You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

发送reCAPTCHA Enterprise令牌评估时INVALID_ARGUMENT错误排查

关于reCAPTCHA Enterprise令牌评估返回INVALID_ARGUMENT错误的原因分析

问题背景

我们通过RecaptchaEnterprise.xcframework在iOS客户端生成reCAPTCHA令牌,后端将令牌发送至Google进行评估时遇到400错误。客户端生成令牌的流程正常,但后端请求始终返回INVALID_ARGUMENT状态码。

客户端代码

实例化RecaptchaClient

private func activateReCAPTCHA() {
    _Concurrency.Task {
        if #available(iOS 14.0, *) {
            let (recaptchaClient, error) = await Recaptcha.getClient(Resources.recaptchaKey)
            if let error {
                print("RecaptchaClient creation error: \(String(describing: error.errorMessage)).")
                error.reportToExternalServices()
            } else if let appDelegate = UIApplication.shared.delegate as? AppDelegate {
                appDelegate.recaptchaClient = recaptchaClient
                print("RecaptchaClient created.")
            } else {
                print("RecaptchaClient creation error: AppDelegate not available.")
            }
            sleep(0)
        }
    }
}

获取令牌

extension RecaptchaClient {
    static var client: RecaptchaClient? {
        if #available(iOS 14.0, *) {
            return (UIApplication.shared.delegate as? AppDelegate)?.recaptchaClient
        } else {
            return nil
        }
    }
}

private func fetchReCAPTCHAToken() {
    guard let recaptchaClient = RecaptchaClient.client else {
        print("fetchReCAPTCHAToken: RecaptchaClient not found")
        return
    }
    
    if #available(iOS 14.0, *) {
        Task {
            let (token, error) = await recaptchaClient.execute(RecaptchaAction(action: .login))
            if let token = token {
                print("fetchReCAPTCHAToken: \(token.recaptchaToken)")
            } else {
                print("fetchReCAPTCHAToken: \(String(describing: error?.errorMessage))")
            }
            sleep(0)
        }
    }
}

后端模拟请求

我们用cURL模拟后端请求,请求体如下:

{
    "event": {
        "token": "...",
        "siteKey": "...",
        "expectedAction": "login"
    }
}

请求方式为POST,URL使用key参数:

https://recaptchaenterprise.googleapis.com/v1/projects/.../assessments?key=..

错误响应

返回400错误:

{
  "error": {
      "code": 400,
      "message": "Request contains an invalid argument.",
      "status": "INVALID_ARGUMENT"
  }
}

成功验证的操作

后续我们改用OAuth2的access_token参数替换key参数,请求成功获得有效响应:

curl "https://recaptchaenterprise.googleapis.com/v1/projects/.../assessments?access_token=$(gcloud auth print-access-token)"

错误原因分析

你使用的key参数是传统reCAPTCHA(v2/v3)的网站密钥/密钥对,但reCAPTCHA Enterprise的评估API不支持这种验证方式:

  1. reCAPTCHA Enterprise属于Google Cloud服务体系,必须使用Google Cloud标准的身份验证方式,比如OAuth2的access_token或服务账号密钥。
  2. 你提到的“用于网站与reCAPTCHA之间通信的密钥”是针对非Enterprise版的reCAPTCHA设计的,完全不适用于Enterprise版本的API调用。
  3. 当你将传统reCAPTCHA密钥作为key参数发送请求时,Google API会判定参数类型无效,直接返回INVALID_ARGUMENT错误。

内容的提问来源于stack exchange,提问作者Arik Segal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 04:05:19