ConsumeEmailToken scopes its lookup to the authenticated user, so a
code minted for a different account is indistinguishable from a bad one
and got "that code is invalid, expired, or already used" — wrong on all
three counts.
The trap is that ssh git@host email verify <code> authenticates as
whichever account owns your default SSH key. Verifying a second account
therefore fails with a message pointing at the code, while the code is
fine and the key is not. Hit live while verifying an account on this
instance; ssh -F /dev/null -i <other key> worked immediately.
Now checks whether a live code exists under another user and says so, naming the account you authenticated as:
that code belongs to a different account; this key authenticated
you as cmc. Re-run with the key registered to the account being
verified: ssh -i <that key> git@<host> email verify <code>
It answers only yes-or-no on ownership and never names the owner —
naming it would turn a guessed code into an oracle for which accounts
exist. Exit is denied rather than usage: the request is well formed,
the caller is not who it needs to be.
This gets more likely now that registration is open, since every second account someone registers hits it.