You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

reCAPTCHA Enterprise调用返回403 Forbidden问题排查求助

reCAPTCHA Enterprise REST API调用返回403 Forbidden的排查方向

背景

已完成以下配置:

  • 创建Google Cloud项目及reCAPTCHA测试站点密钥(域名设为localhost,关闭域名验证,密钥为6L***...***vw)
  • 在凭据页面创建API密钥(密钥为AI***...***So)

前端实现代码

加载reCAPTCHA Enterprise脚本:

scripts = ["https://www.google.com/recaptcha/enterprise.js?render=6L***...***vw"];
loadScripts(0);

登录触发的验证逻辑:

var recaptchResponse;
grecaptcha.enterprise.ready(async () => {
    recaptchResponse = await grecaptcha.enterprise.execute('6L***...***vw', { action: 'LOGIN' });
    authSrv2.login(vm.emailAddress, vm.password, recaptchResponse, 'LOGIN').then(function (loginResult) {
        // 后续逻辑
    });
});

后端C#实现代码

后端Web API中调用reCAPTCHA Enterprise的RunAssessment方法:

public class reCaptcha {
    public async Task<bool> RunAssessment(string token, string action) {
        string SiteKey = "6L***...***vw";
        string APIKey = "AI***...***So";

        string project = ConfigurationManager.AppSettings.Get("reCaptchaProject");
        string url = "https://recaptchaenterprise.googleapis.com/v1/projects/" + project + "/assessments?key=" + APIKey;
        string myJson = "{\"event\": { \"token\": \"" + token + "\", \"siteKey\": \"" + SiteKey + "\", \"expectedAction\": \"" + action + "\" } }";
        HttpResponseMessage response;
        using (var client = new HttpClient()) {
            try {
                ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;
                response = await client.PostAsync(url, new StringContent(myJson, Encoding.UTF8, "application/json")).ConfigureAwait(false);
                if (response.IsSuccessStatusCode) {
                    // TODO 解析结果
                    var dynamicObject = JsonConvert.DeserializeObject<dynamic>(response.Content.ToString());
                    return true;
                } else {
                    return false;
                }
            } catch (Exception ex) {
                var y = ex;
                return false;
            }
        }
    }
}

问题

调用上述后端方法后,始终返回403 Forbidden状态码,请问可能的原因是什么?

更新

附Fiddler捕获的请求头、请求JSON及响应JSON截图。


可能的排查方向

  • API密钥未关联reCAPTCHA Enterprise API:检查API密钥的配置页面,确认“API限制”中已添加并启用reCAPTCHA Enterprise API,未配置的话会被Google拒绝请求。
  • 项目ID不匹配:确认reCaptchaProject配置项对应的项目ID,和创建站点密钥的Google Cloud项目完全一致,项目ID错误会导致权限验证失败。
  • API密钥存在IP限制:如果API密钥设置了IP地址白名单,后端服务器的公网IP不在列表内就会返回403。可以暂时关闭IP限制测试是否恢复正常。
  • reCAPTCHA Enterprise API未启用:在Google Cloud控制台的API库中,确认reCAPTCHA Enterprise API已被启用,未启用的API无法接受请求。
  • 密钥跨项目使用:确保API密钥和站点密钥属于同一个Google Cloud项目,跨项目的密钥组合不被允许。
  • 请求参数拼接错误:检查请求URL中的项目ID是否正确拼接,JSON payload里的token、siteKey、expectedAction是否和前端传入的一致,避免因参数错误导致的权限验证失败。

内容的提问来源于stack exchange,提问作者nuander

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 04:59:50