After having MFA up and running successfully.
User want to add a new phone number/change the device, we remove the old enrollment (with success) and associate a new (with success as well). Up to there everything is fine (we get a new mfa_token and a new oob_code) which we use to verify along with the new binding_code (sent to the new device), but the verification fails:
{"error":"invalid_request","error_description":"The oob_code doesn't match the mfa_token"}
Any help, much appreciated