Errors

Sign-in session expired — start again

Login 2FA step — TOTP pending cookie missing or IP mismatch.

Sign-in session expired — start again

POST /api/auth/login/2fa found no pending TOTP cookie, or the cookie IP no longer matches (AUTH_SESSION_EXPIRED).

Why this happens

After password login with 2FA enabled, a short-lived pending cookie must accompany the code submit. Timeout, cookie clear, VPN/IP change, or starting over without password again triggers this. Distinct from mandatory-setup Setup session expired — sign in again.

Diagnose and fix

1. Enter email/password again; then submit the authenticator code promptly.

2. Same browser and network; allow cookies.

3. Check phone time sync if codes keep failing after a fresh password step (That code did not work — try again).

4. Staff reset 2FA if the member cannot access the app.

Related