Embedded app checks stuck for 18+ hours despite App Bridge 4.x with session tokens

Hi, I’m stuck on the automated embedded app checks for my app listing and hoping someone can tell me what the checker actually looks for.

App: RelayShield Order Screening (unlisted, in review prep)

The two embedded app checks (“Using the latest App Bridge script loaded from Shopify’s CDN” and “Using session tokens for user authentication”) have not passed in over 18 hours, across multiple code deploys. There is no manual re-run option, and “Submit for review” stays greyed out.

What the app does today:

  1. Loads App Bridge 4.x from the CDN in the page head:
    <script src="https://cdn.shopify.com/shopifycloud/app-bridge.js"></script>

  2. On page load, calls window.shopify.idToken() to get a session token, with a retry loop in case the CDN script has not finished loading.

  3. Sends the token to a backend endpoint as Authorization: Bearer <redacted>, which verifies it. I can see the 200 responses in my worker logs when the app loads inside the Shopify admin iframe.

The app loads and renders correctly inside the admin. Webhook and HMAC checks all pass. Only the embedded app checks fail, with no detail on what the checker sees.

Questions:

  1. What exactly does the embedded app checker look for in the page? A specific script tag pattern, a network call, something else?
  2. Is there any way to force a re-check, or see the checker’s output?
  3. Could having two apps with the same name in the dev dashboard (one is an accidental CLI-created duplicate with zero installs) confuse the checker?

Any guidance appreciated. Happy to share code snippets or headers if that helps diagnose.