reCAPTCHA validation fails after v2 key migration in Experience Manager Forms Adaptive Forms

In Adobe Experience Manager Forms Adaptive Forms, submitting a form with a reCAPTCHA component and the Invoke a Workflow submit action fails after reCAPTCHA v2 keys are migrated. The response includes CAPTCHA_VALIDATION and an HTTP 400 status, which prevents the form submission from completing. To fix this, update the reCAPTCHA v2 configuration with the migrated keys, remove stale key references, and verify the form submission.

Description description

Environment

Adobe Experience Manager Forms Adaptive Forms on Adobe Experience Manager as a Cloud Service

Issue/Symptoms

  • Submitting an Adaptive Form with a reCAPTCHA component and the Invoke a Workflow submit action fails with a CAPTCHA validation error.
  • The response includes CAPTCHA_VALIDATION and an HTTP 400 status.
  • Form submissions fail after Google reCAPTCHA v2 keys are migrated to the cloud.
  • All form submissions that use the affected CAPTCHA configuration are impacted.
  • CAPTCHA enforcement doesn’t work as expected, which increases the risk of spam submissions.
  • No additional error message is displayed in the form interface.

Cause

The reCAPTCHA v2 configuration still references an outdated or incorrectly migrated key. As a result, AEM Forms can’t validate the CAPTCHA response during form submission, and the form returns a CAPTCHA_VALIDATION error.

Resolution resolution

To restore reCAPTCHA validation, follow these steps:

  1. Confirm that the Google reCAPTCHA v2 site key and secret key were migrated correctly according to the Google migration procedure.

  2. In AEM, open the Adaptive Forms configuration and verify that the reCAPTCHA component uses the migrated v2 keys.

  3. Remove stale reCAPTCHA v2 key references from previous AEM configurations or application code, and don’t publish the key values.

  4. Open the affected Adaptive Form, complete all required fields, and submit the form using the Invoke a Workflow submit action.

  5. Verify that CAPTCHA validation succeeds, the form is submitted successfully, and the response no longer contains CAPTCHA_VALIDATION or HTTP 400.

    Note: Monitor subsequent form submissions to confirm that CAPTCHA enforcement works as expected and that spam submissions don’t bypass the configured protection.

recommendation-more-help
experience-cloud-kcs-help-kbarticles