered at 2FA setup. No backup codes means the platform’s account-recovery route: identity verification, waiting periods, the works. Expect crypto exchanges to be deliberately slow here, and note that most freeze withdrawals for 24-72 hours after 2FA resets, which is a protection, as our withdrawal guide explains, not a punishment.

Sixty seconds of prevention, while you’re here

Since you’re in the settings anyway: keep automatic time on permanently, and go save your backup codes for the accounts that matter, today, while you’re not locked out. Screenshot them, print them, put them wherever your seed phrase lives. The version of you reading this paragraph calmly is the only version capable of doing it; the locked-out version can’t. That asymmetry is the entire argument.

Common questions

Why does Google Authenticator say my code is invalid?

Almost always clock drift: codes are generated from your phone’s time, and a clock off by even 30-60 seconds produces codes the server rejects. On Android, use the app’s Settings → Time correction for codes → Sync now; on iPhone, ensure Date & Time is set automatically. Wrong or duplicate account entries are the other common cause.

How do I sync Google Authenticator time on iPhone?

The iOS app has no internal sync option; it reads the phone’s clock directly. Fix it in Settings → General → Date & Time → Set Automatically (toggle it off and on to force a refresh). Once the system clock is correct, codes are correct.

Does changing timezone break authenticator codes?

No: codes are calculated in UTC, so timezone and travel are irrelevant. Only an incorrect clock breaks them, which travel can occasionally cause if automatic time is disabled, but the zone itself never matters.

Does Google Authenticator work offline or in airplane mode?

Yes: codes are computed entirely on your device from the stored secret and the clock, no internet required. That’s also why the app can’t detect or warn about clock drift; it has no idea what true time is unless you sync.

Why do codes work for one account but not another?

Clock problems break every account identically, so a single failing account means an entry problem: you’re reading a duplicate or similarly named entry, the platform’s 2FA was re-set at some point, or a restored backup carries a stale secret. Test each candidate entry before deleting anything.

What if I’m completely locked out with no backup codes?

Use the platform’s account-recovery process: identity verification and, on crypto exchanges, deliberate waiting periods with withdrawal freezes after the reset. Slow is the point; it’s the same friction that stops an attacker with your password from resetting your 2FA in minutes.

Do authenticator codes expire exactly every 30 seconds?

Each code belongs to a 30-second window, and servers typically accept the adjacent window as tolerance. Entering a code in its final seconds can still fail in transit, so the habit that eliminates the problem: wait for a fresh code and type it early.

How do I stop this from happening again?

Keep automatic date and time enabled at the system level (the app’s Sync now fixes the symptom, not the source), and store backup codes for every account that matters while you have access. Two settings and a screenshot, and this article becomes irrelevant to you permanently.

Leave a Reply

Your email address will not be published. Required fields are marked *

The DEGX Brief

One email a day. Markets, alpha, and zero fluff.