Google runs two products under the reCAPTCHA name, in two consoles, with two different verification APIs. Here is how to tell which one your keys belong to, and what follows from that.
One key is meant to be read by anyone, the other by nobody. Google’s error codes say which half is wrong, so guessing is never necessary.
Google gives a token two minutes and one verification. A checkout that takes longer than that fails honest shoppers, and the error code says so.
Google says the score is a risk signal, not a verdict. Here is how to read reCAPTCHA v3 scores on your own traffic and pick a threshold that does not cost you real orders.
A captcha on the checkout page only covers the request it is wired to. The block checkout places orders through the Store API, where classic checkout hooks never fire.