Troubleshooting
Common setup problems and what they usually mean.
Invalid API key
The Authorization header is missing, malformed, revoked, or from another deployment.
Expected format:
Authorization: Bearer hic_...
Callback domain is not allowlisted
The API key is valid, but its callback hostname restriction does not match the callback URL.
If your callback is:
https://n8n.dspsolves.com/webhook-waiting/abc
The API key must allow:
n8n.dspsolves.com
Create a new key with that callback hostname, or leave the hostname blank to allow any public HTTPS callback URL, then update your workflow.
Key says "Never used"
Refresh Organization admin after the workflow calls the API. A key counts as used after it authenticates successfully.
If the request fails before authentication, the key will still show as never used.
n8n Wait node keeps waiting
Check:
- the review was approved or rejected;
- the undo window has finished;
- the callback hostname matches the key restriction, if one was configured;
- the n8n execution is still waiting;
- the resume URL belongs to the current execution;
- callback delivery health in Organization admin.
Push notifications do not appear
Push notifications are supported only from the installed Human In Circuit app. Do not enable them from a normal browser tab.
On iPhone, add the PWA to the Home Screen from Safari. On Android, use Chrome's Install app option. Then open the app from the Home Screen and enable notifications in Settings.
Login redirects to localhost
Set NEXT_PUBLIC_APP_URL to the public HTTPS app URL and add the same callback URL in Supabase Auth:
https://your-domain.example/auth/callback
Do not rely on Railway internal request hosts for auth redirects.