ASP.NET MVC身份登录集成Google reCAPTCHA遇无效站点密钥错误
Let's work through why you're hitting that frustrating "Invalid site key" error and dealing with an unclickable reCAPTCHA control. Here are the most common fixes to check, in order of likelihood:
1. Double-check your reCAPTCHA key type and pairing
First off, make sure you're using the right type of keys from the Google reCAPTCHA Admin Console:
- The
reCAPTCHA.MVClibrary is designed for reCAPTCHA v2 (the "I'm not a robot" checkbox). If you created v3 keys or the invisible v2 variant, they won't work with this library—go back and generate v2-specific keys. - Never mix up your site key (public) and secret key (private):
- The site key should be configured in your
web.configand used by the@Html.Recaptcha()helper in your view. - The secret key is what you pass to the
[CaptchaValidator]attribute (either hardcoded or pulled fromweb.config).
- The site key should be configured in your
- Copy-paste errors are super common! Make sure there are no extra spaces, missing characters, or typos in either key.
2. Verify your domain whitelisting is exact
Google reCAPTCHA will block keys that aren't tied to the exact domain your app is running on:
- For local development, add your full local URL (including port number, like
localhost:49217) to the "Domains" list in the reCAPTCHA console. Wildcards like*.localhostoften don't work for local testing—be precise. - For production, add your live domain(s) (e.g.,
yourapp.com,www.yourapp.com). Double-check that you didn't accidentally add a trailing slash or misspell the domain.
3. Ensure web.config settings are correctly configured and read
You mentioned configuring keys in web.config—confirm the setup matches what the reCAPTCHA.MVC library expects:
Your appSettings should look like this:
<appSettings> <add key="ReCaptchaPublicKey" value="YOUR_PUBLIC_SITE_KEY" /> <add key="ReCaptchaPrivateKey" value="YOUR_PRIVATE_SECRET_KEY" /> </appSettings>
- If you're hardcoding the private key in the
[CaptchaValidator]attribute, make sure it matches theReCaptchaPrivateKeyvalue inweb.config. Even better, pull it from config dynamically to avoid mismatches:[CaptchaValidator( PrivateKey = System.Configuration.ConfigurationManager.AppSettings["ReCaptchaPrivateKey"], ErrorMessage = "Invalid input captcha.", RequiredMessage = "The captcha field is required.")]
4. Clear browser cache or test in incognito mode
Sometimes old cached reCAPTCHA data can cause conflicts. Try clearing your browser's cache and cookies, or open the login page in an incognito/private window. This will rule out any stale key data stored locally.
5. Update the reCAPTCHA.MVC NuGet package
Outdated versions of the library might not support the latest reCAPTCHA validation rules. Head to the NuGet Package Manager in Visual Studio, search for reCAPTCHA.MVC, and update it to the latest stable version.
6. Manually test your key validity
To confirm your keys are working outside of your app, use Google's official verification API:
Send a POST request to https://www.google.com/recaptcha/api/siteverify with these form parameters:
secret: Your private secret keyresponse: A test response token (you can get one by loading your page, checking the reCAPTCHA box, and grabbing theg-recaptcha-responsevalue from the DOM)remoteip: Your local IP address
If the response returns success: false, Google will include an error-codes field that tells you exactly what's wrong (e.g., invalid-input-secret, invalid-input-response). This can pinpoint if the issue is with the keys themselves or your app's implementation.
Start with the first three checks—they're the most common culprits for this error. Once you fix the site key issue, the reCAPTCHA control should become clickable and validate correctly.
内容的提问来源于stack exchange,提问作者jelidens

