Troubleshooting
Each entry starts from what you see. For every status and reason code, see Errors.
The verdict fetch always returns 404
- The page and the backend use different
sessionRefvalues. Log the value you pass tostart()and the value you fetch, and compare them. - The fetch runs more than 2 minutes after the collection. Fetch right after
ready()resolves. - The collection never reached Octet. Check the browser console for a rejected
ready(), and look up its status in Errors. - The edge's license and your read token belong to different licenses. A read token reads only the verdicts that arrived under its own license.
The browser console shows a CORS error
The page's origin isn't in the edge's ALLOWED_ORIGIN. Add the exact origin, including the scheme and any port, for example https://www.example.com, and restart the edge.
Every session gets 401 from the edge
Octet refused your license token. The reason in the edge's response, and in the edge's log, says why. See Reasons Octet gives your edge.
Honest users get medium or high
Check that nothing terminates TCP or TLS in front of the edge. A proxy, application load balancer or CDN in front of the edge makes every user look as if they were connecting through that device. See Deploy the Edge.
If the edge is set up correctly and a specific honest session still gets medium or high, send its sessionRef and time to developer@octetproof.com.
Every verdict has the same country, the one where my servers are
Something in front of the edge is replacing the user's IP address with its own. The edge takes the IP address from the TCP connection and ignores forwarded headers. Remove the device, or switch it to layer 4 passthrough.
VPN sessions come back as none
- Check that the page runs in
fullmode, the default.liteandpassivegive Octet less evidence. - Check that your CSP allows the hosts for your mode and
worker-src blob:. See Network and CSP. - Octet reports an estimate, so not every masked session is flagged.
ready() is slow
- Call
start()at page load, not at the moment of action, so that the collection is done by the time the user acts. - In
fullmode, long-distance or tunnelled connections can take up to about 1.5 seconds.liteis usually faster.
The collector script doesn't load
- Serve
octet-collector.jsfrom your own origin. Asrcthat points at the GitHub release URL won't load. - Check that the
integrityvalue is the exact contents ofoctet-collector.js.srifrom the same release as the script. A mismatch blocks the script. - Check that your
script-srcallows the path you serve it from.
The edge log says plain HTTP
EDGE_TLS_CERT_FILE or EDGE_TLS_KEY_FILE is unset, so the edge is serving HTTP. Set both and restart. See Edge Configuration.
Still stuck
Email developer@octetproof.com with the sessionRef, the time of the request, and the status and reason code you saw. Never send a license token, read token or private key.