---
title: Cart error messages
description: What the error messages in the cart drawer mean and how to fix the cause.
sidebar:
  label: Cart error messages
  icon: circle-alert
---

When a cart request fails, CartPops shows a short message in the drawer. This page explains each message. When a request is rejected with a session or cookie error (the first three messages below), CartPops refreshes the cart session and retries once on its own. You normally only see those messages when the cause is still present on the second try.

## "Your cart session could not be verified. Please refresh and try again."

Every cart action from the drawer carries a signed cart token that WooCommerce issues for the visitor's session. This message means the token did not match the visitor's session.

Common causes:

- The visitor's browser blocks cookies, so WooCommerce cannot keep a session.
- A security plugin, firewall, or proxy blocks the WooCommerce Store API or removes the `Cart-Token` header.
- A cache serves one visitor's session to another. See [Caching](/troubleshooting/caching).

Ask the visitor to reload the page. If it keeps happening, check that `/wp-json/wc/store/v1/cart` loads in the browser and that your firewall does not block it.

## "Your cart session is unavailable. Please refresh and try again."

WooCommerce could not start a session for the request. Reloading usually fixes it. If it keeps happening, check your PHP error log for errors.

## "Cookie check failed. Please refresh and try again."

This message appears for logged-in customers when the security token on the page has expired or was cached. It often happens after the customer logs in or out in another tab, or when a page cache serves a logged-in page to others.

Reload the page. Make sure your cache does not store pages for logged-in users, and that `/wp-admin/admin-ajax.php` is not cached.

## "This origin is not allowed to access the CartPops API."

CartPops accepts cart requests only from your own site. The address in the visitor's browser must match your **WordPress Address (URL)** or **Site Address (URL)** under **Settings** > **General**.

This message appears when the store is reached through another address, for example:

- `www.example.com` while your site address is `example.com`, or the other way around.
- A staging or preview domain that points at the same site.
- A reverse proxy or domain mapping that changes the host name.

Fix it by redirecting all visitors to one address. Make sure the site address in WordPress settings matches. If you serve the same site on more than one address on purpose, developers can add the extra addresses with the `cartpops_rest_allowed_origins` filter.

A similar message, "The request origin does not match its referrer.", has the same cause.

## "Too many requests. Please wait and try again."

CartPops limits how often a visitor can run cart actions. For example, applying a coupon is limited to 10 requests per minute. This stops bots from overloading your store.

A normal visitor rarely reaches these limits. If many visitors see this message at once, your server probably sees them all from one IP address. This happens when your site sits behind a proxy or CDN that CartPops is not told to trust. Developers can list the proxy ranges with the `cartpops_rest_trusted_proxy_cidrs` filter.

"Request limiting is temporarily unavailable. Please try again." is a short-lived server-side failure. Try again, and check your database error log if it continues.

Developers can allow extra origins with [`cartpops_rest_allowed_origins`](/developers/php-filters#cartpops_rest_allowed_origins) and declare a CDN or proxy with [`cartpops_rest_trusted_proxy_cidrs`](/developers/php-filters#cartpops_rest_trusted_proxy_cidrs). Both fail closed on invalid input, so test them on staging first.

## Related

- [Caching](/troubleshooting/caching)
- [The drawer does not open after add to cart](/troubleshooting/drawer-not-opening)
