TROUBLESHOOTING
Find the failing boundary before changing policy.
Start with the response status, stable error code, and request_id. Do not weaken hostname, action, replay, or CSP controls to make an integration pass.
The browser request is rejected
Confirm the exact scheme and hostname are registered and that the site version and action are active.
- Inspect the browser Origin header
- Do not send a URL path as the origin
- Use the SDK matching the configured CAPTCHA version
The token fails on the server
Verify immediately and only once. A token cannot be reused across actions, hostnames, or sites.
- expired-token: request a new response
- replayed-token: investigate duplicate submission
- action-mismatch: fix the expected action
The SDK cannot run
Inspect CSP and network failures before increasing timeouts.
- Allow the GIWS origin in script-src and connect-src
- V2 proof of work requires worker-src blob:
- Keep callback and failure paths visible to users