Almost always a Content-Security-Policy. The script is blocked before it runs, and a blocked script cannot tell you it was blocked, so the page looks completely normal.
Add api.askverb.com to both script-src and connect-src. Two directives, and missing the second is the sneakier failure: the widget appears, then every question fails to reach us.
If your policy uses 'strict-dynamic', which is the default in a Next.js app that sets a CSP, that advice changes. A browser honouring 'strict-dynamic' ignores host allowlists in script-src entirely, so adding us there does nothing at all. What the tag needs instead is your per-request nonce. connect-src still needs the host, and that is the half that would otherwise break.
Next.js: the nonce is what matters, not the allowlist
<script src="https://api.askverb.com/v1/verb.js"
data-verb-site="YOUR_SITE_KEY"
nonce={nonce} defer></script>Worth knowing before you ship: many apps only send a CSP in production. That means this failure cannot reproduce on your machine. The install works all afternoon locally and is silently dead the moment it deploys, which is the most expensive shape this particular bug has.
Check your browser console for a CSP violation naming askverb.com. If there is nothing there at all, confirm the script tag is in your root layout rather than a single page, and that the site key matches the one in your dashboard.