Setup session expired — sign in again
requireMandatory2faSetup failed: no mandatory-setup cookie, or the cookie IP does not match the current client IP.
Why this happens
After password login in mandatory-2FA mode, a short-lived cookie gates setup/confirm. Expired cookie, different network/VPN, or cookie blocked → this error on setup/confirm APIs. Distinct from TOTP-pending Sign-in session expired — start again (login 2FA code step).
Diagnose and fix
1. Sign in with password again from the start.
2. Complete QR setup without switching networks or browsers.
3. Allow cookies; avoid aggressive privacy blockers on the login origin.
4. Admin: confirm Two-factor authentication mode is intentional.