Code window already served
authenticator.window_claimed · HTTP 409
What it means
The request asked for an unused code, and another request was served the same window first, or the windows already served are ahead of the server's clock. Two requests never get the same window.
What to do
Retry after the number of seconds in Retry-After, when the next window starts; the SDKs do this for you within their timeout. Pass unused: false if the app under test accepts a code used before in its window.
Every error the API returns is a JSON problem (RFC 9457) whose code names it and whose type links to its page here. See the docs for how the API works.