Identify the browser state
Check whether the last verified session used the same browser profile and device. Private windows, browser resets and some privacy tools discard the local cookie that marks the device as recently verified.

A successful two-factor check can create a short remembered period on the current browser. That state is normally stored locally. Clearing cookies, using private mode or changing devices can remove it, while a withdrawal or security change may still require a fresh code.
Open the secure login routeCheck whether the last verified session used the same browser profile and device. Private windows, browser resets and some privacy tools discard the local cookie that marks the device as recently verified.
A remembered login does not remove every security check. A fresh code can still be required before a withdrawal, contact change or security-preference update.
Do not disable security settings or install an unknown extension to preserve a session. Use a current browser, keep the registered recovery channel secure and sign out on shared devices.
Open the account through the known address rather than an email link. If the prompt follows an action you did not start, stop and review recent activity with support.
Keep the browser profile, last successful verification time, cookie-clearing event and action that triggered the new prompt. Do not record the code.
No. Sensitive actions can still require fresh verification.
Private sessions usually do not retain the remembered-device cookie.
No. Reverify through the official route instead.
Last reviewed: 30 July 2026