How to troubleshoot the Salesforce error message "Error: Invalid or expired verification code. Try again."
Note: If the allowed number of verification attempts is exceeded, the following error will occur, and your user account will be temporarily locked, preventing login:
"Error: The allowed number of attempts has been exceeded." Please be careful not to exceed the allowed attempts when implementing the resolution steps described in this article.
If this error occurs even when entering the correct TOTP code for identity verification using a TOTP code from Salesforce Authenticator, a System Administrator must disconnect the Salesforce Authenticator that is currently connected to the user's account.
After disconnection, the user experiencing the error should log into Salesforce and reconnect the Salesforce Authenticator to their account.
Verify that you are entering the correct or a valid verification code.
The error can also be displayed if there is a discrepancy in the time settings on the device where the authentication application is installed. Please check the time settings on the device.
Troubleshoot Multi-Factor Authentication Issues with Salesforce
Excerpt: "Ensure the time on the device running your TOTP authentication app is synchronized with your computer and the official time at http://www.time.gov/— a discrepancy will cause an invalid token error"
Reference Materials:
000395187

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.