Sign-in session expired — start again
POST /api/auth/login/2fa found no pending TOTP cookie, or the cookie IP no longer matches (AUTH_SESSION_EXPIRED).
Why this happens
After password login with 2FA enabled, a short-lived pending cookie must accompany the code submit. Timeout, cookie clear, VPN/IP change, or starting over without password again triggers this. Distinct from mandatory-setup Setup session expired — sign in again.
Diagnose and fix
1. Enter email/password again; then submit the authenticator code promptly.
2. Same browser and network; allow cookies.
3. Check phone time sync if codes keep failing after a fresh password step (That code did not work — try again).
4. Staff reset 2FA if the member cannot access the app.