Skip to content

Setup key not valid

authenticator.invalid_secret · HTTP 400

What it means

The authenticator's secret, the setup key the app under test shows at MFA enrolment, is not Base32, which is letters and the digits 2 to 7 only (spaces, hyphens and padding are ignored), or it does not decode to between 10 and 64 bytes. A key cut short while copying it is the usual cause.

What to do

Copy the whole setup key again from the enrolment screen, usually shown behind "Can't scan the QR code?", or send the otpauth:// URI instead.

Every error the API returns is a JSON problem (RFC 9457) whose code names it and whose type links to its page here. See the docs for how the API works.