Tencent Cloud KYC Linked Accounts Tencent Cloud COS JS-SDK Uploads Stuck at 99%: Common Root Causes
If your COS JS-SDK upload always stops at 99%, the problem is usually not “the file is too large” in a simple sense. In real projects, 99% often means the browser has already sent most of the data, but the final confirmation step failed somewhere between temporary credentials, CORS, bucket permissions, network interception, or account-side restrictions.
What users usually care about is not just “why it happens,” but what to check first, whether their Tencent Cloud account is actually usable, and how payment or verification issues can affect upload behavior. Those are the parts that save time in production.
First: what 99% usually means in practice
When COS JS-SDK shows 99%, I usually split the issue into two buckets:
- Data transfer is basically done, but the SDK cannot complete the final request.
- Tencent Cloud KYC Linked Accounts The browser UI says 99%, but the request is actually retrying, waiting, or blocked in the background.
That is why the fix is rarely just “increase timeout.” In real troubleshooting, the most common mistakes are:
- only checking the front-end progress bar and ignoring the Network tab;
- assuming it is a COS issue, while the account is under verification or billing restriction;
- Tencent Cloud KYC Linked Accounts using temporary credentials that expire before multipart upload finishes;
- misconfiguring CORS and letting the browser block the final request;
- missing one permission in CAM policy, especially for multipart upload.
The fastest way to narrow it down
Before changing code, ask these four questions:
- Does 99% happen for every file, or only large files?
- Does it happen on all browsers, or only one browser / network?
- Is the Tencent Cloud account fully verified and funded?
- Is the upload using permanent credentials, STS, or server-generated authorization?
Those answers usually point straight to the root cause.
| Symptom | Most likely cause | What to check first |
|---|---|---|
| Stuck at 99% only for large files | STS expiration, multipart completion failure, unstable network | Token validity, part size, retry logs |
| Stuck at 99% on one browser only | CORS, extension interference, browser cache issues | Incognito mode, DevTools Network tab |
| Fails after account registration or KYC | Account still under review, billing not activated | Verification status, billing status, support notices |
| Upload works in test but fails in production | Wrong bucket region, policy mismatch, custom domain issue | Bucket region, COS endpoint, CAM permissions |
| Always 99% with 403/Signature errors | Expired credential, incorrect authorization, insufficient permissions | STS expiration time, signature generation logic |
1) Temporary credentials expire before upload finishes
This is one of the most common real-world causes, especially when the front end uses STS temporary credentials. The file may upload almost completely, but when the SDK tries to complete the multipart request or finalize the upload, the token has already expired.
It happens most often in these scenarios:
- large files such as videos, archives, PSDs, or raw images;
- slow mobile networks or office networks with packet loss;
- short-lived credentials issued for 10–15 minutes;
- users pause the upload, switch tabs, or lose connectivity mid-way.
Practical fix:
- Increase the STS validity period to match real upload time, not just ideal conditions.
- Refresh credentials before starting uploads, especially for files over a few hundred MB.
- Use smaller multipart chunk sizes if completion is failing near the end.
- Do not generate credentials only once on page load if users may upload later.
In production systems, I usually recommend that the front end requests fresh upload authorization right before the file starts. This is safer than caching it for too long.
2) CORS is configured incorrectly, so the browser blocks the final step
If you see 99% in the UI but the browser console shows failed preflight, blocked request, or OPTIONS errors, CORS is a strong suspect. This is especially common when a team tests uploads in one environment and deploys to another domain later.
Tencent Cloud KYC Linked Accounts The pattern I see often:
- upload starts normally;
- multipart data is sent;
- the final request is blocked by the browser;
- Tencent Cloud KYC Linked Accounts the user only sees “stuck at 99%.”
Check these COS bucket CORS settings:
- Allowed origin includes the exact website domain;
- Allowed methods include the methods used by the SDK, usually
GET,POST,PUT, andOPTIONS; - Tencent Cloud KYC Linked Accounts Allowed headers include the headers added by your auth logic;
- Expose headers include the response headers your code reads;
- Use the correct scheme:
httpsandhttpare treated differently.
Operational tip: if it works locally but fails after deployment, compare the deployed origin exactly, including subdomain and protocol. A lot of “random” 99% issues are just CORS rules that were copied too broadly or too narrowly.
3) The CAM policy is missing one permission
Another frequent root cause is incomplete authorization. The upload may start because the SDK can initiate the request, but it fails on multipart operations or completion because the role or sub-account lacks the full set of permissions.
For multipart upload, it is not enough to allow only object write. In practice, you should verify that the account or role can perform the full upload lifecycle, including:
- initiating multipart upload;
- uploading parts;
- completing multipart upload;
- reading object metadata if your code validates the result.
If your policy was copied from another bucket or another project, check the resource scope. A policy that looks correct on paper can still fail if it points to the wrong region, bucket, or prefix path.
What I usually do in a live incident: test with a temporary policy that has only the minimum required COS write permissions for one bucket and one prefix. If the upload works, the issue is policy scope, not SDK code.
4) The bucket region or endpoint does not match the SDK configuration
Region mismatches are especially common during multi-environment deployments. The front-end may be pointing to one bucket, but the authorization service signs for another region. The result can look like a hung upload, intermittent retries, or silent failure near the end.
Typical real-world scenarios:
- the test bucket is in one region, production bucket in another;
- Tencent Cloud KYC Linked Accounts the backend signs the authorization using an old endpoint;
- the front end uses a custom domain that does not map correctly to the bucket region;
- the team cloned a project and forgot to update the COS region variable.
Practical check: confirm that these four values are aligned:
- Tencent Cloud KYC Linked Accounts bucket name;
- bucket region;
- authorization server region;
- front-end SDK endpoint / host configuration.
5) Browser, proxy, or extension interference
Not every 99% problem comes from Tencent Cloud. In enterprise networks, I have seen uploads fail because of proxies, corporate security software, browser extensions, or aggressive traffic inspection.
This is common when:
- Tencent Cloud KYC Linked Accounts the upload works on home Wi-Fi but not office network;
- Chrome fails but Edge works, or vice versa;
- ad blockers or privacy extensions are enabled;
- VPN or proxy settings change the request path;
- the browser tab is backgrounded and the upload gets throttled.
Quick isolation steps:
- Open the page in incognito mode.
- Disable extensions temporarily.
- Test on another network, preferably a mobile hotspot.
- Compare the request and response status in DevTools.
If the problem disappears in incognito mode, the SDK is usually not the main issue.
6) The file path or object key causes completion failures
Some upload bugs only happen with certain filenames. That is why the problem appears “random” to users.
Common troublemakers include:
- Chinese characters combined with special symbols;
- Tencent Cloud KYC Linked Accounts emoji in filenames;
- very long file paths;
- spaces, brackets, and reserved characters;
- repeated separators or accidental control characters from pasted text.
The upload may reach the server, but later steps fail when the object key is encoded, validated, or displayed. If only certain filenames get stuck at 99%, normalize the object key before upload and keep the original filename separately in your database.
7) Account verification, funding, and risk control can block COS usage
This is the part many users overlook. If you are purchasing a new Tencent Cloud International account or just passed registration, upload problems are sometimes not caused by the front end at all. The account may still be in KYC review, under risk control, or not fully activated for billing.
I have seen this especially in the following cases:
- brand-new accounts created with a fresh email and card;
- accounts that switch devices, regions, or payment methods during registration;
- accounts with incomplete identity verification;
- accounts whose cards were declined during the first charge;
- accounts with overdue invoices or failed renewals.
What this means in practice: the COS console may still be accessible, but the account’s ability to create credentials, complete billing activation, or pass risk checks can be limited. You may see 403 errors, authorization failures, or uploads that appear to hang because the backend token issuance is blocked.
What to check in account setup
- Identity verification status: make sure the account owner name matches the payment card or company documents.
- Billing activation: confirm the account is not pending payment verification.
- Service restrictions: check whether COS, STS, or CAM actions are limited.
- Risk review notices: look for alerts in the console or email inbox.
Important operational point: if an account is under review, repeated failed upload attempts, frequent token requests, or switching payment methods too often can make the review take longer. It is better to stabilize the account first, then debug the SDK.
8) Payment method problems can surface as “upload issues”
Users often blame the upload SDK when the real issue is billing. This happens a lot during account purchase and first-time activation.
In practice, the fastest payment method is usually a credit or debit card that supports international online payments. If the card is not accepted, the account may remain in a pending state until verification is completed. Depending on the region, enterprise accounts may also use bank transfer or invoicing, but those methods are slower to activate.
Common payment-related failure patterns:
- card authorization failed, but the user keeps retrying the upload;
- 3D Secure verification was not completed;
- the bank blocked cross-border or recurring cloud charges;
- the payment name and the verification name do not match;
- the account balance or prepaid amount was exhausted and renewal failed.
What this changes for COS: if the billing side is not healthy, some service operations may be restricted or delayed. Even when your code is correct, the upload can still fail because the account cannot finish the auth or service call chain behind the scenes.
Tencent Cloud KYC Linked Accounts 9) Renewal overdue is a real production risk
If your upload service is business-critical, do not wait until the last day to renew. A lot of teams only discover the problem when the upload page is already showing failures.
Once renewal is overdue or payment fails:
- access may become limited after the grace period;
- service endpoints can return authorization errors;
- temporary credentials may stop being issued correctly;
- uploads can stall at the final step, especially if the account is partially suspended.
My practical advice: enable renewal reminders, verify the payment card before the renewal date, and keep a backup payment method if the business depends on uninterrupted COS uploads.
Direct upload vs proxy upload vs pre-signed URL: what usually costs less
When teams get tired of debugging 99% uploads, they sometimes ask whether they should change the architecture. That is a reasonable question.
| Method | Pros | Hidden cost | Best for |
|---|---|---|---|
| JS-SDK direct upload to COS | Lower server load, faster for users, simpler at scale | CORS and STS must be correct; browser issues still possible | Web apps with end-user file uploads |
| Server relay upload | Easier to control auth and logging | Your server pays bandwidth and compute; usually more expensive | Small traffic, strict control requirements |
| Pre-signed / temporary authorization upload | Good balance of control and browser simplicity | Authorization expiry must be managed carefully | Most production web upload scenarios |
From a cost angle, direct browser upload usually saves your own server bandwidth, which matters a lot if users upload large files. But if your auth or CORS setup is unstable, the cheap architecture becomes expensive in support time. The real cost is often the time spent on incident handling, not the COS request itself.
For large files, multipart upload is usually the right approach. It slightly increases request count, but it is often the only reliable way to handle unstable networks and recover from failed chunks.
What I would check in the first 15 minutes
If a client calls me saying “COS JS-SDK upload is stuck at 99%,” I usually ask them to collect these items before making code changes:
- Browser console error and Network tab screenshot.
- STS expiration time and the exact upload duration.
- Bucket region and the endpoint used by the SDK.
- CORS rules currently set on the bucket.
- CAM policy for the upload role or sub-account.
- Account verification and billing status in the console.
- Payment history / overdue notices, if the account is new or recently renewed.
In real cases, this list usually narrows the problem much faster than reading SDK examples.
Two real-world patterns I see often
Case 1: The upload worked in test, failed after go-live
A team deployed a new upload page and started getting 99% stalls on production only. The SDK code had not changed. The issue was that the production domain was not added to the bucket CORS allowed origin list, and the backend auth service was still signing for the test region. After fixing both, the issue disappeared without touching the upload UI.
Lesson: when test and production behave differently, verify environment-specific settings first.
Case 2: Large video uploads stopped near completion
A company uploaded 300 MB to 2 GB files from mobile networks. The progress bar stayed at 99%, but the final multipart completion frequently failed. The root cause was a 15-minute temporary credential lifetime combined with unstable network speed. Extending the token validity, refreshing before upload, and reducing part size solved it.
Lesson: if only large files fail, focus on expiration timing and multipart behavior before debugging the UI.
FAQ
Is 99% always a COS problem?
No. In many cases it is caused by browser blocking, expired authorization, or account-side billing restrictions. COS is only one part of the chain.
Do I need enterprise verification to use COS?
Not always for basic use, but for stable business operations, higher limits, and cleaner billing control, enterprise verification is often the better route. If the account is newly created and still under review, upload behavior can be affected.
Can a failed payment cause upload to hang?
Yes. If the account is not fully activated, under risk review, or overdue on renewal, the SDK may fail during authorization or service calls even if the upload page still looks normal.
Should I use credit card, bank transfer, or prepaid funding?
For fast activation, a working international card is usually the quickest. Bank transfer and invoicing are more suitable for enterprise procurement, but they often take longer to activate. If your launch date is close, do not leave billing setup to the last minute.
Why does it only fail on one office network?
That points to proxy filtering, corporate firewall rules, or TLS inspection. Test with a mobile hotspot and compare the request status in DevTools.
Is multipart upload more expensive?
It can create more requests than a single upload, so request charges may be slightly higher. But for larger files, the reliability gain is usually worth it. A failed single upload that must be retried repeatedly costs more in time and support than multipart request fees.
What to do next if you need the upload live today
If you are under time pressure, do not start by rewriting the SDK integration. Use this order:
- Confirm the account is fully verified and not under billing restriction.
- Check whether the payment method is active and renewal is not overdue.
- Compare the bucket region with the SDK endpoint and auth server region.
- Validate CORS on the bucket.
- Check token expiration time against the real upload duration.
- Test in incognito mode and on another network.
- Inspect the exact error in the Network tab instead of relying on the 99% progress indicator.
In most cases, the first meaningful fix comes from aligning account status, permissions, and authorization timing. If those three are healthy, the JS-SDK usually behaves normally. If one of them is off, 99% is often just the symptom you happen to see first.

