不正なリクエストBad request

リクエストの形式が仕様と一致しません。SDK を経由せずに API を呼び出した場合や、署名(integrity.payload_hmac)が一致しない場合に返されます。The request does not match the specification. This is returned when the API is called without the SDK, or when the signature (integrity.payload_hmac) does not match.

対処What to do

  • ページを再読み込みして、SDK からやり直してください。
  • 独自に API を呼び出している場合は、/api/v1/session/init で得た鍵素材から HKDF でセッション鍵を導出し、正規化 JSON に HMAC を付けているか確認してください。
  • Reload the page and start again through the SDK.
  • If you call the API yourself, derive the session key with HKDF from the key material returned by /api/v1/session/init and sign the canonical JSON with HMAC.

type: https://captcha.taruta.run/problems/bad-request · status: 400