Snowflake Error:
390195
What does this error mean?
Snowflake rejected the MFA token because it had already expired or been used by the time the connection was authenticated — the Duo push or TOTP code was not presented quickly enough.ed, was already used, or was presented outside its valid time window.
Common causes
- 1The MFA token was generated but not used within its validity window (usually 30 seconds for TOTP)
- 2The user's device clock is out of sync, causing tokens to be calculated for the wrong time window
- 3A cached MFA token was replayed after it expired
- 4The MFA passcode was typed incorrectly or with extra whitespace
- 5The Duo Push approval timed out before the user responded
How to fix it
- 1Synchronize the device clock — TOTP tokens are time-based and a 30-second drift causes 390195.
- 2Use a freshly generated token, not one that has been waiting on a clipboard.
- 3For Duo Push, respond to the push notification promptly before it expires.
- 4If using MFA token caching, verify that the cached token has not expired: ALTER USER ... SET MINS_TO_BYPASS_MFA = N.
- 5For service accounts, consider switching to key-pair authentication to eliminate MFA dependency in automated pipelines.