Okta Verify Displays a Too Many Attempts Error on Mobile Devices
Last Updated:
Overview
Okta Verify displays a rate limit error on mobile devices when the authentication attempts exceed the allowed threshold. Force-quitting applications, clearing the browser cache, restarting the device, updating the application, or re-enrolling the account resolves the issue. When this rate limit violation occurs, Okta Verify displays the following error:
Too many attempts. Try again later.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Verify
- Mobile Devices
Cause
The system enforces a rate limit of 20 authentications per 5 seconds. When a user exceeds this limit, Okta triggers a system.operation.rate_limit.violation event in the System Log. This blocks the user and generates an error for the /idp/idx/authenticators/sso_extension/transactions/<transactionId>/verify URL pattern.
Review the following examples of the rate limit violation in the System Log.
Solution
How is the Okta Verify "Too many attempts. Try again later." error resolved?
Resolve the rate limit error by force-quitting applications, clearing the browser cache, restarting the device, updating Okta Verify, or re-enrolling the account.
- Force Quit Applications: Swipe up and force close all apps and the browser (for example, Safari) to kill any active authentication threads.
- Clear Cache and Cookies: For example, if using an Apple iPhone, then since the iOS SSO Extension relies on Safari's shared session state, a corrupted cache can cause this loop. Ask the user to navigate to Settings > Safari > Clear History and Website Data.
- Restart the iPhone: A device restart will help clear the SSO Extension's background processes and memory.
- Update Okta Verify: Verify that the user is running the most recent version of the Okta Verify app from the Apple App Store or Google Play Store.
- Re-enroll in Okta Verify: If the above steps do not resolve the looping behavior, the FastPass binding on the device may be out of sync. The user should open the Okta Verify app, remove their Okta account, and completely re-enroll the account and set up FastPass again.
