Synthetic Industry

Troubleshooting guide · updated 2026-10-11

Address autocomplete on a checkout: which Google component, which key settings, which fields

Use the current Places autocomplete component, restrict the key to your site and to the Maps JavaScript API and Places API (New), and request only the address fields the form uses.

Which component to use

Google's current JavaScript component for address lookup is the place autocomplete element, loaded from the places library of the Maps JavaScript API and served by Places API (New), which Google says must be enabled on your Cloud project. Google marks the older Places API and the JavaScript Places Service as Legacy from 1 March 2025 and says Legacy services are not available in new Cloud projects, while existing projects can keep using them. The legacy page does not name the older autocomplete widget, so if yours stopped working, read the browser console error and Google's migration guide rather than assuming the cause. Note the names: the current product is Places API (New) and the older one is simply Places API, so check which is enabled.

  • Legacy means feature-frozen and supported, not switched off; Google commits to at least twelve months notice before decommissioning.
  • Enable Places API (New) for the new component, not the legacy Places API.
  • Replace the old component on one form first and compare.

Lock the key down

A browser key is visible to anyone who views the page, so its protection is its restrictions. Google advises one application restriction per key, for a website that means HTTP referrers written with scheme and host, optionally with a wildcard subdomain, plus an API restriction listing only the APIs the page uses. For the autocomplete element that is two: the Maps JavaScript API, which Google says to always authorise on the key if your app uses it and which loads the script, and Places API (New), which serves the suggestions and place details. A key restricted to the Places service alone would not be authorised for the script load. Keep keys out of the repository and use a separate key for each application. Google says you are financially responsible for charges caused by abuse of unrestricted keys.

  • Avoid path-level referrers; browsers often strip the path.
  • Disable unused services at the project level.
  • A per-user, per-minute quota on a client-side project can cap damage from misuse.
  • Test the page with the restricted key, not only an unrestricted development key, so a missing service shows up before launch.

Ask only for what the form uses

After a user picks a suggestion, the page asks Google for details of that place. The documentation tells developers to name only the fields they need, and notes that the fields requested affect the billing category. The address components and formatted address sit in the Essentials tier of Place Details. A form that needs a street, town, postcode and country should request the address components and nothing about photos, reviews or opening hours.

  • Capture one real selection's network request and read its field list.
  • The element handles the session token for you; you manage tokens yourself only in a programmatic build.
  • No cost figure is promised here; billing is set by Google's pricing and your usage.

Map the parts and keep typing possible

Addresses differ by country, and a returned component list will not always have a number, a street, or a town in the form's expected place. Write ten sample addresses before building, include a flat or unit, one with no street number and one with accents, write the expected value of each box, then compare. Limit predictions to the countries you serve with the region-code option. If Google is blocked, slow or declined, the form must accept typed text and submit.

  • Never make a selection mandatory for submission.
  • Autocomplete suggests places; it does not certify that a parcel can be delivered.
  • Keep a record of mismatches found during testing.

How the paid outcome is accepted

The address autocomplete outcome is accepted when the ten sample addresses fill the boxes as expected, manual entry still submits with Google blocked, the request names only the agreed fields, and the key is refused from a website not on its list. The fixed £295 test price is untested and payment follows your sign-off. Deliverability checking is a different product and scope.

Sources and limits

  • Google Maps JavaScript API: Place Autocomplete (New) Checked 2026-10-11.
    • The element handles session tokens automatically; fetchFields should name only the fields needed.
    • includedRegionCodes limits predictions to chosen countries.
    • Billing depends on the session and the place fields requested.
    • To use Place Autocomplete you must enable Places API (New) on your Google Cloud project.
  • Google Maps Platform: API security best practices Checked 2026-10-11.
    • Website keys are restricted by HTTP referrer with scheme and host, paired with API restrictions; keys belong outside source code; one key per app.
    • You are financially responsible for abuse of unrestricted keys.
    • Restrict an API key to only the APIs it is used for; if your app uses the Maps JavaScript API, always authorize it on your key.
  • Google Maps Platform: Legacy products Checked 2026-10-11.
    • Places API (legacy) and the Maps JavaScript Places Service were marked Legacy on 1 March 2025 and are not available in new Cloud projects.
    • Places API (New) is the listed replacement for the legacy Places API; legacy services stay fully supported for existing projects, with at least 12 months notice before decommissioning.
  • Google Maps JavaScript API: Place data fields Checked 2026-10-11.
    • addressComponents and formattedAddress are Place Details Essentials fields.