TROUBLESHOOTING

Find the failing boundary before changing policy.

Start with the response status, stable error code, and request_id. Do not weaken hostname, action, replay, or CSP controls to make an integration pass.

Maintained documentation3 sectionsAPI contract

The browser request is rejected

Confirm the exact scheme and hostname are registered and that the site version and action are active.

  • Inspect the browser Origin header
  • Do not send a URL path as the origin
  • Use the SDK matching the configured CAPTCHA version

The token fails on the server

Verify immediately and only once. A token cannot be reused across actions, hostnames, or sites.

  • expired-token: request a new response
  • replayed-token: investigate duplicate submission
  • action-mismatch: fix the expected action

The SDK cannot run

Inspect CSP and network failures before increasing timeouts.

  • Allow the GIWS origin in script-src and connect-src
  • V2 proof of work requires worker-src blob:
  • Keep callback and failure paths visible to users