Skip to content

Turning on two-factor sign-in

Two-factor

Turning on two-factor sign-in; “That code is not valid”.

Two-factor sign-in adds a six-digit code from an authenticator app to your password. gettor uses standard TOTP, so any authenticator works — there is no gettor app to install.

  1. Open the security section of your account page and start the two-factor setup.
  2. Scan the code with your authenticator app.
  3. Enter the six-digit code it shows to confirm the pairing.
  4. Save the eight recovery codes you are given. This is the only time they are shown.

The recovery codes matter more than people expect

They are the only way back into the account if you lose the authenticator. Keep them somewhere that is not the phone holding the authenticator — a password manager, or printed and put away. The account page shows how many you have left.

Careful: Each recovery code works once. Using one reduces the count, and running out with no authenticator means the account cannot be recovered.

“That code is not valid”

Almost always clock drift on the device generating the code.

The message names the usual cause directly:

That code is not valid — check the time on your device and try again.

TOTP codes are derived from the current time. If the clock on the device running your authenticator has drifted by more than a few seconds, every code it produces will be rejected even though you are typing them correctly.

Fixing it

  1. Turn on automatic date and time on the device with the authenticator.
  2. Some authenticator apps have their own time-correction setting — use it if the system clock is already correct.
  3. Wait for the code to roll over and enter the fresh one rather than one that is about to expire.

Tip: If the codes still fail, use a recovery code to get in, then turn two-factor off and set it up again.

Still need help?

Can't find what you need? Contact support.