Hi Colin.
I have experienced something similar when I was testing zMFA and the TOTP factor in combination with various apps. The QR code generated by zMFA contains information that is derived from either the default factor settings or the users factor settings. This includes the digest algorithm, the token code length and the token period. An app may not have implemented support for these settings, and may choose to override the information in the QR code and simply use defaults set by the app. In that case, you may experience that token codes generated from one app are working, whereas token codes generated by other apps are not.
Something similar may be the case with other types of one time passwords.
Best regards
Mikael Rasmussen
------------------------------
Mikael Rasmussen
Senior Mainframe Security Engineer
Danske Bank
Brabrand
+4540766221
------------------------------