A Secondary's passcode lives on the Security tab of that Secondary, and you type it into the Primary in the Configure window when you add the connection. That is the pair that has to match.
Worth getting one thing straight before you go looking, because they are set in different places and constantly get mixed up. The passcode is not the encryption key. Our documentation says it in those words.
There is also a genuinely separate feature called a one-time code, and it is not the Seamless path. It covers a remote KVM connection started through quick connect without a passcode, where the person at the Secondary is shown a code to read out. If that is the screen you have been hunting for, it is the wrong one for this.
The reason KVM can be fine while Seamless is not: the passcode can be set in more than one place, and on the Primary side Seamless and KVM each hold their own. Audio has a third. So a working KVM connection tells you nothing about what is sitting in the Seamless field, and standing up a new Primary is exactly the event that leaves those out of step.
Passcodes are case sensitive. If the values look identical and it still refuses, set every one of them to 123456 and retry. That is the documented test for a case or special character problem. Put them back to something real once you know which it was.
One more thing to confirm while you are in there. The encryption key is global and has to match on the Primary and every Secondary. There is a known issue with upgrades from older versions resetting it, addressed in the 4.2 changelog, so after moving to a new Primary that is worth checking rather than assuming.