Skip to content
DnsLister Forum

Where domain hunters compare notes

Debugging a mysterious “Bot Verification Failed” mobile login error (Cloudflare Turnstile + React Native WebView)

Earlier this week, automated login monitoring for GOM (GamersOfficialMarketing) alerted that mobile users were getting hit with a 403 Forbidden: Bot verification failed error during login, while web users authenticated cleanly.

Here is how I diagnosed and fixed the issue across our hybrid stack.

1. Diagnosing the Drop-off

I ran a quick network audit to rule out SSL or DNS issues:

  • DNS & TLS: Handshakes and API resolution completed cleanly over mobile networks.
  • Headers: Mobile clients sent valid headers and standard User-Agent strings.

Checking our Node.js auth logs revealed the real culprit: Turnstile token missing from request payload. I had recently enabled Cloudflare Turnstile on our web app to prevent credential-stuffing bots. Because the native mobile app was never wired to pass Turnstile tokens, the backend started blocking all mobile login attempts by default.

2. Building a WebView Bridge for Native Mobile

Because Turnstile relies on browser DOM execution, native React Native components cannot run the script directly.

I implemented an invisible verification bridge using react-native-webview:

  1. Hosted an HTML wrapper containing the Turnstile script.
  2. Configured Turnstile's callback to post the generated token string to React Native using window.ReactNativeWebView.postMessage(token).
  3. Wrapped the WebView inside the mobile login screen to generate challenge tokens before invoking the login API.

3. Fixing Domain & Origin Mismatches

Loading the WebView immediately threw Error 110200: Domain not authorized. Because mobile WebViews execute under about:blank or local file origins, Cloudflare's security policy rejected the request against our web sitekey setup.

The Fix:

  • Dual Widgets: Created two separate Turnstile widgets in Cloudflare—one for Web (strict domain matching) and one for Mobile (custom hostname permissions).
  • Dual Secrets on Backend: Updated the backend verification middleware to check incoming tokens against both secret keys (WEB_SECRET and MOBILE_SECRET).

Outcome

Mobile login success rates returned to 100%, with bot protection running seamlessly across both web and native apps.

If you run React Native apps behind Cloudflare-protected endpoints, account for WebView origin requirements early. How do you handle bot verification challenges on mobile?

Source: r/BuildingGOM · by /u/gramerscial

Leave a Reply

Your email address will not be published. Required fields are marked *