Don’t keep pressing “send another code” every minute. That was the confusing part for me when I first dealt with this kind of problem: some services invalidate the previous code as soon as a new one is requested, while email or SMS delivery can be delayed. You can end up entering code number two after code number four has already replaced it, which looks like the recovery system is completely broken.
I would stop requesting codes for a while, then make one clean attempt and note the exact time. When it arrives, check when the message was sent rather than assuming the newest message in your inbox contains the current code. If several arrive together, only the last code requested is likely to work. Repeated attempts can trigger a temporary limit too, so trying harder may extend the lockout.
The saved session is useful, but I would use it to check something simpler before changing the whole security setup: where is the code actually being sent? Masked addresses and phone numbers are easy to misread. An address shown as j***@example.com might be an old mailbox, and the final two digits of a phone number may belong to a number you no longer have. Write down the full recovery destination after confirming it in the account settings.
I agree with keeping that session signed in, although I would avoid making ten security changes in one sitting. Changing the password, recovery email, phone number, and authentication method together can look suspicious to an automated system. Make the minimum changes needed to create one dependable recovery route, save the confirmation, and then leave the account alone long enough for the changes to settle.
There is another small annoyance people can miss: codes sometimes fail because the device time is wrong, especially with authenticator apps. Turn on automatic date, time, and time zone settings on the phone and laptop. For email or text codes, type the code instead of copying extra spaces or punctuation, and make sure the page asking for it is still the same recovery attempt that generated it.
Once you know one fallback works, then set up a second method and store its emergency information somewhere outside the account. The main lesson for me is that “recovery code never arrived” and “account keeps rejecting valid recovery codes” are separate problems. The first points toward delivery or the wrong destination. The second is more likely to be expired codes, too many requests, an old recovery page, or a temporary security hold.