the passwordless component could use the TTL setting to clean up expired codes. Check here for more details: https://github.com/serverless-components/passwordless/issues/4