<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7VcRSAVOkta Classic EngineMulti-Factor AuthenticationAnswered2020-07-09T14:22:50.000Z2018-05-15T18:25:23.000Z2020-07-02T12:24:16.000Z
  • Mihai N. (Okta, Inc.)

    Thank you for reaching out to the Okta Community,  

     

    The SMS code is valid for 5 minutes and this value cannot be edited.

     

    Regards,

     Mihai Negoita

    Okta Global Customer Care
    Expand Post
  • MihaiN.62933 (Customer)

    Hi Roy, 

     

    SMS MFA with expired token:

       - End-user UI experience resulted in a generic "Your session has expired. Please try to log in again." message.

       - API-user experience resulted in:

     

       "errorCode": "E0000011",

       "errorSummary": "Invalid token provided".

     

    Hopefully this answers your question.

     

    Regards,

     

     

    Mihai Negoita, 

     

    Okta Global Customer Care. 

    Expand Post
  • AnirbanG.94385 (Customer)

    Thanks Mihai, yes it does. So if we need to display different messages for actually invalid code and expired code, it would not be possible? The query would be from API perspective.

    • MihaiN.62933 (Customer)

      That is correct. The API error is currently not customizable. The ambiguity is most like by design due to security considerations.

      That being said, please feel free to submit this as an Idea/Feature Enhancement on the Community page. Simply go to Product→ Ideas→ Post Idea. Features suggested in our community are reviewed and can be voted and commented on by other members of the community, therefore making it much easier for the engineering team to understand the priorities that you have for feature requests.

      Expand Post
This question is closed.
Loading
How long are SMS one time passcode valid?