Four common extension errors and the fastest way to fix each one.
Lovable occasionally asks for extra human verification. While the extension is active, that captcha cannot be displayed, so prompts fail with the error popup (status 428, captcha_required). Apply any one of the fixes to get going again.
What the error looks like
{"status":428,"type":"captcha_required","title":"Additional verification is required. Please complete the captcha and try again.","message":"Additional verification is required. Please complete the captcha and try again.","details":"","request_id":"1c7da7117f914eda6af9c40311b5be7e"}
The request_id value changes every time. Any popup mentioning captcha_required or status 428 means the same thing.
Turn the extension off in your browser's extension manager, then send any prompt on Lovable. The captcha popup will now appear — solve it, turn the extension back on, and keep working as usual.
Connect to a VPN (or switch to a different VPN server) so Lovable sees a new IP address, then reload the Lovable tab and send your prompt again.
Sign out of your Lovable account, sign back in, and retry your prompt. A fresh session usually clears the verification requirement.
The extension needs at least 1 credit in your active Lovable workspace to operate. Lovable gives every account 5 free credits per day. If the workspace balance reaches 0, prompts fail with the popup (status 402, Payment required).
What the error looks like
{"status":402,"type":"Payment required","title":"Workspace out of credits","message":"Workspace out of credits","details":"","request_id":"f4cc62012220ccfcca593137fa186484"}
The request_id value changes every time. Any popup mentioning Payment required or status 402 means the same thing.
Lovable gives every account 5 free credits each day, and those same credits work with the extension. Wait up to 24 hours for the daily refresh, then continue using the extension as usual.
Open another workspace that still has at least 1 credit remaining — or create a new one — and use the extension there.
Sign in with a new or secondary Lovable account that still has credits available and continue from there.
When you create a new project through the extension, Lovable's fraud protection sometimes flags the request as suspicious — usually because of your IP address — and blocks it (status 403, castle_denied). Your account is fine; apply any one of the fixes.
What the error looks like
{"status":403,"type":"castle_denied","title":"Project creation was blocked due to suspicious activity. Contact support if you believe this is a mistake.","message":"Project creation was blocked due to suspicious activity. Contact support if you believe this is a mistake.","details":"","request_id":"015bf371ce7f1604c59be2fec1501523"}
The request_id value changes every time. Any popup mentioning castle_denied or status 403 means the same thing.
Turn the extension off, create the new project from the Lovable dashboard as normal, then turn the extension back on and continue prompting inside that project.
This block is mostly based on IP reputation. Connect to a VPN or switch networks so Lovable sees a new IP address, then try creating the project again.
Switch to another workspace, or sign in with a new or secondary Lovable account, and create the project there.
If prompts suddenly fail with the red message (status 401, unauthorized — "Invalid token"), the extension's session token has expired or become invalid. This is the quickest error to fix — a single reload clears it.
What the error looks like
{"status":401,"type":"unauthorized","title":"Invalid token","message":"Invalid token","details":"","request_id":"fa8feffa8080ba8a7e0e8afe8..."}
The request_id value changes every time. Any red message mentioning unauthorized or status 401 means the same thing.
Visit the Lovable website in the same browser and refresh or reload the page. The extension picks up a fresh session token automatically and the error goes away.