THE AUTHENTICATOR HANDBOOK

Invalid authenticator secret key

The setup key is different from a six-digit code or a recovery code. Start by checking that you copied the right value.

Check the source

Use the manual key or otpauth link from the account’s enrollment screen. Passwords, session tokens, and recovery codes are not substitutes.

Check the copied text

Look for missing characters, line breaks, or punctuation introduced while copying. Base32 typically uses letters A–Z and digits 2–7; do not guess replacements for unclear characters.

Use the original link when available

An otpauth link may include settings that a bare key does not. The URI validator can help identify missing or conflicting fields.

If the original key is gone

The service may require a new enrollment or account recovery. A generator cannot reconstruct a secret from past codes.